Latest CVE Feed
-
10.0
CRITICALCVE-2017-5145
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5162
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Lack of authentication for remote service gives access to application set up and configuration.... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2021-30116
Kaseya VSA before 9.5.7 allows credential disclosure, as exploited in the wild in July 2021. By default Kaseya VSA on premise offers a download page where the clients for the installation can be downloaded. The default URL for this page is https://x.x.x.x... Read more
- Actively Exploited
- Published: Jul. 09, 2021
- Modified: Mar. 14, 2025
-
10.0
HIGHCVE-2017-4997
EMC VASA Provider Virtual Appliance versions 8.3.x and prior has an unauthenticated remote code execution vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : emc_vasa_provider_virtual_appliance- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-4982
EMC Mainframe Enablers ResourcePak Base versions 7.6.0, 8.0.0, and 8.1.0 contains a fix for a privilege management vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : mainframe_enablers_resourcepak_base- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2020-4415
IBM Spectrum Protect 7.1 and 8.1 server is vulnerable to a stack-based buffer overflow, caused by improper bounds checking. This could allow a remote attacker to execute arbitrary code on the system with the privileges of an administrator or user associat... Read more
Affected Products : spectrum_protect- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3742
Adobe Acrobat and Reader versions, 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3531
A vulnerability in the REST API of Cisco IoT Field Network Director (FND) could allow an unauthenticated, remote attacker to access the back-end database of an affected system. The vulnerability exists because the affected software does not properly authe... Read more
Affected Products : iot_field_network_director- Published: Nov. 18, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-4918
VMware Horizon View Client (2.x, 3.x and 4.x prior to 4.5.0) contains a command injection vulnerability in the service startup script. Successful exploitation of this issue may allow unprivileged users to escalate their privileges to root on the Mac OSX s... Read more
Affected Products : horizon_view- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2020-28623
Multiple code execution vulnerabilities exists in the Nef polygon-parsing functionality of CGAL libcgal CGAL-5.1.1. A specially crafted malformed file can lead to an out-of-bounds read and type confusion, which could lead to code execution. An attacker ca... Read more
- Published: Apr. 18, 2022
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-47039
In isSlotMarkedSuccessful of BootControl.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploi... Read more
Affected Products : android- Published: Dec. 18, 2024
- Modified: Jul. 24, 2025
-
10.0
CRITICALCVE-2024-47038
In dhd_prot_flowrings_pool_release of dhd_msgbuf.c, there is a possible outcof bounds write due to a missing bounds check. This could lead to localcescalation of privilege with no additional execution privileges needed. Usercinteraction is not needed for ... Read more
Affected Products : android- Published: Dec. 18, 2024
- Modified: Jul. 24, 2025
-
10.0
HIGHCVE-2020-25223
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11... Read more
- Actively Exploited
- Published: Sep. 25, 2020
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2020-1946
In Apache SpamAssassin before 3.4.5, malicious rule configuration (.cf) files can be configured to run system commands without any output or errors. With this, exploits can be injected in a number of scenarios. In addition to upgrading to SA version 3.4.5... Read more
- Published: Mar. 25, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2020-12522
The reported vulnerability allows an attacker who has network access to the device to execute code with specially crafted packets in WAGO Series PFC 100 (750-81xx/xxx-xxx), Series PFC 200 (750-82xx/xxx-xxx), Series Wago Touch Panel 600 Standard Line (762-... Read more
- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7971
Adobe Photoshop CC versions 19.1.8 and earlier and 20.0.5 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- Published: Aug. 26, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7959
Creative Cloud Desktop Application versions 4.6.1 and earlier have a using components with known vulnerabilities vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- Published: Aug. 16, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7112
Adobe Acrobat and Reader versions 2019.010.20098 and earlier, 2019.010.20098 and earlier, 2017.011.30127 and earlier version, and 2015.006.30482 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code executi... Read more
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7102
Adobe Shockwave Player versions 12.3.4.204 and earlier have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- Published: May. 23, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-7086
Adobe Acrobat and Reader versions 2019.010.20069 and earlier, 2019.010.20069 and earlier, 2017.011.30113 and earlier version, and 2015.006.30464 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code executio... Read more
- Published: May. 24, 2019
- Modified: Nov. 21, 2024