Latest CVE Feed
-
10.0
HIGHCVE-2014-2867
Unrestricted file upload vulnerability in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allows remote attackers to execute arbitrary code by uploading a ColdFusion page, and then accessing it via unspecified vectors.... Read more
Affected Products : commonspot_content_server- EPSS Score: %4.11
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-1563
Use-after-free vulnerability in the mozilla::DOMSVGLength::GetTearOff function in Mozilla Firefox before 32.0, Firefox ESR 31.x before 31.1, and Thunderbird 31.x before 31.1 allows remote attackers to execute arbitrary code or cause a denial of service (h... Read more
- EPSS Score: %1.15
- Published: Sep. 03, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-1536
The PropertyProvider::FindJustificationRange function in Mozilla Firefox before 30.0 allows remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.... Read more
Affected Products : firefox- EPSS Score: %0.67
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-1533
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 30.0, Firefox ESR 24.x before 24.6, and Thunderbird before 24.6 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly ... Read more
- EPSS Score: %3.42
- Published: Jun. 11, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-1236
Stack-based buffer overflow in the chkNum function in lib/cgraph/scan.l in Graphviz 2.34.0 allows remote attackers to have unspecified impact via vectors related to a "badly formed number" and a "long digit list."... Read more
Affected Products : graphviz- EPSS Score: %7.86
- Published: Jan. 10, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2014-0754
Directory traversal vulnerability in SchneiderWEB on Schneider Electric Modicon PLC Ethernet modules 140CPU65x Exec before 5.5, 140NOC78x Exec before 1.62, 140NOE77x Exec before 6.2, BMXNOC0401 before 2.05, BMXNOE0100 before 2.9, BMXNOE0110x Exec before 6... Read more
Affected Products : tsxety4103_firmware tsxety5103_firmware modicon_m340_bmxp342020_firmware modicon_m340_bmxp342030_firmware modicon_m340_bmxp342020h_firmware modicon_m340_bmxp3420302_firmware modicon_m340_bmxp3420302h_firmware modicon_m340_bmxp342030h_firmware modicon_m340_bmxnoe0100_firmware modicon_m340_bmxnoe0110_firmware +76 more products- EPSS Score: %2.25
- Published: Oct. 03, 2014
- Modified: Aug. 26, 2025
-
10.0
HIGHCVE-2014-0567
Heap-based buffer overflow in Adobe Reader and Acrobat 10.x before 10.1.12 and 11.x before 11.0.09 on Windows and OS X allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-0561.... Read more
- EPSS Score: %33.99
- Published: Sep. 17, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-0587
Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more
- EPSS Score: %10.80
- Published: Dec. 10, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2013-5486
Directory traversal vulnerability in processImageSave.jsp in DCNM-SAN Server in Cisco Prime Data Center Network Manager (DCNM) before 6.2(1) allows remote attackers to write arbitrary files via the chartid parameter, aka Bug IDs CSCue77035 and CSCue77036.... Read more
Affected Products : prime_data_center_network_manager- EPSS Score: %88.68
- Published: Sep. 23, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-5324
Adobe Flash Player before 11.7.700.242 and 11.8.x before 11.8.800.168 on Windows and Mac OS X, before 11.2.202.310 on Linux, before 11.1.111.73 on Android 2.x and 3.x, and before 11.1.115.81 on Android 4.x; Adobe AIR before 3.8.0.1430; and Adobe AIR SDK &... Read more
- EPSS Score: %11.53
- Published: Sep. 12, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4837
Unspecified vulnerability in Virtual User Generator in HP LoadRunner before 11.52 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1832.... Read more
Affected Products : loadrunner- EPSS Score: %75.60
- Published: Nov. 04, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-4977
Buffer overflow in the RTSP Packet Handler in Hikvision DS-2CD7153-E IP camera with firmware 4.1.0 b130111 (Jan 2013), and possibly other devices, allows remote attackers to cause a denial of service (device crash and reboot) and possibly execute arbitrar... Read more
- EPSS Score: %46.40
- Published: Mar. 03, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2013-4316
Apache Struts 2.0.0 through 2.3.15.1 enables Dynamic Method Invocation by default, which has unknown impact and attack vectors.... Read more
- EPSS Score: %7.07
- Published: Sep. 30, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-3268
Novell iManager 2.7 before SP6 Patch 1 does not refresh a token after a logout action, which has unspecified impact and remote attack vectors.... Read more
Affected Products : imanager- EPSS Score: %0.19
- Published: Apr. 24, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2736
Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-2718, CVE-20... Read more
- EPSS Score: %18.88
- Published: May. 16, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2733
Buffer overflow in Adobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2013-2730.... Read more
- EPSS Score: %2.74
- Published: May. 16, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2383
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier, 6 Update 43 and earlier, and 5.0 Update 41 and earlier; and OpenJDK 6 and 7; allows remote attackers to affect confidentiality, integrity,... Read more
- EPSS Score: %7.36
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2333
Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1680.... Read more
Affected Products : storage_data_protector- EPSS Score: %81.83
- Published: Jun. 06, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-1385
Adobe Shockwave Player before 12.0.2.122 does not prevent access to address information, which makes it easier for attackers to bypass the ASLR protection mechanism via unspecified vectors.... Read more
Affected Products : shockwave_player- EPSS Score: %1.83
- Published: Apr. 10, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-0689
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitra... Read more
Affected Products : ose roc_800l_remote_terminal_unit roc_800_remote_terminal_unit dl_8000_remote_terminal_unit- EPSS Score: %3.26
- Published: Oct. 03, 2013
- Modified: Apr. 11, 2025