Latest CVE Feed
-
10.0
HIGHCVE-2006-0559
Format string vulnerability in the SMTP server for McAfee WebShield 4.5 MR2 and earlier allows remote attackers to execute arbitrary code via format strings in the domain name portion of a destination address, which are not properly handled when a bounce ... Read more
Affected Products : webshield_smtp- EPSS Score: %19.53
- Published: Apr. 04, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-10996
The weblogin_log function in /htdocs/cgibin on D-Link DIR-629-B1 devices allows attackers to execute arbitrary code or cause a denial of service (buffer overflow) via a session.cgi?ACTION=logout request involving a long REMOTE_ADDR environment variable.... Read more
- EPSS Score: %1.42
- Published: May. 12, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-2156
Multiple unknown vulnerabilities in Online Recruitment Agency 1.0 have unknown impact and attack vectors.... Read more
Affected Products : online_recruitment_agency- EPSS Score: %0.64
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2018-18748
Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's intended f... Read more
- EPSS Score: %0.80
- Published: Oct. 29, 2018
- Modified: Aug. 04, 2025
-
10.0
HIGHCVE-2010-3510
Unspecified vulnerability in the Oracle WebLogic Server component in Oracle Fusion Middleware 9.0, 9.1, 9.2.3, 10.0.2, 10.3.2, and 10.3.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Node Ma... Read more
Affected Products : fusion_middleware- EPSS Score: %4.29
- Published: Jan. 19, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-11936
Index of array is processed in a wrong way inside a while loop and result in invalid index (-1 or something else) leads to out of bound memory access. in Snapdragon Auto, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Co... Read more
Affected Products : qca6574au_firmware qca6574_firmware qca6584au_firmware qca9886_firmware msm8996au_firmware sd_450_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd_835_firmware +46 more products- EPSS Score: %0.33
- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-2573
A Command Injection vulnerability exists in the ap parameter to the /cgi-bin/mft/wireless_mft.cgi file in TP-Link IP Cameras TL-SC 3130, TL-SC 3130G, 3171G. and 4171G 1.6.18P12s, which could let a malicious user execute arbitrary code.... Read more
Affected Products : tl-sc_3130g_firmware tl-sc_3171g_firmware tl-sc_4171g_firmware tl-sc_3130g tl-sc_3171g tl-sc_4171g- EPSS Score: %22.39
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-2579
TP-Link IP Cameras TL-SC3130, TL-SC3130G, TL-SC3171, TL-SC3171G, and possibly other models before beta firmware LM.1.6.18P12_sign6 have an empty password for the hardcoded "qmik" account, which allows remote attackers to obtain administrative access via a... Read more
- EPSS Score: %17.78
- Published: Oct. 11, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-19168
Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a POST request. NOTE: unlike in CVE-2... Read more
Affected Products : fruitywifi- EPSS Score: %12.61
- Published: Nov. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2004-2247
Unknown vulnerability in the "admin of paypal email addresses" in AudienceConnect before 1.0.beta.21 has unknown impact and attack vectors.... Read more
Affected Products : audienceconnect- EPSS Score: %0.39
- Published: Dec. 31, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2009-3096
Multiple unspecified vulnerabilities in HP Performance Insight 5.3 allow remote attackers to have an unknown impact, related to (1) a "Remote exploit" on Windows platforms, and (2) a "Remote preauthentication exploit" on the Windows Server 2003 SP2 platfo... Read more
- EPSS Score: %1.50
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2018-19417
An issue was discovered in the MQTT server in Contiki-NG before 4.2. The function parse_publish_vhdr() that parses MQTT PUBLISH messages with a variable length header uses memcpy to input data into a fixed size buffer. The allocated buffer can fit only MQ... Read more
- EPSS Score: %6.15
- Published: Nov. 21, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-3350
Multiple unspecified vulnerabilities in the Subdomain Manager module for Drupal have unknown impact and attack vectors.... Read more
- EPSS Score: %0.39
- Published: Sep. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-20122
The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code executi... Read more
- EPSS Score: %5.91
- Published: Feb. 21, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-13887
Untrusted header fields in GNSS XTRA3 function can lead to integer overflow in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in MDM9150, MDM9206, MDM9607, MDM9635M, MDM9650... Read more
Affected Products : sdm660_firmware sd_450_firmware sd_625_firmware sd_835_firmware mdm9150_firmware qcs605_firmware sd_675_firmware mdm9650_firmware msm8909w_firmware sdx20_firmware +64 more products- EPSS Score: %0.31
- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-3316
Netgear WNR1000v3 with firmware before 1.0.2.60 contains an Authentication Bypass due to the server skipping checks for URLs containing a ".jpg".... Read more
- EPSS Score: %0.23
- Published: Jan. 29, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-13649
TP-Link M7350 devices through 1.0.16 Build 181220 Rel.1116n allow externalPort OS Command Injection (issue 1 of 5).... Read more
- EPSS Score: %4.01
- Published: Oct. 24, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-2204
In FindSharedFunctionInfo of objects.cc, there is a possible out of bounds read due to a mistake in AST traversal. This could lead to remote code execution in the pacprocessor with no additional execution privileges needed. User interaction is not needed ... Read more
Affected Products : android- EPSS Score: %1.25
- Published: Nov. 13, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-2271
Buffer over read can happen while parsing downlink session management OTA messages if network sends un-intended values in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdrago... Read more
Affected Products : sdx55_firmware sdm660_firmware sm8150_firmware sm8250_firmware sxr2130_firmware msm8996au_firmware apq8096au_firmware qcs605_firmware sdx24_firmware apq8009_firmware +100 more products- EPSS Score: %0.37
- Published: Nov. 21, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-3842
Unspecified vulnerability on the HP Color LaserJet M3530 Multifunction Printer with firmware 05.058.4 and the Color LaserJet CP3525 Printer with firmware 53.021.2 allows remote attackers to obtain "access to data" or cause a denial of service via unknown ... Read more
- EPSS Score: %1.13
- Published: Nov. 20, 2009
- Modified: Apr. 09, 2025