Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2020-3765

    Adobe After Effects versions 16.1.2 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more

    Affected Products : windows after_effects
    • EPSS Score: %2.56
    • Published: Feb. 20, 2020
    • Modified: May. 05, 2025
  • 10.0

    HIGH
    CVE-2000-0800

    String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.... Read more

    Affected Products : suse_linux
    • EPSS Score: %2.88
    • Published: Oct. 20, 2000
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2020-3746

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more

    • EPSS Score: %4.38
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2000-0012

    Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.... Read more

    Affected Products : msql
    • EPSS Score: %4.58
    • Published: Dec. 27, 1999
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2020-3743

    Adobe Acrobat and Reader versions 2019.021.20061 and earlier, 2017.011.30156 and earlier, 2017.011.30156 and earlier, and 2015.006.30508 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution .... Read more

    • EPSS Score: %4.38
    • Published: Feb. 13, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-1999-0042

    Buffer overflow in University of Washington's implementation of IMAP and POP servers.... Read more

    Affected Products : aix imap linux bsd_os openlinux pop
    • EPSS Score: %5.49
    • Published: Apr. 07, 1997
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2014-7279

    The Konke Smart Plug K does not require authentication for TELNET sessions, which allows remote attackers to obtain "equipment management authority" via TCP traffic to port 23.... Read more

    • EPSS Score: %57.90
    • Published: Mar. 23, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2014-7235

    htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserial... Read more

    Affected Products : freepbx freepbx
    • EPSS Score: %57.42
    • Published: Oct. 07, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-7192

    Eval injection vulnerability in index.js in the syntax-error package before 1.1.1 for Node.js 0.10.x, as used in IBM Rational Application Developer and other products, allows remote attackers to execute arbitrary code via a crafted file.... Read more

    Affected Products : node.js
    • EPSS Score: %43.94
    • Published: Dec. 11, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-7249

    Buffer overflow on the Allied Telesis AR440S, AR441S, AR442S, AR745, AR750S, AR750S-DP, AT-8624POE, AT-8624T/2M, AT-8648T/2SP, AT-8748XL, AT-8848, AT-9816GB, AT-9924T, AT-9924Ts, CentreCOM AR415S, CentreCOM AR450S, CentreCOM AR550S, CentreCOM AR570S, Cent... Read more

    • EPSS Score: %8.45
    • Published: Dec. 19, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-7232

    GE Healthcare Discovery XR656 and XR656 G2 has a password of (1) 2getin for the insite user, (2) 4$xray for the xruser user, and (3) #superxr for the root user, which has unspecified impact and attack vectors. NOTE: it is not clear whether these password... Read more

    • EPSS Score: %0.62
    • Published: Aug. 04, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-7169

    GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment... Read more

    • Actively Exploited
    • EPSS Score: %90.11
    • Published: Sep. 25, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2011-3548

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applet... Read more

    Affected Products : jre jdk
    • EPSS Score: %2.42
    • Published: Oct. 19, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-3554

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentialit... Read more

    Affected Products : jre jdk
    • EPSS Score: %2.86
    • Published: Oct. 19, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2007-0063

    Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 5501... Read more

    • EPSS Score: %7.59
    • Published: Sep. 21, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2020-3692

    u'Possible buffer overflow while updating output buffer for IMEI and Gateway Address due to lack of check of input validation for parameters received from server' in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, ... Read more

    • EPSS Score: %0.36
    • Published: Nov. 02, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-3686

    Possible memory out of bound issue during music playback when an incorrect bit stream content is copied into array without checking the length of array in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon In... Read more

    Affected Products : apq8009 apq8009w apq8017 apq8030 apq8037 apq8052 apq8053 apq8056 apq8060a apq8062 +482 more products
    • EPSS Score: %0.14
    • Published: Jan. 21, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2014-3525

    Unspecified vulnerability in Apache Traffic Server 3.x through 3.2.5, 4.x before 4.2.1.1, and 5.x before 5.0.1 has unknown impact and attack vectors, possibly related to health checks.... Read more

    Affected Products : traffic_server
    • EPSS Score: %1.27
    • Published: Aug. 22, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-3175

    Multiple unspecified vulnerabilities in Google Chrome before 37.0.2062.94 allow attackers to cause a denial of service or possibly have other impact via unknown vectors, related to the load_truetype_glyph function in truetype/ttgload.c in FreeType and oth... Read more

    Affected Products : chrome
    • EPSS Score: %2.03
    • Published: Aug. 27, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2020-3633

    Array out of bound may occur while playing mp3 file as no check is there on offset if it is greater than the buffer allocated or not in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon ... Read more

    • EPSS Score: %0.33
    • Published: Jun. 02, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 292737 Results