Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2010-3199

    Untrusted search path vulnerability in TortoiseSVN 1.6.10, Build 19898 and earlier allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same fol... Read more

    Affected Products : tortoisesvn
    • EPSS Score: %2.72
    • Published: Sep. 10, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2021-34083

    Google-it is a Node.js package which allows its users to send search queries to Google and receive the results in a JSON format. When using the 'Open in browser' option in versions up to 1.6.2, google-it will unsafely concat the result's link retrieved fr... Read more

    Affected Products : google-it
    • EPSS Score: %0.58
    • Published: Jun. 02, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-10664

    mystem is a Node.js wrapper for MyStem morphology text analyzer by Yandex.ru mystem downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested bin... Read more

    Affected Products : mystem
    • EPSS Score: %0.77
    • Published: Jun. 04, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2011-4012

    Cisco IOS 12.0, 15.0, and 15.1, when a Policy Feature Card 3C (PFC3C) is used, does not create a fragment entry during processing of an ICMPv6 ACL, which has unspecified impact and remote attack vectors, aka Bug ID CSCtj90091.... Read more

    Affected Products : ios
    • EPSS Score: %0.33
    • Published: May. 02, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2022-24532

    HEVC Video Extensions Remote Code Execution Vulnerability... Read more

    Affected Products : hevc_video_extensions
    • EPSS Score: %1.76
    • Published: Apr. 15, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-4470

    Stack-based buffer overflow in Numark CUE 5.0 rev2 allows user-assisted attackers to cause a denial of service (application crash) or execute arbitrary code via an M3U playlist file that contains a long absolute pathname.... Read more

    Affected Products : cue
    • EPSS Score: %7.28
    • Published: Oct. 07, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-4471

    Directory traversal vulnerability in the CExpressViewerControl class in the DWF Viewer ActiveX control (AdView.dll 9.0.0.96), as used in Revit Architecture 2009 SP2 and Autodesk Design Review 2009, allows remote attackers to overwrite arbitrary files via ... Read more

    • EPSS Score: %6.25
    • Published: Oct. 07, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-4499

    Multiple directory traversal vulnerabilities in PHP Web Explorer 0.99b and earlier allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the (1) refer parameter to main.php and the (2) file parameter to edit.php.... Read more

    Affected Products : php_web_explorer_lite
    • EPSS Score: %2.05
    • Published: Oct. 09, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2011-4496

    Buffer overflow in Aviosoft DTV Player 1.0.1.2 allows remote attackers to execute arbitrary code via a crafted .plf (aka playlist) file.... Read more

    Affected Products : dtv_player
    • EPSS Score: %6.62
    • Published: Nov. 21, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2018-17896

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify infor... Read more

    • EPSS Score: %0.25
    • Published: Oct. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2021-37560

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software... Read more

    • EPSS Score: %0.55
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2021-37566

    MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle IEEE 1905 protocols. (Affected Chipsets MT7603E, MT7610, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software Versions 2.0.2; Out-of-bound... Read more

    • EPSS Score: %0.55
    • Published: Dec. 26, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2019-4071

    IBM Tivoli Storage Productivity Center (IBM Spectrum Control Standard Edition 5.2.1 through 5.2.17) could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of csv file contents. IBM X-Force ID: 157063.... Read more

    • EPSS Score: %1.73
    • Published: May. 09, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2014-2262

    Buffer overflow in the client application in Base SAS 9.2 TS2M3, SAS 9.3 TS1M1 and TS1M2, and SAS 9.4 TS1M0 allows user-assisted remote attackers to execute arbitrary code via a crafted SAS program.... Read more

    Affected Products : base_sas
    • EPSS Score: %8.35
    • Published: Mar. 01, 2014
    • Modified: Apr. 12, 2025
  • 9.3

    CRITICAL
    CVE-2022-31537

    The jmcginty15/Solar-system-simulator repository through 2021-07-26 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : solar-system-simulator
    • EPSS Score: %0.41
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2021-41274

    solidus_auth_devise provides authentication services for the Solidus webstore framework, using the Devise gem. In affected versions solidus_auth_devise is subject to a CSRF vulnerability that allows user account takeover. All applications using any versio... Read more

    Affected Products : solidus_auth_devise
    • EPSS Score: %0.11
    • Published: Nov. 17, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-5753

    Stack-based buffer overflow in BulletProof FTP Client 2.63 and 2010 allows user-assisted attackers to execute arbitrary code via a bookmark file entry with a long host name, which appears as a host parameter within the quick-connect bar.... Read more

    Affected Products : bulletproof_ftp_client
    • EPSS Score: %27.78
    • Published: Dec. 30, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2010-4149

    Directory traversal vulnerability in FreshWebMaster Fresh FTP 5.36, 5.37, and possibly earlier, allows remote FTP servers to write arbitrary files via a "..\" (dot dot backslash) in a filename. NOTE: some of these details are obtained from third party in... Read more

    Affected Products : fresh_ftp
    • EPSS Score: %0.28
    • Published: Nov. 02, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2016-8386

    An exploitable heap-based buffer overflow exists in Iceni Argus. When it attempts to convert a PDF containing a malformed font to XML, the tool will attempt to use a size out of the font to search through a linked list of buffers to return. Due to a signe... Read more

    Affected Products : argus
    • EPSS Score: %0.95
    • Published: Feb. 27, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    CRITICAL
    CVE-2020-13537

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary.By default MXViewService... Read more

    Affected Products : mxview
    • EPSS Score: %0.03
    • Published: Nov. 05, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291728 Results