Latest CVE Feed
-
9.3
HIGHCVE-2011-4876
Directory traversal vulnerability in HmiLoad in the runtime loader in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinC... Read more
Affected Products : wincc wincc_flexible simatic_hmi_panels wincc_runtime_advanced wincc_flexible_runtime- EPSS Score: %16.82
- Published: Feb. 03, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-12455
Intelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web interface just by using "admin:" as the name of a cookie.... Read more
- EPSS Score: %45.27
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2024-8752
The Windows version of WebIQ 2.15.9 is affected by a directory traversal vulnerability that allows remote attackers to read any file on the system.... Read more
- Published: Sep. 16, 2024
- Modified: Sep. 20, 2024
-
9.3
HIGHCVE-2020-4724
IBM i2 Analyst Notebook 9.2.0 and 9.2.1 could allow a local attacker to execute arbitrary code on the system, caused by a memory corruption. By persuading a victim to open a specially-crafted file, an attacker could exploit this vulnerability to execute a... Read more
Affected Products : i2_analysts_notebook- EPSS Score: %0.19
- Published: Oct. 29, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-9496
In ixheaacd_real_synth_fft_p3 of ixheaacd_esbr_fft.c there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitatio... Read more
Affected Products : android- EPSS Score: %1.22
- Published: Oct. 02, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2013-3248
Untrusted search path vulnerability in Corel PDF Fusion 1.11 allows local users to gain privileges via a Trojan horse wintab32.dll file in the current working directory, as demonstrated by a directory that contains a .pdf or .xps file.... Read more
Affected Products : pdf_fusion- EPSS Score: %58.19
- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2011-0517
Stack-based buffer overflow in Sielco Sistemi Winlog Pro 2.07.00 and earlier, when Run TCP/IP server is enabled, allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted 0x02 opcode to TCP port 46823.... Read more
Affected Products : winlog_pro- EPSS Score: %71.60
- Published: Jan. 20, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2013-3599
userlogin.jsp in Coursemill Learning Management System (LMS) 6.6 and 6.8 allows remote attackers to gain privileges via a modified user-role value to home.html.... Read more
Affected Products : coursemill_learning_management_system- EPSS Score: %0.62
- Published: Sep. 06, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-1335
From Apache Tika versions 1.7 to 1.17, clients could send carefully crafted headers to tika-server that could be used to inject commands into the command line of the server running tika-server. This vulnerability only affects those running tika-server on ... Read more
Affected Products : tika- EPSS Score: %93.17
- Published: Apr. 25, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2020-13540
An exploitable local privilege elevation vulnerability exists in the file system permissions of the Win-911 Enterprise V4.20.13 install directory via WIN-911 Account Change Utility. Depending on the vector chosen, an attacker can overwrite various executa... Read more
- EPSS Score: %0.12
- Published: Jan. 05, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2017-0797
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-62459766. References: M-ALPS03353854.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0806
An elevation of privilege vulnerability in the Android framework (gatekeeperresponse). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62998805.... Read more
Affected Products : android- EPSS Score: %1.49
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-6467
Advantech WebAccess before 8.1 allows remote attackers to execute arbitrary code via vectors involving a browser plugin.... Read more
- EPSS Score: %0.62
- Published: Jan. 15, 2016
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2013-0855
Integer overflow in the alac_decode_close function in libavcodec/alac.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a large number of samples per frame in Apple Lossless Audio Codec (ALAC) data, which triggers an out-of-... Read more
Affected Products : ffmpeg- EPSS Score: %1.19
- Published: Dec. 07, 2013
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2015-6620
libstagefright in Android before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bugs 24123723 and 24445127.... Read more
Affected Products : android- EPSS Score: %12.57
- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2019-1988
In sample6 of SkSwizzler.cpp, there is a possible out of bounds write due to improper input validation. This could lead to remote code execution in system_server with no additional execution privileges needed. User interaction is needed for exploitation. ... Read more
Affected Products : android- EPSS Score: %0.48
- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-1567
Multiple stack-based buffer overflows in the Lateral Arts Photobox uploader ActiveX control 1.x before 1.3, and 2.2.0.6, allow remote attackers to execute arbitrary code via a long URL string for the (1) LogURL, (2) ConnectURL, (3) SkinURL, (4) AlbumCreat... Read more
Affected Products : uploader_activex_control- EPSS Score: %6.22
- Published: Dec. 03, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2017-5554
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot,... Read more
- EPSS Score: %2.13
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8479
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
- EPSS Score: %0.25
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2008-7162
Buffer overflow in Hero Super Player 3000 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long filename in a .M3U file. NOTE: this might be related to CVE-2008-4504.... Read more
Affected Products : hero_super_player_3000- EPSS Score: %6.90
- Published: Sep. 04, 2009
- Modified: Apr. 09, 2025