Latest CVE Feed
-
10.0
HIGHCVE-2008-7164
Multiple unspecified vulnerabilities in Shareaza before 2.3.1.0 have unknown impact and attack vectors related to "very important security fixes," possibly involving update notifications and a domain that is no longer controlled by the vendor.... Read more
Affected Products : shareaza- EPSS Score: %0.43
- Published: Sep. 04, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-7173
The Jura Internet Connection Kit for the Jura Impressa F90 coffee maker does not properly restrict access to privileged functions, which allows remote attackers to cause a denial of service (physical damage), modify coffee settings, and possibly execute c... Read more
- EPSS Score: %12.59
- Published: Sep. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2008-7200
Double free vulnerability in Deliantra server engine before 2.4 has unknown impact and attack vectors.... Read more
Affected Products : deliantra- EPSS Score: %0.34
- Published: Sep. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3843
HP Operations Manager 8.10 on Windows contains a "hidden account" in the XML file that specifies Tomcat users, which allows remote attackers to conduct unrestricted file upload attacks, and thereby execute arbitrary code, by using the org.apache.catalina.... Read more
Affected Products : operations_manager- EPSS Score: %86.83
- Published: Nov. 24, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-4514
The TELNET daemon in Siemens WinCC flexible 2004, 2005, 2007, and 2008; WinCC V11 (aka TIA portal); the TP, OP, MP, Comfort Panels, and Mobile Panels SIMATIC HMI panels; WinCC V11 Runtime Advanced; and WinCC flexible Runtime does not perform authenticatio... Read more
Affected Products : wincc wincc_flexible simatic_hmi_panels wincc_runtime_advanced wincc_flexible_runtime- EPSS Score: %0.55
- Published: Feb. 03, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-1805
Buffer overflow in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to execute arbitrary code via long strings in unspecified parameters.... Read more
- EPSS Score: %7.58
- Published: Apr. 13, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-6392
Cisco Prime LAN Management Solution (LMS) 4.1 through 4.2.2 on Linux does not properly validate authentication and authorization requests in TCP sessions, which allows remote attackers to execute arbitrary commands via a crafted session, aka Bug ID CSCuc7... Read more
- EPSS Score: %4.18
- Published: Jan. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4610
Unspecified vulnerability in the Data Search utility in data-entry forms in REDCap before 5.0.3 and 5.1.x before 5.1.2 has unknown impact and remote attack vectors.... Read more
- EPSS Score: %0.32
- Published: Jun. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4937
Multiple unspecified vulnerabilities in the AiCloud feature on the ASUS RT-AC66U, RT-N66U, RT-N65U, RT-N14U, RT-N16, RT-N56U, and DSL-N55U with firmware before 3.0.4.372 have unknown impact and attack vectors.... Read more
Affected Products : rt-ac66u_firmware rt-n56u_firmware rt-n14u_firmware rt-n16_firmware rt-n65u_firmware rt-n66u_firmware rt-n66u rt-n56u rt-ac66u rt-n65u +4 more products- EPSS Score: %0.53
- Published: Jul. 26, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-3454
Cisco TelePresence System Software 1.10.1 and earlier on 500, 13X0, 1X00, 30X0, and 3X00 devices, and 6.0.3 and earlier on TX 9X00 devices, has a default password for the pwrecovery account, which makes it easier for remote attackers to modify the configu... Read more
Affected Products : telepresence_system_software telepresence_system_1300-65 telepresence_system_3000 telepresence_system_3010 telepresence_system_3200 telepresence_system_3210 telepresence_system_500-37 telepresence_system_500-32 telepresence_system_tx9000 telepresence_system_tx9200 +1 more products- EPSS Score: %0.84
- Published: Aug. 08, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2006-1886
Unspecified vulnerability in the PeopleTools component in Oracle PeopleSoft Enterprise 8.46.12 and 8.47.04 has unknown impact and attack vectors, aka Vuln# PSE01.... Read more
Affected Products : peoplesoft_enterprise- EPSS Score: %2.30
- Published: Apr. 20, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2016-3149
Barco ClickShare CSC-1 devices with firmware before 01.09.03 and CSM-1 devices with firmware before 01.06.02 allow remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : clickshare_csm-1_firmware clickshare_csc-1_firmware clickshare_csc-1 clickshare_csm-1- EPSS Score: %14.22
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2013-6343
Multiple buffer overflows in web.c in httpd on the ASUS RT-N56U and RT-AC66U routers with firmware 3.0.0.4.374_979 allow remote attackers to execute arbitrary code via the (1) apps_name or (2) apps_flag parameter to APP_Installation.asp.... Read more
Affected Products : rt-ac66u_firmware rt-n56u_firmware tm-ac1900_firmware rt-n56u rt-ac66u tm-ac1900- EPSS Score: %36.56
- Published: Jan. 22, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-0278
libuv before 0.10.34 does not properly drop group privileges, which allows context-dependent attackers to gain privileges via unspecified vectors.... Read more
- EPSS Score: %1.59
- Published: May. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
CRITICALCVE-2018-17160
In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the bhyve host possibly permitting arbitrary code execution. ... Read more
Affected Products : freebsd- EPSS Score: %0.79
- Published: Dec. 04, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-20434
LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostna... Read more
Affected Products : librenms- EPSS Score: %66.99
- Published: Apr. 24, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-10950
Fujifilm FCR Capsula X/ Carbon X/ FCR XC-2, model versions CR-IR 357 FCR Carbon X, CR-IR 357 FCR XC-2, FCR-IR 357 FCR Capsula X provide insecure telnet services that lack authentication requirements. An attacker who successfully exploits this vulnerabilit... Read more
- EPSS Score: %1.13
- Published: Apr. 30, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-2046
In CalculateInstanceSizeForDerivedClass of objects.cc, there is possible memory corruption due to an integer overflow. This could lead to remote code execution in the proxy auto-config with no additional execution privileges needed. User interaction is no... Read more
Affected Products : android- EPSS Score: %1.18
- Published: May. 08, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-19989
In the /HNAP1/SetQoSSettings message, the uplink parameter is vulnerable, and the vulnerability affects D-Link DIR-822 Rev.B 202KRb06 and DIR-822 Rev.C 3.10B06 devices. In the SetQoSSettings.php source code, the uplink parameter is saved in the /bwc/entry... Read more
- EPSS Score: %32.75
- Published: May. 13, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-9871
Jector Smart TV FM-K75 devices allow remote code execution because there is an adb open port with root permission.... Read more
- EPSS Score: %6.89
- Published: May. 31, 2019
- Modified: Nov. 21, 2024