Latest CVE Feed
-
10.0
HIGHCVE-2011-3095
The OGG container in Google Chrome before 19.0.1084.46 allows remote attackers to cause a denial of service or possibly have unspecified other impact via unknown vectors that trigger an out-of-bounds write.... Read more
Affected Products : chrome- EPSS Score: %3.02
- Published: May. 16, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-2365
Unspecified vulnerability in the browser engine in Mozilla Firefox 3.6.x before 3.6.18 and Thunderbird before 3.1.11 allows remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unkn... Read more
- EPSS Score: %1.76
- Published: Jun. 30, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-2452
Adobe Flash Player before 10.3.183.11 and 11.x before 11.1.102.55 on Windows, Mac OS X, Linux, and Solaris and before 11.1.102.59 on Android, and Adobe AIR before 3.1.0.4880, allows attackers to execute arbitrary code or cause a denial of service (memory ... Read more
- EPSS Score: %1.77
- Published: Nov. 11, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-9864
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges.... Read more
- EPSS Score: %1.14
- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-1498
Persistent Systems Radia Client Automation does not properly restrict access to certain request, which allows remote attackers to (1) enumerate user accounts via a getUsers request, (2) assign a role to a user account via an addAssigneesToRole request, (3... Read more
Affected Products : radia_client_automation- EPSS Score: %1.30
- Published: Feb. 16, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2005-1009
Multiple buffer overflows in BakBone NetVault 6.x and 7.x allow (1) remote attackers to execute arbitrary code via a modified computer name and length that leads to a heap-based buffer overflow, or (2) local users to execute arbitrary code via a long Name... Read more
Affected Products : netvault- EPSS Score: %83.52
- Published: May. 02, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2015-1448
The integrated management service on Siemens Ruggedcom WIN51xx devices with firmware before SS4.4.4624.35, WIN52xx devices with firmware before SS4.4.4624.35, WIN70xx devices with firmware before BS4.4.4621.32, and WIN72xx devices with firmware before BS4... Read more
Affected Products : ruggedcom_firmware ruggedcom_win7000 ruggedcom_win7200 ruggedcom_win5100 ruggedcom_win5200- EPSS Score: %3.44
- Published: Feb. 02, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2020-17051
Windows Network File System Remote Code Execution Vulnerability... Read more
- EPSS Score: %18.02
- Published: Nov. 11, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-0492
Adobe Flash Player before 11.7.700.260 and 11.8.x and 11.9.x before 12.0.0.38 on Windows and Mac OS X and before 11.2.202.335 on Linux, Adobe AIR before 4.0.0.1390, Adobe AIR SDK before 4.0.0.1390, and Adobe AIR SDK & Compiler before 4.0.0.1390 allow atta... Read more
- EPSS Score: %3.22
- Published: Jan. 15, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2016-1052
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more
- EPSS Score: %10.86
- Published: May. 11, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1311
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely from third party ... Read more
Affected Products : hana_extended_application_services- EPSS Score: %1.70
- Published: Jan. 22, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1187
The ping tool in multiple D-Link and TRENDnet devices allow remote attackers to execute arbitrary code via the ping_addr parameter to ping.ccp.... Read more
Affected Products : dir-626l_firmware dir-636l_firmware dir-808l_firmware dir-810l_firmware dir-820l_firmware dir-826l_firmware dir-830l_firmware dir-836l_firmware tew-731br_firmware dir-651_firmware +20 more products- Actively Exploited
- EPSS Score: %78.16
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2024-32888
The Amazon JDBC Driver for Redshift is a Type 4 JDBC driver that provides database connectivity through the standard JDBC application program interfaces (APIs) available in the Java Platform, Enterprise Editions. Prior to version 2.1.0.28, SQL injection i... Read more
Affected Products :- Published: May. 15, 2024
- Modified: Jun. 12, 2025
-
10.0
HIGHCVE-2011-4245
The RealVideo renderer in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more
Affected Products : realplayer- EPSS Score: %5.22
- Published: Nov. 24, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2018-5090
Memory safety bugs were reported in Firefox 57. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 58.... Read more
- EPSS Score: %2.53
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2015-1158
The add_job function in scheduler/ipp.c in cupsd in CUPS before 2.0.3 performs incorrect free operations for multiple-value job-originating-host-name attributes, which allows remote attackers to trigger data corruption for reference-counted strings via a ... Read more
Affected Products : cups- EPSS Score: %77.00
- Published: Jun. 26, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-1066
Off-by-one error in IOAcceleratorFamily in Apple OS X through 10.10.2 allows attackers to execute arbitrary code in a privileged context via a crafted app.... Read more
- EPSS Score: %1.17
- Published: Mar. 12, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2013-6195
Unspecified vulnerability in HP Storage Data Protector 6.2X allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-2008.... Read more
Affected Products : storage_data_protector- EPSS Score: %27.67
- Published: Jan. 04, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2014-1541
Use-after-free vulnerability in the RefreshDriverTimer::TickDriver function in the SMIL Animation Controller in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allows remote attackers to execute arbitrary code or cau... Read more
- EPSS Score: %0.61
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2024-32741
A vulnerability has been identified in SIMATIC CN 4100 (All versions < V3.0). The affected device contains hard coded password which is used for the privileged system user `root` and for the boot loader `GRUB` by default . An attacker who manages to crack... Read more
- Published: May. 14, 2024
- Modified: Aug. 26, 2025