Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2008-4731

    Multiple unspecified vulnerabilities in YaCy before 0.61 have unknown impact and attack vectors.... Read more

    Affected Products : yacy
    • EPSS Score: %0.37
    • Published: Oct. 24, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-2362

    Fonality (previously trixbox Pro) 12.6 through 14.1i before 2016-06-01 has a hardcoded password for the FTP account, which allows remote attackers to obtain access via a (1) FTP or (2) SSH connection.... Read more

    Affected Products : fonality
    • EPSS Score: %0.89
    • Published: Jun. 20, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2018-1216

    A hard-coded password vulnerability was discovered in vApp Manager which is embedded in Dell EMC Unisphere for VMAX, Dell EMC Solutions Enabler, Dell EMC VASA Virtual Appliances, and Dell EMC VMAX Embedded Management (eManagement): Dell EMC Unisphere for ... Read more

    • EPSS Score: %26.14
    • Published: Mar. 08, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-2720

    Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-20... Read more

    Affected Products : acrobat acrobat_reader
    • EPSS Score: %13.75
    • Published: May. 16, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2009-4024

    Argument injection vulnerability in the ping function in Ping.php in the Net_Ping package before 2.4.5 for PEAR allows remote attackers to execute arbitrary shell commands via the host parameter. NOTE: this has also been reported as a shell metacharacter... Read more

    Affected Products : pear pear
    • EPSS Score: %2.81
    • Published: Nov. 29, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2015-7641

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.252 and 19.x before 19.0.0.207 on Windows and OS X and before 11.2.202.535 on Linux, Adobe AIR before 19.0.0.213, Adobe AIR SDK before 19.0.0.213, and Adobe AIR SDK & Compiler before 19.0.0.... Read more

    • EPSS Score: %9.68
    • Published: Oct. 18, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2011-0496

    Unspecified vulnerability in Sybase EAServer 5.x and 6.x before 6.3 ESD#2, as used in Appeon, Replication Server Messaging Edition (RSME), and WorkSpace, allows remote attackers to install arbitrary web services and execute arbitrary code, related to a "d... Read more

    • EPSS Score: %11.61
    • Published: Jan. 20, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2016-5118

    The OpenBlob function in blob.c in GraphicsMagick before 1.3.24 and ImageMagick allows remote attackers to execute arbitrary code via a | (pipe) character at the start of a filename.... Read more

    • EPSS Score: %35.42
    • Published: Jun. 10, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    CRITICAL
    CVE-2019-7003

    A SQL injection vulnerability in the reporting component of Avaya Control Manager could allow an unauthenticated attacker to execute arbitrary SQL commands and retrieve sensitive data related to other users on the system. Affected versions of Avaya Contro... Read more

    Affected Products : control_manager
    • EPSS Score: %1.15
    • Published: Jul. 11, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-9054

    Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NA... Read more

    • Actively Exploited
    • EPSS Score: %94.31
    • Published: Mar. 04, 2020
    • Modified: Mar. 21, 2025
  • 10.0

    HIGH
    CVE-2016-6138

    Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.... Read more

    Affected Products : trex
    • EPSS Score: %20.32
    • Published: Aug. 05, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2020-15610

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When par... Read more

    Affected Products : webpanel
    • EPSS Score: %2.07
    • Published: Jul. 28, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2006-2304

    Multiple integer overflows in the DPRPC library (DPRPCW32.DLL) in Novell Client 4.83 SP3, 4.90 SP2 and 4.91 SP2 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which trigger... Read more

    Affected Products : client
    • EPSS Score: %13.23
    • Published: May. 11, 2006
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2016-6969

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more

    • EPSS Score: %1.97
    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-4006

    Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : secure_backup
    • EPSS Score: %2.33
    • Published: Jan. 14, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2016-6980

    Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4263.... Read more

    Affected Products : digital_editions
    • EPSS Score: %6.52
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-0500

    Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0501.... Read more

    Affected Products : shockwave_player
    • EPSS Score: %24.48
    • Published: Feb. 12, 2014
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3559

    Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the prev... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %13.66
    • Published: Oct. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2008-4562

    Buffer overflow in the ovlaunch CGI program in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 on Windows allows remote attackers to execute arbitrary code via a crafted Host parameter. NOTE: this issue may be partially covered by CVE-2009-... Read more

    Affected Products : openview_network_node_manager
    • EPSS Score: %5.57
    • Published: Feb. 08, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2018-5749

    install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary ... Read more

    • EPSS Score: %3.15
    • Published: Jan. 23, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292124 Results