Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2011-0383

    The Java Servlet framework on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x does not require administrative authentication ... Read more

    • EPSS Score: %4.70
    • Published: Feb. 25, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-0062

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.6.x before 3.6.14 and Thunderbird 3.1.x before 3.1.8 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrar... Read more

    Affected Products : firefox thunderbird
    • EPSS Score: %7.09
    • Published: Mar. 02, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-0053

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.5.17 and 3.6.x before 3.6.14, Thunderbird before 3.1.8, and SeaMonkey before 2.0.12 allow remote attackers to cause a denial of service (memory corruption and applicati... Read more

    Affected Products : firefox thunderbird seamonkey
    • EPSS Score: %2.50
    • Published: Mar. 02, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-4601

    Multiple unspecified vulnerabilities in IBM Rational ClearQuest 7.0.x before 7.0.1.11, 7.1.1.x before 7.1.1.4, and 7.1.2.x before 7.1.2.1 allow attackers to have an unknown impact via vectors related to third-party .ocx files.... Read more

    Affected Products : rational_clearquest
    • EPSS Score: %0.49
    • Published: Dec. 29, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3415

    Google Chrome before 6.0.472.59 does not properly implement Geolocation, which allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %1.18
    • Published: Sep. 16, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3117

    Google Chrome before 5.0.375.127 does not properly implement the notifications feature, which allows remote attackers to cause a denial of service (application crash) and possibly have unspecified other impact via unknown vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %0.99
    • Published: Aug. 24, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0174

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 3.0.19, 3.5.x before 3.5.9, and 3.6.x before 3.6.2; Thunderbird before 3.0.4; and SeaMonkey before 2.0.4 allow remote attackers to cause a denial of service (memory corru... Read more

    Affected Products : firefox thunderbird seamonkey
    • EPSS Score: %4.23
    • Published: Apr. 05, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0159

    The browser engine in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbit... Read more

    • EPSS Score: %2.15
    • Published: Feb. 22, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0108

    Buffer overflow in the cliproxy.objects.1 ActiveX control in the Symantec Client Proxy (CLIproxy.dll) in Symantec AntiVirus 10.0.x, 10.1.x before MR9, and 10.2.x before MR4; and Symantec Client Security 3.0.x and 3.1.x before MR9 allows remote attackers t... Read more

    • EPSS Score: %13.17
    • Published: Feb. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2009-3575

    Buffer overflow in DHTRoutingTableDeserializer.cc in aria2 0.15.3, 1.2.0, and other versions allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors.... Read more

    Affected Products : aria2
    • EPSS Score: %3.32
    • Published: Oct. 07, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-3069

    Unspecified vulnerability in the browser engine in Mozilla Firefox 3.5.x before 3.5.3 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more

    Affected Products : firefox
    • EPSS Score: %5.84
    • Published: Sep. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2689

    JDK13Services.getProviders in Sun Java SE 5.0 before Update 20 and 6 before Update 15, and OpenJDK, grants full privileges to instances of unspecified object types, which allows context-dependent attackers to bypass intended access restrictions via an unt... Read more

    Affected Products : openjdk java_se
    • EPSS Score: %7.93
    • Published: Aug. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2021-22707

    A CWE-798: Use of Hard-coded Credentials vulnerability exists in EVlink City (EVC1S22P4 / EVC1S7P4 all versions prior to R8 V3.4.0.1), EVlink Parking (EVW2 / EVF2 / EV.2 all versions prior to R8 V3.4.0.1), and EVlink Smart Wallbox (EVB1A all versions prio... Read more

    • EPSS Score: %90.00
    • Published: Jul. 21, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2009-0928

    Heap-based buffer overflow in Adobe Acrobat Reader and Acrobat Professional 7.1.0, 8.1.3, 9.0.0, and other versions allows remote attackers to execute arbitrary code via a PDF file containing a JBIG2 stream with a size inconsistency related to an unspecif... Read more

    Affected Products : acrobat acrobat_reader
    • EPSS Score: %11.41
    • Published: Mar. 25, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0840

    Heap-based buffer underflow in the readPostBody function in cgiutil.c in mapserv in MapServer 4.x before 4.10.4 and 5.x before 5.2.2 allows remote attackers to have an unknown impact via a negative value in the Content-Length HTTP header.... Read more

    Affected Products : mapserver mapserver
    • EPSS Score: %2.70
    • Published: Mar. 31, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2021-22657

    mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.... Read more

    Affected Products : mypro
    • EPSS Score: %0.40
    • Published: Dec. 23, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2008-5355

    The "Java Update" feature for Java Runtime Environment (JRE) for Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier does not verify the signature of the JRE that is downloaded, which allows... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %17.77
    • Published: Dec. 05, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4619

    The RPC subsystem in Sun Solaris 9 allows remote attackers to cause a denial of service (daemon crash) via a crafted request to procedure 8 in program 100000 (rpcbind), related to the XDR_DECODE operation and the taddr2uaddr function. NOTE: this might be... Read more

    Affected Products : solaris sunos
    • EPSS Score: %8.93
    • Published: Oct. 21, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4293

    Unspecified vulnerability in Opera before 9.52 on Windows, when registered as a protocol handler, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors in which Opera is launched by other appl... Read more

    Affected Products : opera opera_browser windows
    • EPSS Score: %6.35
    • Published: Sep. 27, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4070

    Heap-based buffer overflow in Mozilla Thunderbird before 2.0.0.17 and SeaMonkey before 1.1.12 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a long header in a news article, related to "canc... Read more

    Affected Products : thunderbird seamonkey
    • EPSS Score: %1.72
    • Published: Sep. 27, 2008
    • Modified: Apr. 09, 2025
Showing 20 of 292522 Results