Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2008-2885

    PHP remote file inclusion vulnerability in src/browser/resource/categories/resource_categories_view.php in Open Digital Assets Repository System (ODARS) 1.0.2, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a U... Read more

    Affected Products : odars
    • Published: Jun. 27, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2785

    Mozilla Firefox before 2.0.0.16 and 3.x before 3.0.1, Thunderbird before 2.0.0.16, and SeaMonkey before 1.1.11 use an incorrect integer data type as a CSS object reference counter in the CSSValue array (aka nsCSSValue:Array) data structure, which allows r... Read more

    Affected Products : firefox thunderbird seamonkey
    • Published: Jun. 19, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2779

    Directory traversal vulnerability in GlobalSCAPE CuteFTP Home 8.2.0 Build 02.26.2008.4 and CuteFTP Pro 8.2.0 Build 04.01.2008.1 allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to LIST com... Read more

    Affected Products : cuteftp
    • Published: Jun. 19, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2019-20610

    An issue was discovered on Samsung mobile devices with N(7.X) and O(8.X) (Exynos 7570, 7870, 7880, 7885, 8890, 8895, and 9810 chipsets) software. A double-fetch vulnerability in Trustlet allows arbitrary TEE code execution. The Samsung ID is SVE-2019-1391... Read more

    • Published: Mar. 24, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-2690

    Multiple PHP remote file inclusion vulnerabilities in BrowserCRM 5.002.00, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the bcrm_pub_root parameter to (1) kb.php, (2) login.php, (3) index.php, (4) con... Read more

    Affected Products : browsercrm
    • Published: Jun. 13, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2021-41088

    Elvish is a programming language and interactive shell, combined into one package. In versions prior to 0.14.0 Elvish's web UI backend (started by `elvish -web`) hosts an endpoint that allows executing the code sent from the web UI. The backend does not c... Read more

    Affected Products : elvish
    • Published: Sep. 23, 2021
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2008-2683

    The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to force the download and storage of arbitrary files by specifying the origin URL in the first argument to the DownloadImageFileURL method, a... Read more

    Affected Products : barcode_sdk
    • Published: Jun. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2684

    The BIDIB.BIDIBCtrl.1 ActiveX control in BIDIB.ocx 10.9.3.0 in Black Ice Barcode SDK 5.01 allows remote attackers to execute arbitrary code via long strings in the two arguments to the DownloadImageFileURL method, which trigger memory corruption. NOTE: s... Read more

    Affected Products : black_ice_barcode_sdk
    • Published: Jun. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2570

    Multiple unspecified vulnerabilities in LimeSurvey (formerly PHPSurveyor) before 1.71 have unknown impact and attack vectors.... Read more

    Affected Products : limesurvey
    • Published: Jun. 06, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2545

    Skype 3.6.0.248, and other versions before 3.8.0.139, uses a case-sensitive comparison when checking for dangerous extensions, which allows user-assisted remote attackers to bypass warning dialogs and possibly execute arbitrary code via a file: URI with a... Read more

    Affected Products : skype skype
    • Published: Jun. 06, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2503

    Buffer overflow in Uploadlist in eMule X-Ray before 1.4 has unknown impact and remote attack vectors.... Read more

    Affected Products : emule_x-ray
    • Published: May. 29, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2548

    Stack-based buffer overflow in the JPEG thumbprint component in the EXIF parser on Motorola cell phones with RAZR firmware allows user-assisted remote attackers to execute arbitrary code via an MMS transmission of a malformed JPEG image, which triggers me... Read more

    Affected Products : razr
    • Published: Jun. 04, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2547

    Stack-based buffer overflow in msiexec.exe 3.1.4000.1823 and 4.5.6001.22159 in Microsoft Windows Installer allows context-dependent attackers to execute arbitrary code via a long GUID value for the /x (aka /uninstall) option. NOTE: this issue might cross... Read more

    Affected Products : windows_installer
    • Published: Jun. 04, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2025-54946

    A SQL injection vulnerability in SUNNET Corporate Training Management System before 10.11 allows remote attackers to execute arbitrary SQL commands.... Read more

    Affected Products :
    • Published: Aug. 30, 2025
    • Modified: Sep. 02, 2025
    • Vuln Type: Injection
  • 9.3

    HIGH
    CVE-2008-2435

    Use-after-free vulnerability in the Trend Micro HouseCall ActiveX control 6.51.0.1028 and 6.6.0.1278 in Housecall_ActiveX.dll allows remote attackers to execute arbitrary code via a crafted notifyOnLoadNative callback function.... Read more

    Affected Products : housecall housecall
    • Published: Dec. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-4197

    Opera before 9.52 on Windows, Linux, FreeBSD, and Solaris, when processing custom shortcut and menu commands, can produce argument strings that contain uninitialized memory, which might allow user-assisted remote attackers to execute arbitrary code or con... Read more

    • Published: Sep. 27, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2408

    Heap-based buffer overflow in the XML parsing functionality in talk.dll in Cerulean Studios Trillian Pro before 3.1.10.0 allows remote attackers to execute arbitrary code via a malformed attribute in an IMG tag.... Read more

    Affected Products : trillian_pro
    • Published: May. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2409

    Stack-based buffer overflow in Cerulean Studios Trillian before 3.1.10.0 allows remote attackers to execute arbitrary code via unspecified attributes in the X-MMS-IM-FORMAT header in an MSN message.... Read more

    Affected Products : trillian
    • Published: May. 23, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2399

    Directory traversal vulnerability in the FireFTP add-on before 0.98.20080518 for Firefox allows remote FTP servers to create or overwrite arbitrary files via ..\ (dot dot backslash) sequences in responses to (1) MLSD and (2) LIST commands, a related issue... Read more

    Affected Products : firefox fireftp
    • Published: May. 22, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2427

    Stack-based buffer overflow in NConvert 4.92, GFL SDK 2.82, and XnView 1.93.6 on Windows and 1.70 on Linux and FreeBSD allows user-assisted remote attackers to execute arbitrary code via a crafted format keyword in a Sun TAAC file.... Read more

    • Published: Jun. 24, 2008
    • Modified: Apr. 09, 2025
Showing 20 of 294545 Results