Latest CVE Feed
-
10.0
HIGHCVE-2020-9054
Multiple ZyXEL network-attached storage (NAS) devices running firmware version 5.21 contain a pre-authentication command injection vulnerability, which may allow a remote, unauthenticated attacker to execute arbitrary code on a vulnerable device. ZyXEL NA... Read more
Affected Products : usg20-vpn_firmware usg20w-vpn_firmware usg40_firmware usg40w_firmware usg60_firmware usg60w_firmware usg110_firmware usg210_firmware usg310_firmware usg1100_firmware +44 more products- Actively Exploited
- EPSS Score: %94.31
- Published: Mar. 04, 2020
- Modified: Mar. 21, 2025
-
10.0
HIGHCVE-2016-6138
Directory traversal vulnerability in SAP TREX 7.10 Revision 63 allows remote attackers to read arbitrary files via unspecified vectors, aka SAP Security Note 2203591.... Read more
Affected Products : trex- EPSS Score: %20.32
- Published: Aug. 05, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2020-15610
This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_php_pecl.php. When par... Read more
Affected Products : webpanel- EPSS Score: %2.07
- Published: Jul. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-2304
Multiple integer overflows in the DPRPC library (DPRPCW32.DLL) in Novell Client 4.83 SP3, 4.90 SP2 and 4.91 SP2 allow remote attackers to execute arbitrary code via an XDR encoded array with a field that specifies a large number of elements, which trigger... Read more
Affected Products : client- EPSS Score: %13.23
- Published: May. 11, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2016-6969
Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more
- EPSS Score: %1.97
- Published: Oct. 13, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2008-4006
Unspecified vulnerability in the Oracle Secure Backup component in Oracle Secure Backup 10.1.0.3 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : secure_backup- EPSS Score: %2.33
- Published: Jan. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-6980
Use-after-free vulnerability in Adobe Digital Editions before 4.5.2 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2016-4263.... Read more
Affected Products : digital_editions- EPSS Score: %6.52
- Published: Sep. 26, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0500
Adobe Shockwave Player before 12.0.9.149 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0501.... Read more
Affected Products : shockwave_player- EPSS Score: %24.48
- Published: Feb. 12, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-3559
Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the prev... Read more
- EPSS Score: %13.66
- Published: Oct. 19, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2008-4562
Buffer overflow in the ovlaunch CGI program in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 on Windows allows remote attackers to execute arbitrary code via a crafted Host parameter. NOTE: this issue may be partially covered by CVE-2009-... Read more
Affected Products : openview_network_node_manager- EPSS Score: %5.57
- Published: Feb. 08, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-5749
install.php in Minecraft Servers List Lite before commit c1cd164 and Premium Minecraft Servers List before 2.0.4 does not sanitize input before saving database connection information in connect.php, which might allow remote attackers to execute arbitrary ... Read more
- EPSS Score: %3.15
- Published: Jan. 23, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2006-3742
The KDE PAM configuration shipped with Fedora Core 5 causes KDM passwords to be cached, which allows attackers to login without a password by attempting to log in multiple times.... Read more
Affected Products : kdebase- EPSS Score: %0.39
- Published: Sep. 06, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2022-30105
In Belkin N300 Firmware 1.00.08, the script located at /setting_hidden.asp, which is accessible before and after configuring the device, exhibits multiple remote command injection vulnerabilities. The following parameters in the [form name] form; [list vu... Read more
- EPSS Score: %3.58
- Published: May. 18, 2022
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2021-39615
D-Link DSR-500N version 1.02 contains hard-coded credentials for undocumented user accounts in the '/etc/passwd' file.If an attacker succeeds in recovering the cleartext password of the identified hash value, he will be able to log in via SSH or Telnet an... Read more
- EPSS Score: %2.20
- Published: Aug. 23, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-5306
GE Healthcare Optima CT680, CT540, CT640, and CT520 has a default password of #bigguy for the root user, which has unspecified impact and attack vectors.... Read more
- EPSS Score: %1.61
- Published: Aug. 04, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2013-4983
The get_referers function in /opt/ws/bin/sblistpack in Sophos Web Appliance before 3.7.9.1 and 3.8 before 3.8.1.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to end-user/index.php.... Read more
- EPSS Score: %92.69
- Published: Sep. 10, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2011-0271
The CGI scripts in HP OpenView Network Node Manager (OV NNM) 7.51 and 7.53 do not properly validate an unspecified parameter, which allows remote attackers to execute arbitrary commands by using a command string for this parameter's value, related to a "c... Read more
Affected Products : openview_network_node_manager- EPSS Score: %26.60
- Published: Jan. 13, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2010-4235
Format string vulnerability in RealNetworks Helix Server 12.x, 13.x, and 14.x before 14.2, and Helix Mobile Server 12.x, 13.x, and 14.x before 14.2, allows remote attackers to execute arbitrary code via vectors related to the x-wap-profile HTTP header.... Read more
- EPSS Score: %4.35
- Published: Apr. 04, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2009-0228
Stack-based buffer overflow in the EnumeratePrintShares function in Windows Print Spooler Service (win32spl.dll) in Microsoft Windows 2000 SP4 allows remote printer servers to execute arbitrary code via a crafted ShareName in a response to an RPC request,... Read more
Affected Products : windows_2000- EPSS Score: %41.21
- Published: Jun. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2011-0914
Integer signedness error in ndiiop.exe in the DIIOP implementation in the server in IBM Lotus Domino before 8.5.3 allows remote attackers to execute arbitrary code via a GIOP client request, leading to a heap-based buffer overflow.... Read more
Affected Products : lotus_domino- EPSS Score: %11.11
- Published: Feb. 08, 2011
- Modified: Apr. 11, 2025