Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2016-6567

    SHDesigns' Resident Download Manager provides firmware update capabilities for Rabbit 2000/3000 CPU boards, which according to the reporter may be used in some industrial control and embedded applications. The Resident Download Manager does not verify tha... Read more

    Affected Products : resident_download_manager
    • EPSS Score: %1.25
    • Published: Jul. 13, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2018-3907

    An exploitable vulnerability exists in the REST parser of video-core's HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The video-core process incorrectly handles pipelined HTTP requests, which allows successive requests ... Read more

    Affected Products : sth-eth-250_firmware sth-eth-250
    • EPSS Score: %0.48
    • Published: Aug. 24, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2017-14078

    SQL Injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.... Read more

    Affected Products : mobile_security
    • EPSS Score: %66.34
    • Published: Sep. 22, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2017-14915

    In Android before 2018-01-05 on Qualcomm Snapdragon Mobile SD 625, SD 650/52, SD 835, accessing SPCOM functions with a compromised client structure can result in a Use After Free condition.... Read more

    • EPSS Score: %0.87
    • Published: Mar. 30, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2014-10056

    In Android before 2018-04-05 or earlier security patch level on Qualcomm Snapdragon Mobile SD 210/SD 212/SD 205, A buffer overflow can potentially occur in any OpenCL application that calls clBuildProgram() with a device of type CL_DEVICE_TYPE_CPU in its ... Read more

    • EPSS Score: %0.23
    • Published: Apr. 18, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2024-6209

    Unauthorized file access in WEB Server in ABB ASPECT - Enterprise v3.08.01; NEXUS Series v3.08.01 ; MATRIX Series v3.08.01 allows Attacker to access files unauthorized... Read more

    • Published: Jul. 05, 2024
    • Modified: Dec. 05, 2024
  • 10.0

    HIGH
    • EPSS Score: %8.86
    • Published: Nov. 10, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2022-25434

    Tenda AC9 v15.03.2.21 was discovered to contain a stack overflow via the firewallen parameter in the SetFirewallCfg function.... Read more

    Affected Products : ac9_firmware ac9
    • EPSS Score: %2.39
    • Published: Mar. 18, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2024-37143

    Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions p... Read more

    Affected Products : data_lakehouse
    • Published: Dec. 10, 2024
    • Modified: Dec. 10, 2024
  • 10.0

    CRITICAL
    CVE-2025-30580

    Improper Control of Generation of Code ('Code Injection') vulnerability in NotFound DigiWidgets Image Editor allows Remote Code Inclusion. This issue affects DigiWidgets Image Editor: from n/a through 1.10.... Read more

    Affected Products :
    • Published: Apr. 01, 2025
    • Modified: Apr. 02, 2025
    • Vuln Type: Injection
  • 10.0

    HIGH
    CVE-2006-0218

    Multiple unspecified vulnerabilities in MyBulletinBoard (MyBB) before 1.0.2 have unspecified impact and attack vectors, related to (1) admin/moderate.php, (2) admin/themes.php, (3) inc/functions.php, (4) inc/functions_upload.php, (5) printthread.php, and ... Read more

    Affected Products : mybb
    • EPSS Score: %0.31
    • Published: Jan. 16, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2006-0271

    Unspecified vulnerability in the Upgrade & Downgrade component of Oracle Database server 8.1.7.4, 9.0.1.5, 9.2.0.7, and 10.1.0.4 has unspecified impact and attack vectors, as identified by Oracle Vuln# DB28. NOTE: details are unavailable from Oracle, but... Read more

    • EPSS Score: %1.39
    • Published: Jan. 18, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0101

    Vulnerability in fetchmail 5.5.0-2 and earlier in the AUTHENTICATE GSSAPI command.... Read more

    Affected Products : fetchmail
    • EPSS Score: %0.44
    • Published: Feb. 12, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0180

    Lars Ellingsen guestserver.cgi allows remote attackers to execute arbitrary commands via shell metacharacters in the "email" parameter.... Read more

    Affected Products : guestserver
    • EPSS Score: %2.53
    • Published: May. 03, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0372

    Akopia Interchange 4.5.3 through 4.6.3 installs demo stores with a default group account :backup with no password, which allows a remote attacker to gain administrative access via the demo stores (1) barry, (2) basic, or (3) construct.... Read more

    Affected Products : akopia_interchange
    • EPSS Score: %1.55
    • Published: Jun. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0434

    Marcus S. Xenakis directory.php script allows remote attackers to execute arbitrary commands via shell metacharacters in the dir parameter.... Read more

    Affected Products : directory.php
    • EPSS Score: %2.73
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-0602

    A network intrusion detection system (IDS) does not properly reassemble fragmented packets.... Read more

    Affected Products :
    • EPSS Score: %0.48
    • Published: Jan. 01, 1999
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-1081

    Aspppls for Solaris 8 allows local users to overwrite arbitrary files via a symlink attack on the .asppp.fifo temporary file.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %2.20
    • Published: Sep. 09, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-0201

    Heap-based buffer overflow in the HtmlHelp program (hh.exe) in HTML Help for Microsoft Windows 98, Me, NT 4.0, 2000, XP, and Server 2003 allows remote attackers to execute arbitrary commands via a .CHM file with a large length field, a different vulnerabi... Read more

    • EPSS Score: %45.13
    • Published: Aug. 06, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-1024

    eWave ServletExec 3.0C and earlier does not restrict access to the UploadServlet Java/JSP servlet, which allows remote attackers to upload files and execute arbitrary commands.... Read more

    Affected Products : ewave_servletexec
    • EPSS Score: %2.32
    • Published: Dec. 11, 2000
    • Modified: Apr. 03, 2025
Showing 20 of 291898 Results