Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2024-9166

    The device enables an unauthorized attacker to execute system commands with elevated privileges. This exploit is facilitated through the use of the 'getcommand' query within the application, allowing the attacker to gain root access.... Read more

    Affected Products :
    • Published: Sep. 26, 2024
    • Modified: Sep. 30, 2024
  • 9.3

    HIGH
    CVE-2013-0654

    CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.... Read more

    • EPSS Score: %0.73
    • Published: Jan. 27, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2008-2684

    The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: s... Read more

    Affected Products : black_ice_barcode_sdk
    • EPSS Score: %10.36
    • Published: Jun. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2019-1641

    A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more

    • EPSS Score: %0.30
    • Published: Jan. 23, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-2348

    Stack-based buffer overflow in Batch Audio Converter Lite Edition 1.0.0.0 and earlier allows remote attackers to execute arbitrary code via a long line in a .WAV file.... Read more

    Affected Products : batch_audio_converter
    • EPSS Score: %6.93
    • Published: Jun. 21, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2011-4201

    remote_support.cgi in the Tadasoft Restorepoint 3.2 evaluation image allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) pid1 or (2) pid2 parameter in a stop_remote_support action.... Read more

    Affected Products : restorepoint
    • EPSS Score: %1.02
    • Published: Dec. 13, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2009-5109

    Stack-based buffer overflow in Mini-Stream Ripper 3.0.1.1 allows remote attackers to execute arbitrary code via a long entry in a .pls file.... Read more

    Affected Products : ripper
    • EPSS Score: %62.22
    • Published: Dec. 25, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2015-6621

    SystemUI in Android 5.x before 5.1.1 LMY48Z and 6.0 before 2015-12-01 allows attackers to gain privileges via a crafted application, as demonstrated by obtaining Signature or SignatureOrSystem access, aka internal bug 23909438.... Read more

    Affected Products : android
    • EPSS Score: %0.16
    • Published: Dec. 08, 2015
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-6637

    The MediaTek misc-sd driver in Android before 5.1.1 LMY49F and 6.0 before 2016-01-01 allows attackers to gain privileges via a crafted application, aka internal bug 25307013.... Read more

    Affected Products : android
    • EPSS Score: %0.07
    • Published: Jan. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2009-1260

    Multiple stack-based buffer overflows in UltraISO 9.3.3.2685 and earlier allow remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted (1) CCD or (2) IMG file.... Read more

    Affected Products : ultraiso
    • EPSS Score: %74.52
    • Published: Apr. 07, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-0509

    Multiple unspecified vulnerabilities in MaklerPlus before 1.2 have unknown impact and attack vectors, possibly relating to cross-site scripting (XSS) in the slogan parameter in main.tpl, or information leaks in error messages.... Read more

    Affected Products : maklerplus
    • EPSS Score: %0.64
    • Published: Jan. 26, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2010-2434

    Buffer overflow in Arcext.dll 2.16.1 and earlier in pon software Explzh 5.62 and earlier allows remote attackers to execute arbitrary code via an LZH LHA file with a crafted header that is not properly handled during expansion.... Read more

    Affected Products : explzh
    • EPSS Score: %6.80
    • Published: Jun. 25, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2012-4865

    Buffer overflow in Oreans Themida 2.1.8.0 allows remote attackers to execute arbitrary code via a crafted .TMD file.... Read more

    Affected Products : themida
    • EPSS Score: %28.76
    • Published: Sep. 06, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2010-2590

    Heap-based buffer overflow in the CrystalReports12.CrystalPrintControl.1 ActiveX control in PrintControl.dll 12.3.2.753 in SAP Crystal Reports 2008 SP3 Fix Pack 3.2 allows remote attackers to execute arbitrary code via a long ServerResourceVersion propert... Read more

    Affected Products : crystal_reports
    • EPSS Score: %71.78
    • Published: Dec. 22, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2007-3210

    Stack-based buffer overflow in nptoken.mox in the Cellosoft Tokens Object 2.0.0.6 extension for Vitalize! allows remote attackers to execute arbitrary code via a long string argument to the RemoveChr method. NOTE: the provenance of this information is un... Read more

    Affected Products : cellosoft_tokens_object
    • EPSS Score: %4.14
    • Published: Jun. 14, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2007-2864

    Stack-based buffer overflow in the Anti-Virus engine before content update 30.6 in multiple CA (formerly Computer Associates) products allows remote attackers to execute arbitrary code via a large invalid value of the coffFiles field in a .CAB file.... Read more

    • EPSS Score: %79.93
    • Published: Jun. 06, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2010-3155

    Untrusted search path vulnerability in Adobe ExtendScript Toolkit (ESTK) CS5 3.5.0.52 allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse dwmapi.dll that is located in the same ... Read more

    Affected Products : extendedscript_toolkit_cs5
    • EPSS Score: %3.34
    • Published: Aug. 27, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2010-3150

    Untrusted search path vulnerability in Adobe Premier Pro CS4 4.0.0 (314 (MC: 160820)) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse ibfs32.dll that is located in the same ... Read more

    Affected Products : premier_pro_cs4
    • EPSS Score: %3.48
    • Published: Aug. 27, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2016-1894

    NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.... Read more

    Affected Products : oncommand_workflow_automation
    • EPSS Score: %0.41
    • Published: Feb. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2012-5360

    Libavcodec in FFmpeg before 0.11 allows remote attackers to execute arbitrary code via a crafted QT file.... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.79
    • Published: Feb. 08, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 291804 Results