Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2003-1425

    guestbook.cgi in cPanel 5.0 allows remote attackers to execute arbitrary commands via the template parameter.... Read more

    Affected Products : cpanel
    • EPSS Score: %3.68
    • Published: Dec. 31, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2016-2554

    Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TAR archive.... Read more

    Affected Products : php
    • EPSS Score: %16.57
    • Published: May. 16, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-0543

    Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Co... Read more

    • EPSS Score: %0.66
    • Published: Aug. 12, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    CRITICAL
    CVE-2020-6207

    SAP Solution Manager (User Experience Monitoring), version- 7.2, due to Missing Authentication Check does not perform any authentication for a service resulting in complete compromise of all SMDAgents connected to the Solution Manager.... Read more

    Affected Products : solution_manager
    • Actively Exploited
    • EPSS Score: %94.27
    • Published: Mar. 10, 2020
    • Modified: Mar. 13, 2025
  • 10.0

    CRITICAL
    CVE-2020-6287

    SAP NetWeaver AS JAVA (LM Configuration Wizard), versions - 7.30, 7.31, 7.40, 7.50, does not perform an authentication check which allows an attacker without prior authentication to execute configuration tasks to perform critical actions against the SAP J... Read more

    • Actively Exploited
    • EPSS Score: %94.40
    • Published: Jul. 14, 2020
    • Modified: Mar. 13, 2025
  • 10.0

    HIGH
    CVE-2008-0401

    Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary c... Read more

    • EPSS Score: %28.52
    • Published: Jan. 23, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2015-0301

    Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe... Read more

    • EPSS Score: %7.40
    • Published: Jan. 13, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-6998

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more

    • EPSS Score: %2.24
    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-7019

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more

    • EPSS Score: %5.86
    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-7406

    Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.... Read more

    Affected Products : dropbear_ssh
    • EPSS Score: %8.15
    • Published: Mar. 03, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2004-0623

    Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.... Read more

    Affected Products : gnats
    • EPSS Score: %3.45
    • Published: Dec. 06, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2008-3107

    Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an u... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %14.53
    • Published: Jul. 09, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-3108

    Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to fo... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %10.64
    • Published: Jul. 09, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2015-3039

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more

    • EPSS Score: %8.70
    • Published: Apr. 14, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-4059

    Heap-based buffer overflow in the License Server (LicenseServer.exe) in Wavelink Terminal Emulation (TE) allows remote attackers to execute arbitrary code via a large HTTP header.... Read more

    Affected Products : terminal_emulation
    • EPSS Score: %11.63
    • Published: May. 29, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-4032

    projectContents.jsp in the Developer tools in Visual Mining NetCharts Server allows remote attackers to rename arbitrary files, and consequently execute them, via unspecified vectors.... Read more

    Affected Products : netcharts_server
    • EPSS Score: %1.30
    • Published: May. 29, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-5589

    The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (segmenta... Read more

    Affected Products : php
    • EPSS Score: %8.49
    • Published: May. 16, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-3964

    SMA Solar Sunny WebBox has hardcoded passwords, which makes it easier for remote attackers to obtain access via unspecified vectors.... Read more

    Affected Products : webbox_firmware
    • EPSS Score: %0.91
    • Published: Sep. 11, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2020-5902

    In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vulnerability in und... Read more

    • Actively Exploited
    • EPSS Score: %94.44
    • Published: Jul. 01, 2020
    • Modified: Apr. 02, 2025
  • 10.0

    HIGH
    CVE-2015-0304

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SD... Read more

    • EPSS Score: %8.01
    • Published: Jan. 13, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 292508 Results