Latest CVE Feed
-
10.0
HIGHCVE-2003-0648
Multiple buffer overflows in vfte, based on FTE, before 0.50, allow local users to execute arbitrary code.... Read more
- EPSS Score: %1.76
- Published: May. 04, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2003-0201
Buffer overflow in the call_trans2open function in trans2.c for Samba 2.2.x before 2.2.8a, 2.0.10 and earlier 2.0.x versions, and Samba-TNG before 0.3.2, allows remote attackers to execute arbitrary code.... Read more
- EPSS Score: %80.77
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2006-3700
Multiple unspecified vulnerabilities in Oracle Database 9.2.0.6 and 10.1.0.4 have unknown impact and attack vectors, aka Oracle Vuln# (1) DB04 for Web Distributed Authoring and Versioning (DAV) and (2) DB23 for XMLDB.... Read more
Affected Products : database_server- EPSS Score: %3.61
- Published: Jul. 21, 2006
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0609
Format string vulnerability in Infodrom cfingerd 1.4.3 and earlier allows a remote attacker to gain additional privileges via a malformed ident reply that is passed to the syslog function.... Read more
Affected Products : cfingerd- EPSS Score: %9.91
- Published: Aug. 02, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0133
The web administration interface for Interscan VirusWall 3.6.x and earlier does not use encryption, which could allow remote attackers to obtain the administrator password to sniff the administrator password via the setpasswd.cgi program or other HTTP GET... Read more
Affected Products : interscan_viruswall- EPSS Score: %0.84
- Published: Mar. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0100
bslist.cgi mailing list script allows remote attackers to execute arbitrary commands via shell metacharacters in the email address.... Read more
Affected Products : bslist.cgi- EPSS Score: %18.80
- Published: Feb. 12, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-1077
Buffer overflow in the SHTML logging functionality of iPlanet Web Server 4.x allows remote attackers to execute arbitrary commands via a long filename with a .shtml extension.... Read more
Affected Products : iplanet_web_server- EPSS Score: %3.46
- Published: Dec. 11, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2000-0584
Buffer overflow in Canna input system allows remote attackers to execute arbitrary commands via an SR_INIT command with a long user name or group name.... Read more
- EPSS Score: %5.33
- Published: Jul. 02, 2000
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-1420
NBase switches NH2012, NH2012R, NH2015, and NH2048 have a back door password that cannot be disabled, which allows remote attackers to modify the switch's configuration.... Read more
- EPSS Score: %1.64
- Published: Jul. 20, 1998
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0937
BNBForm allows remote attackers to read arbitrary files via the automessage hidden form variable.... Read more
Affected Products :- EPSS Score: %2.01
- Published: Dec. 03, 1998
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0853
Buffer overflow in Netscape Enterprise Server and Netscape FastTrack Server allows remote attackers to gain privileges via the HTTP Basic Authentication procedure.... Read more
- EPSS Score: %0.93
- Published: Dec. 01, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0452
A service or application has a backdoor password that was placed there by the developer.... Read more
Affected Products :- EPSS Score: %0.48
- Published: Jan. 01, 1999
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-1999-0204
Sendmail 8.6.9 allows remote attackers to execute root commands, using ident.... Read more
Affected Products : sendmail- EPSS Score: %6.71
- Published: Jan. 01, 1997
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2025-20188
A vulnerability in the Out-of-Band Access Point (AP) Image Download, the Clean Air Spectral Recording, and the client debug bundles features of Cisco IOS XE Software for Wireless LAN Controllers (WLCs) could allow an unauthenticated, remote attacker to up... Read more
Affected Products : ios_xe- Published: May. 07, 2025
- Modified: Jun. 23, 2025
- Vuln Type: Authentication
-
10.0
CRITICALCVE-2024-5991
In function MatchDomainName(), input param str is treated as a NULL terminated string despite being user provided and unchecked. Specifically, the function X509_check_host() takes in a pointer and length to check against, with no requirements that it be N... Read more
Affected Products : wolfssl- Published: Aug. 27, 2024
- Modified: Sep. 06, 2024
-
10.0
CRITICALCVE-2024-44146
A logic issue was addressed with improved file handling. This issue is fixed in macOS Sequoia 15. An app may be able to break out of its sandbox.... Read more
Affected Products : macos- Published: Sep. 17, 2024
- Modified: Mar. 25, 2025
-
10.0
CRITICALCVE-2024-38999
jrburke requirejs v2.3.6 was discovered to contain a prototype pollution via the function s.contexts._.configure. This vulnerability allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via injecting arbitrary properties.... Read more
Affected Products :- Published: Jul. 01, 2024
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-22515
Atlassian has been made aware of an issue reported by a handful of customers where external attackers may have exploited a previously unknown vulnerability in publicly accessible Confluence Data Center and Server instances to create unauthorized Confluenc... Read more
- Actively Exploited
- EPSS Score: %94.36
- Published: Oct. 04, 2023
- Modified: Feb. 09, 2025
-
10.0
HIGHCVE-2022-22954
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in remote code executi... Read more
- Actively Exploited
- EPSS Score: %94.44
- Published: Apr. 11, 2022
- Modified: Mar. 12, 2025
-
10.0
CRITICALCVE-2021-41556
sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an out-of-bounds read (in the core interpreter) that can lead to Code Execution. If a victim executes an attacker-controlled squirrel script, it is possible for the attacker to break out of ... Read more
- EPSS Score: %0.56
- Published: Jul. 28, 2022
- Modified: Nov. 21, 2024