Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2000-1126

    Vulnerability in auto_parms and set_parms in HP-UX 11.00 and earlier allows remote attackers to execute arbitrary commands or cause a denial of service.... Read more

    Affected Products : hp-ux
    • EPSS Score: %0.84
    • Published: Jan. 09, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0742

    Sun Java System Portal Server 6.2 (formerly Sun ONE) allows remote authenticated users to obtain Calendar Server privileges and modify Calendar data by changing the display options to a non-default view.... Read more

    Affected Products : java_system_calendar_server
    • EPSS Score: %1.04
    • Published: Jul. 27, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2007-1567

    Stack-based buffer overflow in War FTP Daemon 1.65, and possibly earlier, allows remote attackers to cause a denial of service or execute arbitrary code via unspecified vectors, as demonstrated by warftp_165.tar by Immunity. NOTE: this might be the same ... Read more

    Affected Products : war_ftp_daemon
    • EPSS Score: %4.05
    • Published: Mar. 21, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-1631

    PHP remote file inclusion vulnerability in signup.php in CLBOX 1.01 allows remote attackers to execute arbitrary PHP code via a URL in the header parameter. NOTE: this issue has been disputed by a reliable third party, stating that header is defined thro... Read more

    Affected Products : clbox
    • EPSS Score: %1.01
    • Published: Mar. 23, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2025-8731

    A vulnerability was identified in TRENDnet TI-G160i, TI-PG102i and TPL-430AP up to 20250724. This affects an unknown part of the component SSH Service. The manipulation leads to use of default credentials. It is possible to initiate the attack remotely. T... Read more

    Affected Products :
    • Published: Aug. 08, 2025
    • Modified: Aug. 13, 2025
  • 10.0

    HIGH
    CVE-2007-2375

    The agent remote upgrade interface in Symantec Enterprise Security Manager (ESM) before 20070405 does not verify the authenticity of upgrades, which allows remote attackers to execute arbitrary code via software that implements the agent upgrade protocol.... Read more

    Affected Products : enterprise_security_manager
    • EPSS Score: %6.75
    • Published: Apr. 30, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-2387

    Apple Xserve Lights-Out Management before Firmware Update 1.0 on Intel hardware does not require a password for remote access to IPMI, which allows remote attackers to gain administrative access via unspecified requests with ipmitool.... Read more

    Affected Products : xserve_lights-out_management
    • EPSS Score: %3.27
    • Published: Jun. 04, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-2417

    Heap-based buffer overflow in _mprosrv.exe in Progress Software Progress 9.1E and OpenEdge 10.1x, as used by the RSA Authentication Manager 6.0 and 6.1, SecurID Appliance 2.0, ACE/Server 5.2, and possibly other products, allows remote attackers to execute... Read more

    Affected Products : openedge ace_server progress securid
    • EPSS Score: %1.64
    • Published: Jul. 15, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2001-1067

    Buffer overflow in AOLserver 3.0 allows remote attackers to cause a denial of service, and possibly execute arbitrary code, via an HTTP request with a long Authorization header.... Read more

    Affected Products : aol_server
    • EPSS Score: %29.25
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1113

    Buffer overflow in TrollFTPD 1.26 and earlier allows local users to execute arbitrary code by creating a series of deeply nested directories with long names, then running the ls -R (recursive) command.... Read more

    Affected Products : trollftpd
    • EPSS Score: %1.45
    • Published: Aug. 13, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-0992

    HP VirtualVault with the PHSS_17692 patch allows unprivileged processes to bypass access restrictions via the Trusted Gateway Proxy (TGP).... Read more

    Affected Products : vvos
    • EPSS Score: %0.41
    • Published: Jan. 18, 2000
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1440

    Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.... Read more

    Affected Products : aix
    • EPSS Score: %3.10
    • Published: Dec. 21, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2007-2849

    KnowledgeTree Document Management (aka KnowledgeTree Open Source) before STABLE 3.3.7 does not require a password for an unregistered user, when the user exists in Active Directory, which allows remote attackers to log onto KTDMS without the intended auth... Read more

    Affected Products : knowledgetree_document_management
    • EPSS Score: %2.25
    • Published: May. 24, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2004-2237

    Unknown vulnerability in Moodle before 1.3.4 has unknown impact and attack vectors, related to "strings in Moodle texts."... Read more

    Affected Products : moodle
    • EPSS Score: %0.44
    • Published: Dec. 31, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0005

    Buffer overflow in AOL Instant Messenger (AIM) 4.7.2480, 4.8.2616, and other versions allows remote attackers to execute arbitrary code via a long argument in a game request (AddGame).... Read more

    Affected Products : instant_messenger
    • EPSS Score: %27.93
    • Published: Jan. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-2532

    Serv-U FTP server before 5.1.0.0 has a default account and password for local administration, which allows local users to execute arbitrary commands by connecting to the server using the default administrator account, creating a new user, logging in as th... Read more

    Affected Products : serv-u_file_server
    • EPSS Score: %7.22
    • Published: Dec. 31, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0255

    The default configuration of Arescom NetDSL 800 does not require authentication, which allows remote attackers to cause a denial of service or reconfigure the router.... Read more

    Affected Products : netdsl
    • EPSS Score: %0.49
    • Published: May. 29, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0308

    admin.asp in AdMentor 2.11 allows remote attackers to bypass authentication and gain privileges via a SQL injection attack on the Login and Password arguments.... Read more

    Affected Products : admentor
    • EPSS Score: %0.43
    • Published: May. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0359

    xfsmd for IRIX 6.5 through 6.5.16 uses weak authentication, which allows remote attackers to call dangerous RPC functions, including those that can mount or unmount xfs file systems, to gain root privileges.... Read more

    Affected Products : irix
    • EPSS Score: %1.38
    • Published: Jul. 03, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0398

    Red-M 1050 (Bluetooth Access Point) PPP server allows bonded users to cause a denial of service and possibly execute arbitrary code via a long user name.... Read more

    Affected Products : 1050ap_lan_acess_point
    • EPSS Score: %0.82
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
Showing 20 of 291014 Results