Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2020-35798

    Certain NETGEAR devices are affected by command injection by an unauthenticated attacker. This affects R6400v2 before 1.0.4.84, R6700v3 before 1.0.4.84, R6900P before 1.3.2.124, R7000 before 1.0.11.100, R7000P before 1.3.2.124, R7800 before 1.0.2.74, R785... Read more

    • EPSS Score: %0.38
    • Published: Dec. 30, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2022-32252

    A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.1). The application does not perform the integrity check of the update packages. Without validation, an admin user might be tricked to install a malicious package, gran... Read more

    Affected Products : sinema_remote_connect_server
    • EPSS Score: %0.13
    • Published: Jun. 14, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2020-6238

    SAP Commerce, versions - 6.6, 6.7, 1808, 1811, 1905, does not process XML input securely in the Rest API from Servlet xyformsweb, leading to Missing XML Validation. This affects confidentiality and availability (partially) of SAP Commerce.... Read more

    Affected Products : commerce_cloud commerce
    • EPSS Score: %0.41
    • Published: Apr. 14, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-7922

    Huawei ALP-L09 smart phones with versions earlier than ALP-L09 8.0.0.150(C432) have an insufficient input validation vulnerability due to lack of parameter check. An attacker tricks the user who has root privilege to install a crafted application, the app... Read more

    Affected Products : alp-l09_firmware alp-l09
    • EPSS Score: %0.12
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-31588

    The zippies/testplatform repository through 2016-07-19 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : testplatform
    • EPSS Score: %0.41
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-10750

    An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using the 'staticGet <node_name attr>' function and cause ... Read more

    • EPSS Score: %0.97
    • Published: May. 04, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2015-3842

    Multiple heap-based buffer overflows in libeffects in the Audio Policy Service in mediaserver in Android before 5.1.1 LMY48I allow attackers to execute arbitrary code via a crafted application, aka internal bug 21953516.... Read more

    Affected Products : android
    • EPSS Score: %0.46
    • Published: Oct. 01, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    CRITICAL
    CVE-2023-0606

    Cross-site Scripting (XSS) - Reflected in GitHub repository ampache/ampache prior to 5.5.7.... Read more

    Affected Products : ampache
    • EPSS Score: %0.14
    • Published: Feb. 01, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2007-5279

    Heap-based buffer overflow in ConeXware PowerArchiver before 10.20.21 might allow remote attackers to execute arbitrary code via a long filename in a BlackHole archive.... Read more

    Affected Products : powerarchiver powerarchiver
    • EPSS Score: %18.33
    • Published: Oct. 09, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-8936

    The AMD EPYC Server, Ryzen, Ryzen Pro, and Ryzen Mobile processor chips allow Platform Security Processor (PSP) privilege escalation.... Read more

    • EPSS Score: %0.60
    • Published: Mar. 22, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-0679

    Multiple stack-based buffer overflows in the HyleosChemView.HLChemView ActiveX control (HyleosChemView.ocx) in Hyleos ChemView 1.9.5.1 allow remote attackers to execute arbitrary code via a large number of white space characters in the filename argument t... Read more

    Affected Products : chemview
    • EPSS Score: %73.24
    • Published: Feb. 22, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2018-9232

    Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update.... Read more

    Affected Products : be126_firmware be126
    • EPSS Score: %0.19
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2007-3400

    The NCTAudioEditor2 ActiveX control in NCTWMAFile2.dll 2.6.2.157, as distributed in NCTAudioEditor and NCTAudioStudio 2.7, allows remote attackers to overwrite arbitrary files via the CreateFile method.... Read more

    Affected Products : nctaudioeditor nctaudiostudio
    • EPSS Score: %6.42
    • Published: Jun. 26, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-9490

    In CollectValuesOrEntriesImpl of elements.cc, there is possible remote code execution due to type confusion. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Pro... Read more

    Affected Products : android
    • EPSS Score: %0.32
    • Published: Oct. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9521

    In parseMPEGCCData of NuPlayer2CCDecoder.cpp, there is a possible out of bounds write due to an incorrect bounds check. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is... Read more

    Affected Products : android
    • EPSS Score: %0.48
    • Published: Nov. 14, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9571

    In impd_parse_loud_eq_instructions of impd_drc_dynamic_payload.c there is a possible out-of-bound write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for ex... Read more

    Affected Products : android
    • EPSS Score: %0.37
    • Published: Dec. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9577

    In impd_parametric_drc_parse_gain_set_params of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is nee... Read more

    Affected Products : android
    • EPSS Score: %0.18
    • Published: Dec. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9574

    In impd_parse_split_drc_characteristic of impd_drc_static_payload.c there is a possible out of bounds write due to missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed fo... Read more

    Affected Products : android
    • EPSS Score: %0.18
    • Published: Dec. 07, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-4723

    Smarty before 3.0.0, when security is enabled, does not prevent access to the (1) dynamic and (2) private object members of an assigned object, which has unspecified impact and remote attack vectors.... Read more

    Affected Products : smarty
    • EPSS Score: %0.43
    • Published: Feb. 03, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2013-0742

    Stack-based buffer overflow in Corel PDF Fusion 1.11 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a long ZIP directory entry name in an XPS file.... Read more

    Affected Products : pdf_fusion
    • EPSS Score: %76.06
    • Published: Oct. 03, 2013
    • Modified: Apr. 11, 2025
Showing 20 of 291717 Results