Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2019-1988

    In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitation. ... Read more

    Affected Products : android
    • EPSS Score: %0.48
    • Published: Feb. 28, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-1567

    Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreat... Read more

    Affected Products : uploader_activex_control
    • EPSS Score: %6.22
    • Published: Dec. 03, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2017-5554

    An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot,... Read more

    Affected Products : oxygenos oneplus_3 oneplus_3t
    • EPSS Score: %2.13
    • Published: Jan. 23, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2016-8479

    An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more

    Affected Products : android linux_kernel
    • EPSS Score: %0.25
    • Published: Mar. 08, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2008-7162

    Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.... Read more

    Affected Products : hero_super_player_3000
    • EPSS Score: %6.90
    • Published: Sep. 04, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2015-6033

    Qolsys IQ Panel (aka QOL) before 1.5.1 does not verify the digital signatures of software updates, which allows man-in-the-middle attackers to bypass intended access restrictions via a modified update.... Read more

    Affected Products : iq_panel
    • EPSS Score: %0.13
    • Published: Oct. 31, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2018-15418

    A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more

    • EPSS Score: %0.23
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-31501

    The ChaoticOnyx/OnyxForum repository before 2022-05-04 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : onyxforum
    • EPSS Score: %0.46
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-2884

    PHP remote file inclusion vulnerability in display.php in RSS-aggregator allows remote attackers to execute arbitrary PHP code via a URL in the path parameter. NOTE: some of these details are obtained from third party information.... Read more

    Affected Products : rss_aggregator
    • EPSS Score: %1.72
    • Published: Jun. 27, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2022-31543

    The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : setupbox
    • EPSS Score: %0.41
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2017-11344

    Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-... Read more

    • EPSS Score: %1.19
    • Published: Jul. 17, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2014-9789

    The (1) alloc and (2) free APIs in arch/arm/mach-msm/qdsp6v2/msm_audio_ion.c in the Qualcomm components in Android before 2016-07-05 on Nexus 5 devices do not validate parameters, which allows attackers to gain privileges via a crafted application, aka An... Read more

    Affected Products : android
    • EPSS Score: %0.06
    • Published: Jul. 11, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2007-1771

    PHP remote file inclusion vulnerability in manage/javascript/formjavascript.php in Ay System Solutions Web Content System (WCS) 2.7.1 allows remote attackers to execute arbitrary PHP code via a URL in the path[JavascriptEdit] parameter.... Read more

    Affected Products : web_content_system
    • EPSS Score: %4.29
    • Published: Mar. 30, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2013-7186

    Buffer overflow in Steinberg MyMp3PRO 5.0 (Build 5.1.0.21) allows remote attackers to execute arbitrary code via a long string in a .m3u file.... Read more

    Affected Products : mymp3pro
    • EPSS Score: %33.67
    • Published: Dec. 20, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2009-0476

    Stack-based buffer overflow in MultiMedia Soft AdjMmsEng.dll 7.11.1.0 and 7.11.2.7, as distributed in multiple MultiMedia Soft audio components for .NET, allows remote attackers to execute arbitrary code via a long string in a playlist (.pls) file, as ori... Read more

    • EPSS Score: %83.26
    • Published: Feb. 08, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2012-0269

    Buffer overflow in JustSystems Ichitaro 2011 Sou, Ichitaro 2006 through 2011, Ichitaro Government 2006 through 2010, Ichitaro Portable with oreplug, Ichitaro Viewer, JUST School, JUST School 2009 and 2010, JUST Jump 4, JUST Frontier, oreplug, Shuriken Pro... Read more

    • EPSS Score: %10.43
    • Published: Apr. 27, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2007-4421

    SQL injection vulnerability in Admin.php in Olate Download (od) 3.4.1 allows remote attackers to execute arbitrary SQL commands via an OD3_AutoLogin cookie.... Read more

    Affected Products : olatedownload
    • EPSS Score: %2.73
    • Published: Aug. 18, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2015-8940

    Integer overflow in sound/soc/msm/qdsp6v2/q6lsm.c in the Qualcomm components in Android before 2016-08-05 on Nexus 6 devices allows attackers to gain privileges via a crafted application, aka Android internal bug 28813987 and Qualcomm internal bug CR79236... Read more

    Affected Products : android
    • EPSS Score: %0.06
    • Published: Aug. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2013-3480

    Integer overflow in Sagelight 4.4 and earlier allows remote attackers to execute arbitrary code via crafted width and height dimensions in a BMP file, which triggers a heap-based buffer overflow.... Read more

    Affected Products : sagelight
    • EPSS Score: %10.52
    • Published: Aug. 09, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2011-4875

    Stack-based buffer overflow in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flex... Read more

    • EPSS Score: %41.05
    • Published: Feb. 03, 2012
    • Modified: Apr. 11, 2025
Showing 20 of 292387 Results