Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2009-1571

    Use-after-free vulnerability in the HTML parser in Mozilla Firefox 3.0.x before 3.0.18 and 3.5.x before 3.5.8, Thunderbird before 3.0.2, and SeaMonkey before 2.0.3 allows remote attackers to execute arbitrary code via unspecified method calls that attempt... Read more

    Affected Products : firefox seamonkey
    • Published: Feb. 22, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-7251

    libraries/File.class.php in phpMyAdmin 2.11.x before 2.11.10 creates a temporary directory with 0777 permissions, which has unknown impact and attack vectors.... Read more

    Affected Products : phpmyadmin
    • Published: Jan. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-5340

    Unspecified vulnerability in Java Web Start (JWS) and Java Plug-in with Sun JDK and JRE 6 Update 10 and earlier; JDK and JRE 5.0 Update 16 and earlier; and SDK and JRE 1.4.2_18 and earlier allows untrusted JWS applications to gain privileges to access loc... Read more

    Affected Products : jre sdk jdk
    • Published: Dec. 05, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-5052

    The AppendAttributeValue function in the JavaScript engine in Mozilla Firefox 2.x before 2.0.0.18, Thunderbird 2.x before 2.0.0.18, and SeaMonkey 1.x before 1.1.13 allows remote attackers to cause a denial of service (crash) via unknown vectors that trigg... Read more

    Affected Products : firefox thunderbird seamonkey
    • Published: Nov. 13, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4226

    Integer overflow in the xmlSAX2Characters function in libxml2 2.7.2 allows context-dependent attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a large XML document.... Read more

    Affected Products : libxml
    • Published: Nov. 25, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-3693

    Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMw... Read more

    Affected Products : player server workstation ace
    • Published: Sep. 03, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-3692

    Unspecified vulnerability in a certain ActiveX control in VMware Workstation 5.5.x before 5.5.8 build 108000, VMware Workstation 6.0.x before 6.0.5 build 109488, VMware Player 1.x before 1.0.8 build 108000, VMware Player 2.x before 2.0.5 build 109488, VMw... Read more

    Affected Products : player server workstation ace
    • Published: Sep. 03, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-3113

    Unspecified vulnerability in Sun Java Web Start in JDK and JRE 5.0 before Update 16 and SDK and JRE 1.4.x before 1.4.2_18 allows remote attackers to create or delete arbitrary files via an untrusted application, aka CR 6704077.... Read more

    Affected Products : jre sdk jdk
    • Published: Jul. 09, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-6818

    SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS comma... Read more

    Affected Products : business_intelligence_platform
    • Published: Apr. 13, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2008-1100

    Buffer overflow in the cli_scanpe function in libclamav (libclamav/pe.c) for ClamAV 0.92 and 0.92.1 allows remote attackers to execute arbitrary code via a crafted Upack PE file.... Read more

    Affected Products : clamav
    • Published: Apr. 14, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-0657

    Multiple unspecified vulnerabilities in the Java Runtime Environment in Sun JDK and JRE 6 Update 1 and earlier, and 5.0 Update 13 and earlier, allow context-dependent attackers to gain privileges via an untrusted (1) application or (2) applet, as demonstr... Read more

    Affected Products : jre jdk
    • Published: Feb. 07, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-6726

    Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.... Read more

    Affected Products : android
    • Published: Apr. 17, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2007-6047

    Unspecified vulnerability in the DB2DART tool in IBM DB2 UDB 9.1 before Fixpak 4 allows attackers to execute arbitrary commands as the DB2 instance owner, related to invocation of TPUT by DB2DART.... Read more

    • Published: Nov. 20, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-6045

    Unspecified vulnerability in (1) DB2WATCH and (2) DB2FREEZE in IBM DB2 UDB 9.1 before Fixpak 4 has unknown impact and attack vectors.... Read more

    • Published: Nov. 20, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2021-1609

    Multiple vulnerabilities in the web-based management interface of the Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an attacker to do the following: Execute arbitrary code Cause a denial of service (DoS) co... Read more

    • Published: Aug. 04, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2007-2831

    Array index error in the (1) ieee80211_ioctl_getwmmparams and (2) ieee80211_ioctl_setwmmparams functions in net80211/ieee80211_wireless.c in MadWifi before 0.9.3.1 allows local users to cause a denial of service (system crash), possibly obtain kernel memo... Read more

    Affected Products : madwifi
    • Published: May. 24, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-2418

    Heap-based buffer overflow in the Rendezvous / Extensible Messaging and Presence Protocol (XMPP) component (plugins\rendezvous.dll) for Cerulean Studios Trillian Pro before 3.1.5.1 allows remote attackers to execute arbitrary code via a message that trigg... Read more

    Affected Products : trillian_pro
    • Published: May. 02, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-6646

    The vApp Managers web application in EMC Unisphere for VMAX Virtual Appliance 8.x before 8.3.0 and Solutions Enabler Virtual Appliance 8.x before 8.3.0 allows remote attackers to execute arbitrary code via crafted input to the (1) GetSymmCmdRequest or (2)... Read more

    • Published: Oct. 05, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2006-5362

    Unspecified vulnerability in Oracle Containers for J2EE component in Oracle Application Server 10.1.3.0.0 has unknown impact and remote attack vectors, aka Vuln# OC4J04.... Read more

    Affected Products : application_server
    • Published: Oct. 18, 2006
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2006-5349

    Unspecified vulnerability in Oracle HTTP Server 9.2.0.7, when running on HP Tru64 UNIX, has unknown impact and remote attack vectors related to HTTPS and SSL, aka Vuln# OHS07.... Read more

    Affected Products : http_server
    • Published: Oct. 18, 2006
    • Modified: Apr. 09, 2025
Showing 20 of 293258 Results