Latest CVE Feed
-
9.3
HIGHCVE-2018-0103
A Buffer Overflow vulnerability in Cisco WebEx Network Recording Player for Advanced Recording Format (ARF) files could allow a local attacker to execute arbitrary code on the system of a user. The attacker could exploit this vulnerability by sending the ... Read more
- EPSS Score: %0.38
- Published: Jan. 04, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-1671
Multiple buffer overflows in the Deployment Toolkit ActiveX control in deploytk.dll 6.0.130.3 in Sun Java SE Runtime Environment (aka JRE) 6 Update 13 allow remote attackers to execute arbitrary code via a long string argument to the (1) setInstallerType,... Read more
Affected Products : jre- EPSS Score: %6.71
- Published: May. 18, 2009
- Modified: Apr. 09, 2025
-
9.3
CRITICALCVE-2025-32778
Web-Check is an all-in-one OSINT tool for analyzing any website. A command injection vulnerability exists in the screenshot API of the Web Check project (Lissy93/web-check). The issue stems from user-controlled input (url) being passed unsanitized into a ... Read more
Affected Products :- Published: Apr. 15, 2025
- Modified: Apr. 16, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2025-41370
A SQL injection vulnerability has been found in Gandia Integra Total of TESI from version 2.1.2217.3 to v4.4.2236.1. The vulnerability allows an authenticated attacker to retrieve, create, update and delete databases through the 'idestudio' parameter in /... Read more
Affected Products :- Published: Aug. 01, 2025
- Modified: Aug. 04, 2025
- Vuln Type: Injection
-
9.3
CRITICALCVE-2024-1143
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.... Read more
Affected Products : central_dogma- EPSS Score: %0.28
- Published: Feb. 02, 2024
- Modified: Jun. 03, 2025
-
9.3
HIGHCVE-2009-1640
Stack-based buffer overflow in Nucleus Data Recovery Kernel Recovery for Macintosh 4.04 allows user-assisted attackers to execute arbitrary code via a crafted .AMHH file.... Read more
Affected Products : kernel_recovery- EPSS Score: %1.43
- Published: May. 15, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2261
PeaZIP 2.6.1, 2.5.1, and earlier on Windows allows user-assisted remote attackers to execute arbitrary commands via a .zip archive with a .txt file whose name contains | (pipe) characters and a command.... Read more
Affected Products : peazip- EPSS Score: %70.59
- Published: Jun. 30, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-2396
PHP remote file inclusion vulnerability in template/album.php in DM Albums 1.9.2, as used standalone or as a WordPress plugin, allows remote attackers to execute arbitrary PHP code via a URL in the SECURITY_FILE parameter.... Read more
- EPSS Score: %1.89
- Published: Jul. 09, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2018-0649
Untrusted search path vulnerability in the installers of multiple Canon IT Solutions Inc. software programs (ESET Smart Security Premium, ESET Internet Security, ESET Smart Security, ESET NOD32 Antivirus, DESlock+ Pro, and CompuSec (all programs except pa... Read more
Affected Products : nod32_antivirus smart_security compusec deslock\+_pro internet_security smart_security_premium- EPSS Score: %0.14
- Published: Sep. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
CRITICALCVE-2023-4088
Incorrect Default Permissions vulnerability in Mitsubishi Electric Corporation multiple FA engineering software products allows a malicious local attacker to execute a malicious code, resulting in information disclosure, tampering with and deletion, or a ... Read more
Affected Products : gx_works3 gx_works2 melsoft_iq_appportal melsoft_navigator ezsocket fr_configurator2 mx_component- EPSS Score: %0.03
- Published: Sep. 20, 2023
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2015-8507
mediaserver in Android 6.0 before 2015-12-01 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted media file, aka internal bug 24157524, a different vulnerability than CVE-2015-6616, CVE-2015-850... Read more
Affected Products : android- EPSS Score: %0.93
- Published: Dec. 08, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2009-2784
Multiple directory traversal vulnerabilities in dit.cms 1.3, when register_globals is enabled, allow remote attackers to include and execute arbitrary local files via a .. (dot dot) in the path parameter to index.php in (1) install/, (2) menus/left_rights... Read more
Affected Products : dit.cms- EPSS Score: %0.84
- Published: Aug. 17, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2015-7717
mediaserver in Android 5.x before 5.1.1 LMY48T and 6.0 before 2015-10-01 allows attackers to gain privileges via a crafted application, aka internal bug 19573085, a different vulnerability than CVE-2015-6596.... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Oct. 06, 2015
- Modified: Apr. 12, 2025
-
9.3
HIGHCVE-2021-0514
In several functions of the V8 library, there is a possible use after free due to a race condition. This could lead to remote code execution in an unprivileged process with no additional execution privileges needed. User interaction is not needed for expl... Read more
Affected Products : android- EPSS Score: %2.01
- Published: Jul. 14, 2021
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2020-0002
In ih264d_init_decoder of ih264d_api.c, there is a possible out of bounds write due to a use after free. This could lead to remote code execution with no additional execution privileges needed. User interaction is needed for exploitation Product: Android ... Read more
Affected Products : android- EPSS Score: %0.29
- Published: Jan. 08, 2020
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2009-3658
Use-after-free vulnerability in the Sb.SuperBuddy.1 ActiveX control (sb.dll) in America Online (AOL) 9.5.0.1 allows remote attackers to trigger memory corruption or possibly execute arbitrary code via a malformed argument to the SetSuperBuddy method.... Read more
Affected Products : superbuddy_activex_control- EPSS Score: %22.02
- Published: Oct. 09, 2009
- Modified: Apr. 09, 2025
-
9.3
HIGHCVE-2009-3737
The Oracle Siebel Option Pack for IE ActiveX control does not properly initialize memory that is used by the NewBusObj method, which allows remote attackers to execute arbitrary code via a crafted HTML document.... Read more
- EPSS Score: %6.88
- Published: Aug. 17, 2010
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2018-1000118
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their ... Read more
Affected Products : electron- EPSS Score: %4.78
- Published: Mar. 07, 2018
- Modified: Nov. 21, 2024
-
9.3
HIGHCVE-2012-1661
ESRI ArcMap 9 and ArcGIS 10.0.2.3200 and earlier does not properly prompt users before executing embedded VBA macros, which allows user-assisted remote attackers to execute arbitrary VBA code via a crafted map (.mxd) file.... Read more
- EPSS Score: %11.82
- Published: Jul. 12, 2012
- Modified: Apr. 11, 2025
-
9.3
HIGHCVE-2009-3930
Multiple integer overflows in Christos Zoulas file before 5.02 allow user-assisted remote attackers to have an unspecified impact via a malformed compound document (aka cdf) file that triggers a buffer overflow.... Read more
- EPSS Score: %0.88
- Published: Nov. 10, 2009
- Modified: Apr. 09, 2025