Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2013-4977

    Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrar... Read more

    Affected Products : ds-2cd7153-e_firmware ds-2cd7153-e
    • EPSS Score: %56.34
    • Published: Mar. 03, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2013-4316

    Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.... Read more

    • EPSS Score: %7.07
    • Published: Sep. 30, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3268

    Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.... Read more

    Affected Products : imanager
    • EPSS Score: %0.19
    • Published: Apr. 24, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2736

    Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-20... Read more

    Affected Products : acrobat acrobat_reader
    • EPSS Score: %18.88
    • Published: May. 16, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2733

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.... Read more

    Affected Products : acrobat acrobat_reader
    • EPSS Score: %2.74
    • Published: May. 16, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2383

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity,... Read more

    Affected Products : jdk jre jre jdk
    • EPSS Score: %7.36
    • Published: Apr. 17, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2333

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %81.83
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2015-6683

    Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow... Read more

    • EPSS Score: %5.38
    • Published: Oct. 14, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6680

    Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6681.... Read more

    Affected Products : shockwave_player
    • EPSS Score: %9.40
    • Published: Sep. 09, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6681

    Adobe Shockwave Player before 12.2.0.162 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6680.... Read more

    Affected Products : shockwave_player
    • EPSS Score: %2.56
    • Published: Sep. 09, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6677

    Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute a... Read more

    • EPSS Score: %6.37
    • Published: Sep. 22, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2020-9027

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the TRACE field of the resource ping.cmd. The NTP-2 device is also affected.... Read more

    • EPSS Score: %3.19
    • Published: Feb. 17, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-9026

    ELTEX NTP-RG-1402G 1v10 3.25.3.32 devices allow OS command injection via the PING field of the resource ping.cmd. The NTP-2 device is also affected.... Read more

    • EPSS Score: %3.19
    • Published: Feb. 17, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-1385

    Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.... Read more

    Affected Products : shockwave_player
    • EPSS Score: %1.83
    • Published: Apr. 10, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-0689

    The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitra... Read more

    • EPSS Score: %3.26
    • Published: Oct. 03, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-0639

    Integer overflow in Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and... Read more

    • EPSS Score: %12.99
    • Published: Feb. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-0621

    Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0606, CVE-2013-0612, CVE-2013-0615, and CV... Read more

    Affected Products : acrobat acrobat_reader
    • EPSS Score: %7.91
    • Published: Jan. 10, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    CRITICAL
    CVE-2020-8967

    There is an improper Neutralization of Special Elements used in an SQL Command (SQL Injection) vulnerability in php files of GESIO ERP. GESIO ERP all versions prior to 11.2 allows malicious users to retrieve all database information.... Read more

    Affected Products : erp
    • EPSS Score: %0.26
    • Published: Jun. 01, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2012-6706

    A VMSF_DELTA memory corruption was discovered in unrar before 5.5.5, as used in Sophos Anti-Virus Threat Detection Engine before 3.37.2 and other products, that can lead to arbitrary code execution. An integer overflow can be caused in DataSize+CurChannel... Read more

    Affected Products : unrar threat_detection_engine
    • EPSS Score: %2.83
    • Published: Jun. 22, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2020-9020

    Iteris Vantage Velocity Field Unit 2.3.1, 2.4.2, and 3.0 devices allow the injection of OS commands into cgi-bin/timeconfig.py via shell metacharacters in the NTP Server field.... Read more

    • EPSS Score: %0.54
    • Published: Feb. 17, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 292495 Results