Latest CVE Feed
-
10.0
HIGHCVE-2017-11307
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution ... Read more
- EPSS Score: %17.15
- Published: May. 19, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-11302
An issue was discovered in Adobe InDesign 12.1.0 and earlier versions. An exploitable memory corruption vulnerability exists. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : indesign- EPSS Score: %10.80
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-11291
An issue was discovered in Adobe Connect 9.6.2 and earlier versions. A Server-Side Request Forgery (SSRF) vulnerability exists that could be abused to bypass network access controls.... Read more
Affected Products : connect- EPSS Score: %2.28
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11253
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution ... Read more
- EPSS Score: %17.15
- Published: May. 19, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-11240
Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution ... Read more
- EPSS Score: %17.15
- Published: May. 19, 2018
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-43242
Deserialization of Untrusted Data vulnerability in azzaroco Ultimate Membership Pro allows Object Injection.This issue affects Ultimate Membership Pro: from n/a through 12.6.... Read more
Affected Products : ultimate_membership_pro- Published: Aug. 19, 2024
- Modified: Sep. 06, 2024
-
10.0
HIGHCVE-2017-11351
Axesstel MU553S MU55XS-V1.14 devices have a default password of admin for the admin account.... Read more
- EPSS Score: %0.28
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2024-43243
Unrestricted Upload of File with Dangerous Type vulnerability in ThemeGlow JobBoard Job listing allows Upload a Web Shell to a Web Server.This issue affects JobBoard Job listing: from n/a through 1.2.6.... Read more
Affected Products :- Published: Jan. 07, 2025
- Modified: Jan. 07, 2025
- Vuln Type: Misconfiguration
-
10.0
HIGHCVE-2017-11293
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. An exploitable memory corruption vulnerability exists. Su... Read more
- EPSS Score: %10.80
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11274
Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : digital_editions- EPSS Score: %4.71
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2021-37535
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.... Read more
- EPSS Score: %0.34
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-35211
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarW... Read more
Affected Products : serv-u- Actively Exploited
- EPSS Score: %94.00
- Published: Jul. 14, 2021
- Modified: Mar. 12, 2025
-
10.0
HIGHCVE-2017-11011
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 835, a Use After Free condition can occur in a communication API.... Read more
Affected Products : android sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware +13 more products- EPSS Score: %0.26
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-11006
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during positioning.... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11010
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.... Read more
Affected Products : android- EPSS Score: %0.58
- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-10992
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.... Read more
Affected Products : storage_essentials- EPSS Score: %2.86
- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-31755
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.... Read more
- Actively Exploited
- EPSS Score: %94.23
- Published: May. 07, 2021
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2017-10906
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.... Read more
- EPSS Score: %1.36
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10871
Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors.... Read more
- EPSS Score: %0.64
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10903
Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct arbitrary operations via unspecified vectors.... Read more
- EPSS Score: %4.81
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025