Latest CVE Feed
-
9.3
HIGHCVE-2016-10435
In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Automobile, Snapdragon Mobile, and Snapdragon Wear MDM9206, MDM9625, MDM9635M, MDM9640, MDM9645, MSM8909W, SD 210/SD 212/SD 205, SD 400, SD 410/12, SD 425, SD 430, SD 450,... Read more
Affected Products : sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware msm8909w_firmware mdm9206_firmware mdm9635m_firmware mdm9640_firmware mdm9645_firmware mdm9625_firmware +42 more products- EPSS Score: %0.17
- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-11457
A vulnerability has been identified in SINUMERIK 828D V4.7 (All versions < V4.7 SP6 HF1), SINUMERIK 840D sl V4.7 (All versions < V4.7 SP6 HF5), SINUMERIK 840D sl V4.8 (All versions < V4.8 SP3). The integrated web server on port 4842/tcp of the affected pr... Read more
- EPSS Score: %1.26
- Published: Dec. 12, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-26912
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.... Read more
Affected Products : netmotion_mobility- EPSS Score: %35.43
- Published: Feb. 08, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2016-10591
Prince is a Node API for executing XML/HTML to PDF renderer PrinceXML via prince(1) CLI. prince downloads zipped resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the r... Read more
Affected Products : prince- EPSS Score: %0.77
- Published: May. 29, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-3139
Untrusted search path vulnerability in Microsoft Windows Progman Group Converter (grpconv.exe) allows local users, and possibly remote attackers, to execute arbitrary code and conduct DLL hijacking attacks via a Trojan horse imm.dll that is located in the... Read more
Affected Products : windows- EPSS Score: %17.05
- Published: Aug. 27, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2016-10643
jstestdriver is a wrapper for Google's jstestdriver. jstestdriver downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attack... Read more
Affected Products : jstestdriver- EPSS Score: %0.77
- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2022-21817
NVIDIA Omniverse Launcher contains a Cross-Origin Resource Sharing (CORS) vulnerability which can allow an unprivileged remote attacker, if they can get user to browse malicious site, to acquire access tokens allowing them to access resources in other sec... Read more
- EPSS Score: %0.91
- Published: Feb. 02, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2019-2132
It is possible to overlay the VPN dialog by a malicious application. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: Android-7.0 Andr... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 20, 2019
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2010-1273
Emweb Wt before 3.1.1 does not validate the UTF-8 encoding of (1) form values and (2) JSignal arguments, which has unspecified impact and remote attack vectors.... Read more
Affected Products : wt- EPSS Score: %0.40
- Published: Apr. 06, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2021-35062
A Shell Metacharacter Injection vulnerability in result.php in DRK Odenwaldkreis Testerfassung March-2021 allow an attacker with a valid token of a COVID-19 test result to execute shell commands with the permissions of the web server.... Read more
- EPSS Score: %0.31
- Published: Aug. 30, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2011-4219
Investintech.com SlimPDF Reader does not prevent faulting-address data from affecting branch selection, which allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted PDF document.... Read more
Affected Products : slimpdf_reader- EPSS Score: %2.79
- Published: Nov. 01, 2011
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-5210
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock information (PIN, password, or pattern... Read more
Affected Products : samsung_mobile- EPSS Score: %1.36
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-33256
A CSV injection vulnerability on the login panel of ManageEngine ADSelfService Plus Version: 6.1 Build No: 6101 can be exploited by an unauthenticated user. The j_username parameter seems to be vulnerable and a reverse shell could be obtained if a privile... Read more
Affected Products : manageengine_adselfservice_plus- EPSS Score: %16.30
- Published: Aug. 09, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-35082
Improper integrity check can lead to race condition between tasks PDCP and RRC? right after a valid RRC security mode command packet has been received in Snapdragon Industrial IOT... Read more
- EPSS Score: %0.17
- Published: Jun. 14, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-22710
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (C... Read more
Affected Products : interactive_graphical_scada_system- EPSS Score: %0.70
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-37563
MediaTek microchips, as used in NETGEAR devices through 2021-11-11 and other devices, mishandle the WPS (Wi-Fi Protected Setup) protocol. (Affected Chipsets MT7603E, MT7610, MT7612, MT7613, MT7615, MT7620, MT7622, MT7628, MT7629, MT7915; Affected Software... Read more
Affected Products : mt7613_firmware mt7615_firmware mt7622_firmware mt7628_firmware mt7629_firmware mt7915_firmware mt7603e_firmware mt7612_firmware mt7620_firmware mt7610_firmware +10 more products- EPSS Score: %0.55
- Published: Dec. 26, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-42635
PrinterLogic Web Stack versions 19.1.1.13 SP9 and below use a hardcoded APP_KEY value, leading to pre-auth remote code execution.... Read more
- EPSS Score: %23.53
- Published: Jan. 31, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-37803
An SQL Injection vulnerability exists in Sourcecodester Online Covid Vaccination Scheduler System 1.0 via the username in lognin.php .... Read more
Affected Products : online_covid_vaccination_scheduler_system- EPSS Score: %0.32
- Published: Oct. 27, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2021-39692
In onCreate of SetupLayoutActivity.java, there is a possible way to setup a work profile bypassing user consent due to a tapjacking/overlay attack. This could lead to local escalation of privilege with User execution privileges needed. User interaction is... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Mar. 16, 2022
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2018-6267
NVIDIA Tegra OpenMax driver (libnvomx) contains a vulnerability in which the software does not validate or incorrectly validates input that can affect the control flow or data flow of a program, which may lead to denial of service or escalation of privile... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Feb. 13, 2019
- Modified: Nov. 21, 2024