Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2013-0011

    The Print Spooler in Microsoft Windows Server 2008 R2 and R2 SP1 and Windows 7 Gold and SP1 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted print job, aka "Windows Print Spooler Components V... Read more

    Affected Products : windows_7 windows_server_2008
    • Published: Jan. 09, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2024-24621

    Softaculous Webuzo contains an authentication bypass vulnerability through the password reset functionality. Remote, anonymous attackers can exploit this vulnerability to gain full server access as the root user.... Read more

    Affected Products : webuzo
    • Published: Jul. 25, 2024
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2019-16028

    A vulnerability in the web-based management interface of Cisco Firepower Management Center (FMC) could allow an unauthenticated, remote attacker to bypass authentication and execute arbitrary actions with administrative privileges on an affected device. T... Read more

    • Published: Sep. 23, 2020
    • Modified: Nov. 26, 2024
  • 10.0

    HIGH
    CVE-2013-3175

    Microsoft Windows XP SP2 and SP3, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT allow remote attackers to execute arbitrary code via a malformed asynchronous R... Read more

    • Published: Aug. 14, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2021-38391

    A Blind SQL injection vulnerability exists in the /DataHandler/AM/AM_Handler.ashx endpoint of Delta Electronics DIAEnergie Version 1.7.5 and prior. The application does not properly validate the user-controlled value supplied through the parameter type be... Read more

    Affected Products : diaenergie
    • Published: Aug. 30, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-0603

    Heap-based buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.3, 10.x before 10.1.5, and 11.x before 11.0.1 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-0604.... Read more

    Affected Products : acrobat acrobat_reader
    • Published: Jan. 10, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-0638

    Adobe Flash Player before 10.3.183.63 and 11.x before 11.6.602.168 on Windows, before 10.3.183.61 and 11.x before 11.6.602.167 on Mac OS X, before 10.3.183.61 and 11.x before 11.2.202.270 on Linux, before 11.1.111.43 on Android 2.x and 3.x, and before 11.... Read more

    • Published: Feb. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2007-0445

    Heap-based buffer overflow in the arj.ppl module in the OnDemand Scanner in Kaspersky Anti-Virus, Anti-Virus for Workstations, and Anti-Virus for File Servers 6.0, and Internet Security 6.0 before Maintenance Pack 2 build 6.0.2.614 allows remote attackers... Read more

    • Published: Apr. 06, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2013-2940

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.... Read more

    Affected Products : cloudportal_services_manager
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2936

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.... Read more

    Affected Products : cloudportal_services_manager
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2935

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.... Read more

    Affected Products : cloudportal_services_manager
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2933

    Unspecified vulnerability in Citrix CloudPortal Services Manager (aka Cortex) 10.0 before Cumulative Update 3 has unknown impact and attack vectors, a different vulnerability than other CVEs listed in CTX137162.... Read more

    Affected Products : cloudportal_services_manager
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2931

    Multiple unspecified vulnerabilities in Google Chrome before 31.0.1650.48 allow attackers to execute arbitrary code or possibly have other impact via unknown vectors.... Read more

    Affected Products : chrome
    • Published: Nov. 13, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-5251

    Buffer overflow in Adobe Flash Player before 10.3.183.29 and 11.x before 11.4.402.287 on Windows and Mac OS X, before 10.3.183.29 and 11.x before 11.2.202.243 on Linux, before 11.1.111.19 on Android 2.x and 3.x, and before 11.1.115.20 on Android 4.x; Adob... Read more

    • Published: Oct. 09, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2820

    The Sierra Wireless AirLink Raven X EV-DO gateway 4221_4.0.11.003 and 4228_4.0.11.003 allows remote attackers to reprogram the firmware via a replay attack using UDP ports 17336 and 17388.... Read more

    • Published: Jan. 15, 2014
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2802

    The universal protocol implementation in Sixnet UDR before 2.0 and RTU firmware before 4.8 allows remote attackers to execute arbitrary code; read, modify, or create files; or obtain file metadata via function opcodes.... Read more

    Affected Products : udr rtu_firmware
    • Published: Aug. 21, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2015-8066

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.268 and 19.x and 20.x before 20.0.0.228 on Windows and OS X and before 11.2.202.554 on Linux, Adobe AIR before 20.0.0.204, Adobe AIR SDK before 20.0.0.204, and Adobe AIR SDK & Compiler befor... Read more

    • Published: Dec. 10, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6682

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.... Read more

    • Published: Sep. 22, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2013-2781

    Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.... Read more

    Affected Products : codesys_gateway-server
    • Published: May. 23, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-5141

    Google Chrome before 23.0.1271.97 does not properly restrict instantiation of the Chromoting client plug-in, which has unspecified impact and attack vectors.... Read more

    Affected Products : chrome opensuse
    • Published: Dec. 12, 2012
    • Modified: Apr. 11, 2025
Showing 20 of 293261 Results