Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2008-2245

    Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allo... Read more

    • Published: Aug. 13, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2228

    PHP remote file inclusion vulnerability in portfolio/commentaires/derniers_commentaires.php in Cyberfolio 7.12, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the rep parameter.... Read more

    Affected Products : cyberfolio
    • Published: May. 14, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2283

    IDAutomation allows remote attackers to overwrite arbitrary files via the argument to the (1) SaveBarCode and (2) SaveEnhWMF methods in (a) the IDAuto.BarCode.1 ActiveX control in IDAutomationLinear6.dll (aka IDAutomation Linear BarCode) 1.6.0.6, (b) the ... Read more

    • Published: May. 18, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2258

    Microsoft Internet Explorer 5.01, 6, and 7 accesses uninitialized memory in certain conditions, which allows remote attackers to cause a denial of service (crash) and execute arbitrary code via vectors related to a document object "appended in a specific ... Read more

    Affected Products : internet_explorer
    • Published: Aug. 13, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2020-17124

    Microsoft PowerPoint Remote Code Execution Vulnerability... Read more

    • Published: Dec. 10, 2020
    • Modified: Aug. 28, 2025
  • 9.3

    HIGH
    CVE-2008-2152

    Integer overflow in the rtl_allocateMemory function in sal/rtl/source/alloc_global.c in OpenOffice.org (OOo) 2.0 through 2.4 allows remote attackers to execute arbitrary code via a crafted file that triggers a heap-based buffer overflow.... Read more

    Affected Products : openoffice.org
    • Published: Jun. 10, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2160

    Multiple unspecified vulnerabilities in the JPEG (GDI+) and GIF image processing in Microsoft Windows CE 5.0 allow remote attackers to execute arbitrary code via crafted (1) JPEG and (2) GIF images.... Read more

    Affected Products : windows_embedded_compact windows_ce
    • Published: May. 12, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2111

    The ActiveX Control (yNotifier.dll) in Yahoo! Assistant 3.6 and earlier allows remote attackers to execute arbitrary code via unspecified vectors in the Ynoifier COM object that trigger memory corruption.... Read more

    Affected Products : yahoo_assistant
    • Published: May. 07, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2069

    Buffer overflow in Novell GroupWise 7 allows remote attackers to cause a denial of service or execute arbitrary code via a long argument in a mailto: URI.... Read more

    Affected Products : groupwise
    • Published: May. 02, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    CRITICAL
    CVE-2025-54720

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in SteelThemes Nest Addons allows SQL Injection. This issue affects Nest Addons: from n/a through 1.6.3.... Read more

    Affected Products :
    • Published: Aug. 28, 2025
    • Modified: Aug. 29, 2025
    • Vuln Type: Injection
  • 9.3

    HIGH
    CVE-2008-2015

    Multiple absolute path traversal vulnerabilities in certain ActiveX controls in WatchFire AppScan 7.0 allow remote attackers to create or overwrite arbitrary files via a full pathname in the argument to the (1) CompactSave and (2) SaveSession method in on... Read more

    Affected Products : appscan
    • Published: Apr. 30, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2008

    Buffer overflow in the Display Names message feature in Cerulean Studios Trillian Basic and Pro 3.1.9.0 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long nickname in an MSN protocol message.... Read more

    Affected Products : trillian
    • Published: Apr. 29, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2054

    Unspecified vulnerability in Cisco CiscoWorks Common Services 3.0.3 through 3.1.1 allows remote attackers to execute arbitrary code on a client machine via unknown vectors.... Read more

    Affected Products : ciscoworks_common_services
    • Published: May. 29, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-2010

    Unspecified vulnerability in Apple QuickTime Player on Windows XP SP2 and Vista SP1 allows remote attackers to execute arbitrary code via a crafted QuickTime media file. NOTE: as of 20080429, the only disclosure is a vague pre-advisory with no actionable... Read more

    Affected Products : quicktime windows_vista windows_xp
    • Published: Apr. 30, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1973

    Heap-based buffer overflow in SubEdit Player build 4056 and 4066 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a long subtitle file.... Read more

    Affected Products : subedit_player
    • Published: Apr. 27, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1965

    Argument injection vulnerability in the cai: URI handler in rcplauncher in IBM Lotus Expeditor Client for Desktop 6.1.1 and 6.1.2, as used by Lotus Symphony and possibly other products, allows remote attackers to execute arbitrary code by injecting a -lau... Read more

    • Published: Apr. 25, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1912

    Stack-based buffer overflow in DivX Player 6.7 build 6.7.0.22 and earlier allows user-assisted remote attackers to cause a denial of service (application crash) or execute arbitrary code via a long subtitle in a .SRT file.... Read more

    Affected Products : divx_player
    • Published: Apr. 22, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1898

    A certain ActiveX control in WkImgSrv.dll 7.03.0616.0, as distributed in Microsoft Works 7 and Microsoft Office 2003 and 2007, allows remote attackers to execute arbitrary code or cause a denial of service (browser crash) via an invalid WksPictureInterfac... Read more

    Affected Products : office works
    • Published: Apr. 21, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2008-1860

    Static code injection vulnerability in admin.php in LokiCMS 0.3.3 and earlier allows remote attackers to inject arbitrary PHP code into includes/Config.php via the default parameter.... Read more

    Affected Products : lokicms
    • Published: Apr. 17, 2008
    • Modified: Apr. 09, 2025
  • 9.3

    HIGH
    CVE-2019-1925

    Multiple vulnerabilities in Cisco Webex Network Recording Player for Microsoft Windows and Cisco Webex Player for Microsoft Windows could allow an attacker to execute arbitrary code on an affected system. The vulnerabilities exist because the affected sof... Read more

    • Published: Aug. 07, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 294690 Results