Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2016-2554

    Stack-based buffer overflow in ext/phar/tar.c in PHP before 5.5.32, 5.6.x before 5.6.18, and 7.x before 7.0.3 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted TAR archive.... Read more

    Affected Products : php
    • EPSS Score: %16.57
    • Published: May. 16, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2804

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 46.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.... Read more

    Affected Products : firefox firefox_esr
    • EPSS Score: %1.20
    • Published: Apr. 30, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-0543

    Adobe Flash Player before 13.0.0.241 and 14.x before 14.0.0.176 on Windows and OS X and before 11.2.202.400 on Linux, Adobe AIR before 14.0.0.178 on Windows and OS X and before 14.0.0.179 on Android, Adobe AIR SDK before 14.0.0.178, and Adobe AIR SDK & Co... Read more

    • EPSS Score: %0.78
    • Published: Aug. 12, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-4350

    Multiple SQL injection vulnerabilities in the Web Services web server in SolarWinds Storage Resource Monitor (SRM) Profiler (formerly Storage Manager (STM)) before 6.2.3 allow remote attackers to execute arbitrary SQL commands via the (1) ScriptSchedule p... Read more

    Affected Products : storage_resource_monitor
    • EPSS Score: %47.63
    • Published: May. 09, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-0401

    Buffer overflow in the logging functionality of the HTTP server in IBM Tivoli Provisioning Manager for OS Deployment (TPMfOSD) before 5.1.0.3 Interim Fix 3 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary c... Read more

    • EPSS Score: %28.52
    • Published: Jan. 23, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2004-0386

    Buffer overflow in the HTTP parser for MPlayer 1.0pre3 and earlier, 0.90, and 0.91 allows remote attackers to execute arbitrary code via a long Location header.... Read more

    Affected Products : mplayer linux mandrake_linux
    • EPSS Score: %34.06
    • Published: May. 04, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2015-0301

    Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SDK before 16.0.0.272, and Adobe... Read more

    • EPSS Score: %7.40
    • Published: Jan. 13, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-6944

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more

    • EPSS Score: %1.97
    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-6998

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more

    • EPSS Score: %2.24
    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-7019

    Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more

    • EPSS Score: %5.86
    • Published: Oct. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-7406

    Format string vulnerability in Dropbear SSH before 2016.74 allows remote attackers to execute arbitrary code via format string specifiers in the (1) username or (2) host argument.... Read more

    Affected Products : dropbear_ssh
    • EPSS Score: %10.35
    • Published: Mar. 03, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2004-0623

    Format string vulnerability in misc.c in GNU GNATS 4.00 may allow remote attackers to execute arbitrary code via format string specifiers in a string that gets logged by syslog.... Read more

    Affected Products : gnats
    • EPSS Score: %3.45
    • Published: Dec. 06, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2008-3107

    Unspecified vulnerability in the Virtual Machine in Sun Java Runtime Environment (JRE) in JDK and JRE 6 before Update 7, JDK and JRE 5.0 before Update 16, and SDK and JRE 1.4.x before 1.4.2_18 allows context-dependent attackers to gain privileges via an u... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %14.53
    • Published: Jul. 09, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-3108

    Buffer overflow in Sun Java Runtime Environment (JRE) in JDK and JRE 5.0 before Update 10, SDK and JRE 1.4.x before 1.4.2_18, and SDK and JRE 1.3.x before 1.3.1_23 allows context-dependent attackers to gain privileges via unspecified vectors related to fo... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %10.64
    • Published: Jul. 09, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2015-3039

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.281 and 14.x through 17.x before 17.0.0.169 on Windows and OS X and before 11.2.202.457 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more

    • EPSS Score: %8.70
    • Published: Apr. 14, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-4477

    Use-after-free vulnerability in the MediaStream playback feature in Mozilla Firefox before 40.0 allows remote attackers to execute arbitrary code via unspecified use of the Web Audio API.... Read more

    Affected Products : firefox ubuntu_linux opensuse
    • EPSS Score: %4.96
    • Published: Aug. 16, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2017-0561

    A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due to the possibility of remote code execution in the conte... Read more

    Affected Products : android linux_kernel
    • EPSS Score: %44.37
    • Published: Apr. 07, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2015-5589

    The phar_convert_to_other function in ext/phar/phar_object.c in PHP before 5.4.43, 5.5.x before 5.5.27, and 5.6.x before 5.6.11 does not validate a file pointer before a close operation, which allows remote attackers to cause a denial of service (segmenta... Read more

    Affected Products : php
    • EPSS Score: %8.49
    • Published: May. 16, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2004-0897

    The Indexing Service for Microsoft Windows XP and Server 2003 does not properly validate the length of a message, which allows remote attackers to execute arbitrary code via a buffer overflow attack.... Read more

    Affected Products : windows_2003_server windows_xp
    • EPSS Score: %55.01
    • Published: Jan. 11, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2012-1695

    Unspecified vulnerability in the Oracle JRockit component in Oracle Fusion Middleware 28.2.2 and earlier, and JDK/JRE 5 and 6 27.7.1 and earlier, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : fusion_middleware jre jdk
    • EPSS Score: %1.44
    • Published: May. 03, 2012
    • Modified: Apr. 11, 2025
Showing 20 of 291305 Results