Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2019-2134

    In phFriNfc_ExtnsTransceive of phNxpExtns_MifareStd.cpp, there is a possible out of bounds write due to an integer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for ex... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: Aug. 20, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-3221

    Stack-based buffer overflow in Audio Lib Player (ALP) allows remote attackers to execute arbitrary code via a long URL in a .m3u playlist file.... Read more

    Affected Products : audio_lib_player
    • EPSS Score: %7.68
    • Published: Sep. 16, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2019-2702

    Vulnerability in the Oracle Hospitality Cruise Dining Room Management component of Oracle Hospitality Applications (subcomponent: Web Service). The supported version that is affected is 8.0.80. Easily exploitable vulnerability allows unauthenticated attac... Read more

    • EPSS Score: %1.47
    • Published: Apr. 23, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2013-4737

    The CONFIG_STRICT_MEMORY_RWX implementation for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not properly consider certain memory sections, which makes it easier for atta... Read more

    Affected Products : quic_mobile_station_modem_kernel
    • EPSS Score: %0.63
    • Published: Feb. 15, 2014
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2020-0099

    In addWindow of WindowManagerService.java, there is a possible window overlay attack due to an insecure default value. This could lead to local escalation of privilege via tapjacking with no additional execution privileges needed. User interaction is need... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: Dec. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2013-4859

    INSTEON Hub 2242-222 lacks Web and API authentication... Read more

    Affected Products : hub_firmware hub
    • EPSS Score: %8.60
    • Published: Dec. 27, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-2855

    An exploitable buffer overflow vulnerability exists in the DDNS client used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.43. On devices with DDNS enabled, an attacker who is able to intercept HTTP connections will be able to fully... Read more

    Affected Products : c1_firmware c1
    • EPSS Score: %0.42
    • Published: Sep. 19, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2019-2094

    In parseMPEGCCData of NuPlayerCCDecoder.cpp, there is a possible out of bounds write due to missing bounds checks. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation. Produc... Read more

    Affected Products : android
    • EPSS Score: %0.18
    • Published: Jun. 07, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-3834

    A memory corruption issue was addressed with improved state management. This issue is fixed in watchOS 6.1.2. An application may be able to execute arbitrary code with kernel privileges.... Read more

    Affected Products : watchos
    • EPSS Score: %0.37
    • Published: Feb. 27, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-5610

    Global TechStream (GTS) for TOYOTA dealers version 15.10.032 and earlier allows an attacker to cause a denial-of-service (DoS) condition and execute arbitrary code via unspecified vectors.... Read more

    Affected Products : global_techstream
    • EPSS Score: %0.25
    • Published: Jul. 30, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-11581

    An issue was discovered in Pulse Secure Pulse Connect Secure (PCS) through 2020-04-06. The applet in tncc.jar, executed on macOS, Linux, and Solaris clients when a Host Checker policy is enforced, allows a man-in-the-middle attacker to perform OS command ... Read more

    • EPSS Score: %39.32
    • Published: Apr. 06, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2014-9890

    Off-by-one error in drivers/media/platform/msm/camera_v2/sensor/cci/msm_cci.c in the Qualcomm components in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices allows attackers to gain privileges via a crafted application that sends an I2C command, ... Read more

    Affected Products : android
    • EPSS Score: %0.06
    • Published: Aug. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2020-0080

    In onOpActiveChanged and related methods of AppOpsControllerImpl.java, there is a possible way to display an app overlaying other apps without the notification icon that it's overlaying. This could lead to local escalation of privilege with User execution... Read more

    Affected Products : android
    • EPSS Score: %0.08
    • Published: Apr. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-14977

    An issue was discovered in F-Secure SAFE 17.7 on macOS. The XPC services use the PID to identify the connecting client, which allows an attacker to perform a PID reuse attack and connect to a privileged XPC service, and execute privileged commands on the ... Read more

    Affected Products : safe
    • EPSS Score: %0.80
    • Published: Jun. 23, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-1180

    Safari on Apple iPhone OS 3.1.3 for iPod touch allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long exception string in a throw statement, possibly a related issue to CVE-2009-1514.... Read more

    Affected Products : iphone_os safari
    • EPSS Score: %5.13
    • Published: Mar. 29, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2020-0267

    In WindowManager, there is a possible launch of an unexpected app due to a confused deputy. This could lead to local escalation of privilege due to launching a malicious app instead of the one the user intended, with no additional execution privileges nee... Read more

    Affected Products : android
    • EPSS Score: %0.03
    • Published: Sep. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-0387

    In manifest files of the SmartSpace package, there is a possible tapjacking vector due to a missing permission check. This could lead to local escalation of privilege and account hijacking with no additional execution privileges needed. User interaction i... Read more

    Affected Products : android
    • EPSS Score: %0.03
    • Published: Sep. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-9590

    Adobe DNG Software Development Kit (SDK) 1.5 and earlier versions have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more

    • EPSS Score: %3.63
    • Published: Jun. 26, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-9688

    Adobe Download Manager version 2.0.0.518 have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more

    Affected Products : windows download_manager
    • EPSS Score: %2.51
    • Published: Jul. 17, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-6193

    Buffer overflow in the Wi-Fi driver in Huawei P8 smartphones with software before GRA-CL00C92B363 allows attackers to cause a denial of service (system crash) or gain privileges via a crafted application, a different vulnerability than CVE-2016-6192.... Read more

    Affected Products : p8_smartphone_firmware
    • EPSS Score: %0.15
    • Published: Aug. 02, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291638 Results