Latest CVE Feed
-
10.0
HIGHCVE-2017-11293
An issue was discovered in Adobe Acrobat and Reader: 2017.012.20098 and earlier versions, 2017.011.30066 and earlier versions, 2015.006.30355 and earlier versions, and 11.0.22 and earlier versions. An exploitable memory corruption vulnerability exists. Su... Read more
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11274
Adobe Digital Editions 4.5.4 and earlier has an exploitable use after free vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
Affected Products : digital_editions- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2021-37535
SAP NetWeaver Application Server Java (JMS Connector Service) - versions 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, does not perform necessary authorization checks for user privileges.... Read more
- Published: Sep. 14, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2021-35211
Microsoft discovered a remote code execution (RCE) vulnerability in the SolarWinds Serv-U product utilizing a Remote Memory Escape Vulnerability. If exploited, a threat actor may be able to gain privileged access to the machine hosting Serv-U Only. SolarW... Read more
Affected Products : serv-u- Actively Exploited
- Published: Jul. 14, 2021
- Modified: Mar. 12, 2025
-
10.0
HIGHCVE-2017-11011
In Android before security patch level 2018-04-05 on Qualcomm Snapdragon Mobile and Snapdragon Wear MDM9206, MDM9607, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 820, SD 835, a Use After Free condition can occur in a communication API.... Read more
Affected Products : android sd_450_firmware sd_625_firmware sd_820_firmware sd_835_firmware mdm9206_firmware mdm9607_firmware sd_210_firmware sd_212_firmware sd_205_firmware +13 more products- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-11006
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a Use After Free condition can occur during positioning.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11010
In Android before 2018-01-05 on Qualcomm Snapdragon IoT, Snapdragon Mobile MDM9206, MDM9650, SD 210/SD 212/SD 205, SD 625, SD 650/52, SD 835, access control left a configuration space unprotected.... Read more
Affected Products : android- Published: Mar. 30, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-10992
In HPE Storage Essentials 9.5.0.142, there is Unauthenticated Java Deserialization with remote code execution via OS commands in a request to invoker/JMXInvokerServlet, aka PSRT110461.... Read more
Affected Products : storage_essentials- Published: Mar. 10, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-31755
An issue was discovered on Tenda AC11 devices with firmware through 02.03.01.104_CN. A stack buffer overflow vulnerability in /goform/setmac allows attackers to execute arbitrary code on the system via a crafted post request.... Read more
- Actively Exploited
- Published: May. 07, 2021
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2017-10906
Escape sequence injection vulnerability in Fluentd versions 0.12.29 through 0.12.40 may allow an attacker to change the terminal UI or execute arbitrary commands on the device via unspecified vectors.... Read more
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10871
Buffer overflow in NTT DOCOMO Wi-Fi STATION L-02F Software version L02F-MDM9625-V10h-JUN-23-2017-DCM-JP and earlier allows an attacker to execute arbitrary code via unspecified vectors.... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10903
Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct arbitrary operations via unspecified vectors.... Read more
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2024-42479
llama.cpp provides LLM inference in C/C++. The unsafe `data` pointer member in the `rpc_tensor` structure can cause arbitrary address writing. This vulnerability is fixed in b3561.... Read more
Affected Products : llama.cpp- Published: Aug. 12, 2024
- Modified: Aug. 15, 2024
-
10.0
CRITICALCVE-2024-42489
Pro Macros provides XWiki rendering macros. Missing escaping in the Viewpdf macro allows any user with view right on the `CKEditor.HTMLConverter` page or edit or comment right on any page to perform remote code execution. Other macros like Viewppt are vul... Read more
Affected Products : pro_macros- Published: Aug. 12, 2024
- Modified: Sep. 16, 2024
-
10.0
CRITICALCVE-2017-10921
The grant-table feature in Xen through 4.8.x does not ensure sufficient type counts for a GNTMAP_device_map and GNTMAP_host_map mapping, which allows guest OS users to cause a denial of service (count mismanagement and memory corruption) or obtain privile... Read more
Affected Products : xen- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2024-42462
Improper Authentication vulnerability in upKeeper Solutions product upKeeper Manager allows Authentication Bypass.This issue affects upKeeper Manager: through 5.1.9.... Read more
Affected Products : upkeeper_manager- Published: Aug. 16, 2024
- Modified: Aug. 28, 2024
-
10.0
HIGHCVE-2021-26895
Windows DNS Server Remote Code Execution Vulnerability... Read more
- Published: Mar. 11, 2021
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2024-42472
Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to,... Read more
- Published: Aug. 15, 2024
- Modified: Aug. 19, 2025
-
10.0
HIGHCVE-2017-10845
Wi-Fi STATION L-02F Software version V10g and earlier allows remote attackers to access the device with administrative privileges and perform unintended operations through a backdoor account.... Read more
- Published: Sep. 15, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10700
In the medialibrary component in QNAP NAS 4.3.3.0229, an un-authenticated, remote attacker can execute arbitrary system commands as the root user of the NAS application.... Read more
Affected Products : qts- Published: Sep. 19, 2017
- Modified: Apr. 20, 2025