Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2014-1849

    Foscam IP camera 11.37.2.49 and other versions, when using the Foscam DynDNS option, generates credentials based on predictable camera subdomain names, which allows remote attackers to spoof or hijack arbitrary cameras and conduct other attacks by modifyi... Read more

    Affected Products : ip_camera_firmware
    • EPSS Score: %20.85
    • Published: May. 14, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-0405

    Multiple directory traversal vulnerabilities in HTTP File Server (HFS) before 2.2c, when account names are used as log filenames, allow remote attackers to create arbitrary (1) files and (2) directories via a .. (dot dot) in an account name, when requesti... Read more

    Affected Products : http_file_server http_file_server
    • EPSS Score: %1.26
    • Published: Jan. 29, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-4898

    The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.... Read more

    Affected Products : novabackup_datacenter
    • EPSS Score: %4.48
    • Published: Apr. 13, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-5080

    Integer overflow in the rtxMemHeapAlloc function in asn1rt_a.lib in Objective Systems ASN1C for C/C++ before 7.0.2 allows context-dependent attackers to execute arbitrary code or cause a denial of service (heap-based buffer overflow), on a system running ... Read more

    Affected Products : asn1c
    • EPSS Score: %40.64
    • Published: Jul. 19, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-0550

    Off-by-one error in Steamcast 0.9.75 and earlier allows remote attackers to cause a denial of service (daemon crash) or execute arbitrary code via a certain HTTP request that leads to a buffer overflow, as demonstrated by a long User-Agent header.... Read more

    Affected Products : steamcast
    • EPSS Score: %68.16
    • Published: Feb. 01, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2004-0315

    Buffer overflow in Avirt Voice 4.0 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long GET request on port 1080.... Read more

    Affected Products : voice
    • EPSS Score: %3.18
    • Published: Nov. 23, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0338

    SQL injection vulnerability in search.php for Invision Board Forum allows remote attackers to execute arbitrary SQL queries via the st parameter.... Read more

    Affected Products : invision_board
    • EPSS Score: %0.42
    • Published: Nov. 23, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0377

    Buffer overflow in the win32_stat function for (1) ActiveState's ActivePerl and (2) Larry Wall's Perl before 5.8.3 allows local or remote attackers to execute arbitrary commands via filenames that end in a backslash character.... Read more

    Affected Products : perl activeperl
    • EPSS Score: %10.19
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2005-3957

    Unspecified vulnerability in the Trackback functionality in DotClear 1.2.1 has unknown impact and attack vectors.... Read more

    Affected Products : dotclear
    • EPSS Score: %0.45
    • Published: Dec. 01, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2008-0647

    Multiple stack-based buffer overflows in the HanGamePluginCn18.HanGamePluginCn18.1 ActiveX control in HanGamePluginCn18.dll in Ourgame GLWorld 2.6.1.29 (aka Lianzong Game Platform) allow remote attackers to execute arbitrary code via long arguments to the... Read more

    • EPSS Score: %7.15
    • Published: Feb. 07, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-6536

    The /setup URI on AVer Information EH6108H+ devices with firmware X9.03.24.00.07l allows remote attackers to bypass intended page-access restrictions or modify passwords by leveraging knowledge of a handle parameter value.... Read more

    Affected Products : eh6108h\+_firmware eh6108h\+
    • EPSS Score: %0.80
    • Published: Sep. 19, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-6598

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting file storage service (FileStorageService) on port 9010. This service contains a method that allows uploading a file to an arbitrary path on the machine that is running Track-It!. ... Read more

    Affected Products : track-it\!
    • EPSS Score: %36.87
    • Published: Jan. 30, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-7112

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more

    • EPSS Score: %0.52
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-0735

    SQL injection vulnerability in mod/gallery/ajax/gallery_data.php in AuraCMS 2.2 allows remote attackers to execute arbitrary SQL commands via the albums parameter.... Read more

    Affected Products : auracms
    • EPSS Score: %0.35
    • Published: Feb. 13, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2004-0636

    Buffer overflow in the goaway function in the aim:goaway URI handler for AOL Instant Messenger (AIM) 5.5, including 5.5.3595, allows remote attackers to execute arbitrary code via a long Away message.... Read more

    Affected Products : instant_messenger
    • EPSS Score: %78.52
    • Published: Nov. 23, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2015-1845

    Buffer overflow in the EntrReadArch function in unzoo might allow remote attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : unzoo
    • EPSS Score: %10.96
    • Published: May. 19, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-8364

    An issue was discovered in IBHsoftec S7-SoftPLC prior to 4.12b. Object memory can read a network packet that is larger than the space that is available, a Heap-based Buffer Overflow.... Read more

    Affected Products : s7-softplc
    • EPSS Score: %0.65
    • Published: Feb. 13, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-8440

    Possible buffer overflow in SMMU system call. Improper input validation in ADSP SID2CB system call may result in hypervisor memory overwrite. Product: Android. Versions: Kernel 3.18. Android ID: A-31625306. References: QC-CR#1036747.... Read more

    Affected Products : android linux_kernel
    • EPSS Score: %0.53
    • Published: Jan. 12, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2015-2767

    Unspecified vulnerability in Websense TRITON AP-EMAIL before 8.0.0 has unknown impact and attack vectors, related to "Autocomplete Enabled."... Read more

    Affected Products : triton_ap_email
    • EPSS Score: %0.38
    • Published: Mar. 27, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-3116

    Format string vulnerability in dx8render.dll in Snail Game (aka Suzhou Snail Electronic Company) 5th street (aka Hot Step or High Street 5) allows remote attackers to execute arbitrary code via format string specifiers in a chat message.... Read more

    Affected Products : 5th_street high_street_5 hot_step
    • EPSS Score: %5.10
    • Published: Jul. 10, 2008
    • Modified: Apr. 09, 2025
Showing 20 of 291398 Results