Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2013-3027

    Integer overflow in the DWA9W ActiveX control in iNotes in IBM Domino 9.0 before IF3 allows remote attackers to execute arbitrary code via a crafted web page, aka SPR PTHN97XHFW.... Read more

    Affected Products : lotus_domino
    • EPSS Score: %4.40
    • Published: Aug. 09, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2008-4321

    Buffer overflow in FlashGet (formerly JetCar) FTP 1.9 allows remote FTP servers to execute arbitrary code via a long response to the PWD command.... Read more

    Affected Products : flashget_ftp
    • EPSS Score: %36.20
    • Published: Sep. 29, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2020-13259

    A vulnerability in the web-based management interface of RAD SecFlow-1v os-image SF_0290_2.3.01.26 could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. The vulnerability is due to ins... Read more

    Affected Products : secflow-1v_firmware secflow-1v
    • EPSS Score: %1.04
    • Published: Sep. 16, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2020-5760

    Grandstream HT800 series firmware version 1.0.17.5 and below is vulnerable to an OS command injection vulnerability. Unauthenticated remote attackers can execute arbitrary commands as root by crafting a special configuration file and sending a crafted SIP... Read more

    • EPSS Score: %3.94
    • Published: Jul. 29, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9083

    In System Management Module (SMM) versions prior to 1.06, the SMM contains weak default root credentials which could be used to log in to the device OS -- if the attacker manages to enable SSH or Telnet connections via some other vulnerability.... Read more

    • EPSS Score: %0.36
    • Published: Nov. 27, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2006-7046

    PHP remote file inclusion vulnerability in cmpro.intern/login.inc.php for Clan Manager Pro (CMPRO) 1.1.0 allows remote attackers to execute arbitrary PHP code via a URL in the rootpath parameter. NOTE: the provenance of this information is unknown; the d... Read more

    Affected Products : clan_manager_pro
    • EPSS Score: %0.69
    • Published: Feb. 24, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2017-0604

    An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent ... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: May. 12, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    CRITICAL
    CVE-2020-13536

    An exploitable local privilege elevation vulnerability exists in the file system permissions of Moxa MXView series 3.1.8 installation. Depending on the vector chosen, an attacker can either add code to a script or replace a binary. By default MXViewServic... Read more

    Affected Products : mxview
    • EPSS Score: %0.03
    • Published: Nov. 05, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2006-7185

    PHP remote file inclusion vulnerability in includes/user_standard.php in CMSmelborp Beta allows remote attackers to execute arbitrary PHP code via a URL in the relative_root parameter.... Read more

    Affected Products : cmsmelborp
    • EPSS Score: %4.16
    • Published: Mar. 30, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2017-0675

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.... Read more

    Affected Products : android
    • EPSS Score: %0.21
    • Published: Jul. 06, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-0684

    A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: Jul. 06, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2007-0020

    Heap-based buffer overflow in the SFTP protocol handler for Panic Transmit (Transmit.app) up to 3.5.5 allows remote attackers to execute arbitrary code via a long ftps:// URL.... Read more

    Affected Products : panic_transmit
    • EPSS Score: %7.34
    • Published: Jan. 24, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2018-13806

    A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to execute code with the permission of the user running TD D... Read more

    Affected Products : td_keypad_designer
    • EPSS Score: %0.23
    • Published: Sep. 12, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2024-9166

    The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.... Read more

    Affected Products :
    • Published: Sep. 26, 2024
    • Modified: Sep. 30, 2024
  • 9.3

    HIGH
    CVE-2013-0654

    CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.... Read more

    • EPSS Score: %0.73
    • Published: Jan. 27, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2008-2684

    The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: s... Read more

    Affected Products : black_ice_barcode_sdk
    • EPSS Score: %10.36
    • Published: Jun. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2019-1641

    A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more

    • EPSS Score: %0.30
    • Published: Jan. 23, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-2348

    Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.... Read more

    Affected Products : batch_audio_converter
    • EPSS Score: %6.93
    • Published: Jun. 21, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2011-4201

    remote_support.cgi in the Tadasoft Restorepoint 3.2 evaluation image allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) pid1 or (2) pid2 parameter in a stop_remote_support action.... Read more

    Affected Products : restorepoint
    • EPSS Score: %1.02
    • Published: Dec. 13, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2009-5109

    Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.... Read more

    Affected Products : ripper
    • EPSS Score: %62.22
    • Published: Dec. 25, 2011
    • Modified: Apr. 11, 2025
Showing 20 of 291728 Results