Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2012-1288

    The UTC Fire & Security GE-MC100-NTP/GPS-ZB Master Clock device uses hardcoded credentials for an administrative account, which makes it easier for remote attackers to obtain access via an HTTP session.... Read more

    • Published: Feb. 23, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-1381

    Unspecified vulnerability in the NetEase CloudAlbum (com.netease.cloudalbum) application 2.0.0 and 2.2.0 for Android has unknown impact and attack vectors.... Read more

    Affected Products : android netease_cloudalbum
    • Published: Mar. 07, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-1250

    Logitec LAN-W300N/R routers with firmware before 2.27 do not properly restrict login access, which allows remote attackers to obtain administrative privileges and modify settings via vectors related to PPPoE authentication.... Read more

    • Published: Jun. 04, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2007-2122

    Unspecified vulnerability in the Wireless component in Oracle Application Server 9.0.4.3 has unknown impact and attack vectors, aka AS03.... Read more

    Affected Products : application_server
    • Published: Apr. 18, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-3999

    Stack-based buffer overflow in goform/formExportDataLogs in HP Power Manager before 4.2.10 allows remote attackers to execute arbitrary code via a long fileName parameter.... Read more

    Affected Products : power_manager
    • Published: Jan. 20, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2009-4009

    Buffer overflow in PowerDNS Recursor before 3.1.7.2 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted packets.... Read more

    Affected Products : recursor
    • Published: Jan. 08, 2010
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2024-52046

    The ObjectSerializationDecoder in Apache MINA uses Java’s native deserialization protocol to process incoming serialized data but lacks the necessary security checks and defenses. This vulnerability allows attackers to exploit the deserialization process ... Read more

    Affected Products : mina
    • Published: Dec. 25, 2024
    • Modified: Feb. 12, 2025
  • 10.0

    HIGH
    CVE-2012-1002

    SQL injection vulnerability in author/edit.php in OpenConf 4.x before 4.12 allows remote attackers to execute arbitrary SQL commands via the pid parameter.... Read more

    Affected Products : openconf
    • Published: Feb. 08, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    CRITICAL
    CVE-2012-10026

    The WordPress plugin Asset-Manager version 2.0 and below contains an unauthenticated arbitrary file upload vulnerability in upload.php. The endpoint fails to properly validate and restrict uploaded file types, allowing remote attackers to upload malicious... Read more

    Affected Products :
    • Published: Aug. 05, 2025
    • Modified: Aug. 07, 2025
    • Vuln Type: Authentication
  • 10.0

    HIGH
    CVE-2016-7004

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more

    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-7013

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more

    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2012-0838

    Apache Struts 2 before 2.2.3.1 evaluates a string as an OGNL expression during the handling of a conversion error, which allows remote attackers to modify run-time data values, and consequently execute arbitrary code, via invalid input to a field.... Read more

    Affected Products : struts
    • Published: Mar. 02, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0804

    Heap-based buffer overflow in the proxy_connect function in src/client.c in CVS 1.11 and 1.12 allows remote HTTP proxy servers to cause a denial of service (crash) and possibly execute arbitrary code via a crafted HTTP response.... Read more

    Affected Products : cvs
    • Published: May. 29, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0764

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, ... Read more

    Affected Products : shockwave_player
    • Published: Feb. 15, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0775

    The JavaScript implementation in Adobe Reader and Acrobat 9.x before 9.5.1 and 10.x before 10.1.3 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : acrobat acrobat_reader
    • Published: Apr. 10, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0758

    Heap-based buffer overflow in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : shockwave_player
    • Published: Feb. 15, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0759

    Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0771.... Read more

    Affected Products : shockwave_player
    • Published: Feb. 15, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0766

    The Shockwave 3D Asset component in Adobe Shockwave Player before 11.6.4.634 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-0757, CVE-2012-0760, ... Read more

    Affected Products : shockwave_player
    • Published: Feb. 15, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0695

    Multiple unspecified vulnerabilities in Google Chrome before 17.0.963.27 on the Acer AC700, Samsung Series 5, and Cr-48 Chromebook platforms have unknown impact and attack vectors.... Read more

    • Published: Jan. 12, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    CRITICAL
    CVE-2024-20419

    A vulnerability in the authentication system of Cisco Smart Software Manager On-Prem (SSM On-Prem) could allow an unauthenticated, remote attacker to change the password of any user, including administrative users. This vulnerability is due to improper... Read more

    Affected Products : smart_software_manager_on-prem
    • Published: Jul. 17, 2024
    • Modified: Jul. 31, 2025
Showing 20 of 293284 Results