Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    CRITICAL
    CVE-2022-31552

    The project-anuvaad/anuvaad-corpus repository through 2020-11-23 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : anuvaad-corpus
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-31556

    The rusyasoft/TrainEnergyServer repository through 2017-08-03 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.... Read more

    Affected Products : trainenergyserver
    • Published: Jul. 11, 2022
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-5073

    Heap-based buffer overflow in an ActiveX control in Novell ZENworks Desktop Management 6.5 allows remote attackers to execute arbitrary code via a long argument to the CanUninstall method.... Read more

    Affected Products : zenworks_desktop_management
    • Published: Nov. 14, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2020-3925

    A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted sc... Read more

    Affected Products : windows servisign
    • Published: Feb. 03, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    CRITICAL
    CVE-2022-33232

    Memory corruption due to buffer copy without checking size of input while running memory sharing tests with large scattered memory.... Read more

    • Published: Feb. 12, 2023
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2018-9551

    In CAacDecoder_Init of aacdecoder.cpp, there is a possible out-of-bound write due to a missing bounds check. This could lead to remote code execution in the media server with no additional execution privileges needed. User interaction is needed for exploi... Read more

    Affected Products : android
    • Published: Dec. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2011-0500

    Buffer overflow in VideoSpirit Pro 1.6.8.1, 1.68, and earlier; and VideoSpirit Lite 1.4.0.1 and possibly other versions; allows user-assisted remote attackers to execute arbitrary code via a VideoSpirit project (.visprj) file containing a valitem element ... Read more

    Affected Products : videospirit_lite videospirit_pro
    • Published: Jan. 20, 2011
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2017-0679

    A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-36996978.... Read more

    Affected Products : android
    • Published: Jul. 06, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-0805

    A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.... Read more

    Affected Products : android
    • Published: Aug. 24, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2019-1639

    A vulnerability in the Cisco Webex Network Recording Player for Microsoft Windows and the Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerability exist because the affected softwa... Read more

    • Published: Jan. 23, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2007-6082

    Direct static code injection vulnerability in acp/savenews.php in Sciurus Hosting Panel, possibly 2.0.3, allows remote attackers to inject arbitrary PHP code via the filecontents parameter, which can be executed by accessing includes/news.php.... Read more

    Affected Products : sciurus_hosting_panel
    • Published: Nov. 22, 2007
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2013-0859

    The add_doubles_metadata function in libavcodec/tiff.c in FFmpeg before 1.1 allows remote attackers to have an unspecified impact via a negative or zero count value in a TIFF image, which triggers an out-of-bounds array access.... Read more

    Affected Products : ffmpeg
    • Published: Dec. 07, 2013
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2012-1264

    Unspecified vulnerability in Gretech GOM Media Player before 2.1.37.5091 allows remote attackers to execute arbitrary code via a crafted AVI file.... Read more

    Affected Products : gom_media_player
    • Published: Mar. 18, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2018-6268

    NVIDIA Tegra library contains a vulnerability in libnvmmlite_video.so, where referencing memory after it has been freed may lead to denial of service or possible escalation of privileges. Android ID: A-80433161.... Read more

    Affected Products : android
    • Published: Feb. 13, 2019
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2010-2343

    Stack-based buffer overflow in D.R. Software Audio Converter 8.1, 2007, and 8.05 allows remote attackers to execute arbitrary code via a crafted pls playlist file.... Read more

    Affected Products : audio_converter
    • Published: Jun. 21, 2010
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2012-4864

    Oreans WinLicense 2.1.8.0 allows remote attackers to cause a denial of service (memory corruption and crash) and possibly execute arbitrary code via a crafted xml file.... Read more

    Affected Products : winlicense
    • Published: Sep. 06, 2012
    • Modified: Apr. 11, 2025
  • 9.3

    HIGH
    CVE-2016-10581

    Steroids is PhoneGap on Steroids, providing native UI elements, multiple WebViews and enhancements for better developer productivity. steroids downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause re... Read more

    Affected Products : steroids
    • Published: Jun. 01, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2009-3807

    Stack-based buffer overflow in MixVibes 7.043 Pro allows remote attackers to cause a denial of service (crash) via a long string in a .vib file.... Read more

    Affected Products : mixvibes
    • Published: Oct. 27, 2009
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2016-6758

    An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to ... Read more

    Affected Products : android linux_kernel
    • Published: Jan. 12, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2010-2701

    Multiple buffer overflows in the FathFTP ActiveX control 1.7 allow remote attackers to execute arbitrary code via (1) the GetFromURL member or (2) a long argument to the RasIsConnected method.... Read more

    Affected Products : fathftp
    • Published: Jul. 12, 2010
    • Modified: Apr. 11, 2025
Showing 20 of 292801 Results