Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2015-0304

    Heap-based buffer overflow in Adobe Flash Player before 13.0.0.260 and 14.x through 16.x before 16.0.0.257 on Windows and OS X and before 11.2.202.429 on Linux, Adobe AIR before 16.0.0.245 on Windows and OS X and before 16.0.0.272 on Android, Adobe AIR SD... Read more

    • EPSS Score: %8.01
    • Published: Jan. 13, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2004-0989

    Multiple buffer overflows in libXML 2.6.12 and 2.6.13 (libxml2), and possibly other versions, may allow remote attackers to execute arbitrary code via (1) a long FTP URL that is not properly handled by the xmlNanoFTPScanURL function, (2) a long proxy URL ... Read more

    • EPSS Score: %28.23
    • Published: Mar. 01, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-1065

    Buffer overflow in the exif_read_data function in PHP before 4.3.10 and PHP 5.x up to 5.0.2 allows remote attackers to execute arbitrary code via a long section name in an image file.... Read more

    Affected Products : php ubuntu_linux secure_linux openpkg
    • EPSS Score: %6.90
    • Published: Jan. 10, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2012-1797

    IBM DB2 9.5 uses world-writable permissions for nodes.reg, which has unspecified impact and attack vectors.... Read more

    Affected Products : db2
    • EPSS Score: %0.44
    • Published: Mar. 20, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2015-8548

    Multiple unspecified vulnerabilities in Google V8 before 4.7.80.23, as used in Google Chrome before 47.0.2526.80, allow attackers to cause a denial of service or possibly have other impact via unknown vectors, a different issue than CVE-2015-8478.... Read more

    Affected Products : chrome v8
    • EPSS Score: %0.82
    • Published: Dec. 14, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-5578

    Adobe Flash Player before 18.0.0.241 and 19.x before 19.0.0.185 on Windows and OS X and before 11.2.202.521 on Linux, Adobe AIR before 19.0.0.190, Adobe AIR SDK before 19.0.0.190, and Adobe AIR SDK & Compiler before 19.0.0.190 allow attackers to execute a... Read more

    • EPSS Score: %4.30
    • Published: Sep. 22, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2004-1128

    Buffer overflow in CMailCOM.dll in CMailServer 5.2 allows remote attackers to execute arbitrary code via an attachment with a long filename.... Read more

    Affected Products : cmailserver
    • EPSS Score: %5.63
    • Published: Jan. 10, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2004-1152

    Buffer overflow in the mailListIsPdf function in Adobe Acrobat Reader 5.09 for Unix allows remote attackers to execute arbitrary code via an e-mail message with a crafted PDF attachment.... Read more

    Affected Products : acrobat_reader
    • EPSS Score: %16.62
    • Published: Jan. 10, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    CRITICAL
    CVE-2017-14462

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in... Read more

    • EPSS Score: %36.58
    • Published: Apr. 05, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2004-1287

    Buffer overflow in the error function in preproc.c for NASM 0.98.38 1.2 allows attackers to execute arbitrary code via a crafted asm file, a different vulnerability than CVE-2005-1194.... Read more

    Affected Products : netwide_assembler
    • EPSS Score: %16.45
    • Published: Jan. 10, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2016-1061

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more

    • EPSS Score: %10.86
    • Published: May. 11, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2011-0863

    Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 6 Update 25 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, and availability via u... Read more

    Affected Products : jre jdk
    • EPSS Score: %3.60
    • Published: Jun. 14, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2015-5133

    Buffer overflow in Adobe Flash Player before 18.0.0.232 on Windows and OS X and before 11.2.202.508 on Linux, Adobe AIR before 18.0.0.199, Adobe AIR SDK before 18.0.0.199, and Adobe AIR SDK & Compiler before 18.0.0.199 allows attackers to execute arbitrar... Read more

    • EPSS Score: %71.45
    • Published: Aug. 14, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1094

    Use-after-free vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows attackers to execute arbitrary ... Read more

    • EPSS Score: %10.41
    • Published: May. 11, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-4262

    The password-change feature in Cisco Unified MeetingPlace Web Conferencing before 8.5(5) MR3 and 8.6 before 8.6(2) does not check the session ID or require entry of the current password, which allows remote attackers to reset arbitrary passwords via a cra... Read more

    • EPSS Score: %0.37
    • Published: Jul. 24, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2009-2476

    The Java Management Extensions (JMX) implementation in Sun Java SE 6 before Update 15, and OpenJDK, does not properly enforce OpenType checks, which allows context-dependent attackers to bypass intended access restrictions by leveraging finalizer resurrec... Read more

    Affected Products : openjdk java_se
    • EPSS Score: %1.82
    • Published: Aug. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2015-3132

    Use-after-free vulnerability in Adobe Flash Player before 13.0.0.302 and 14.x through 18.x before 18.0.0.203 on Windows and OS X and before 11.2.202.481 on Linux, Adobe AIR before 18.0.0.180, Adobe AIR SDK before 18.0.0.180, and Adobe AIR SDK & Compiler b... Read more

    • EPSS Score: %13.60
    • Published: Jul. 09, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-4401

    ActionScript in Adobe Flash Player 9.0.124.0 and earlier does not require user interaction in conjunction with (1) the FileReference.browse operation in the FileReference upload API or (2) the FileReference.download operation in the FileReference download... Read more

    Affected Products : flash_player
    • EPSS Score: %4.52
    • Published: Oct. 17, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-2721

    Multiple unspecified vulnerabilities in the Provider class in Sun Java SE 5.0 before Update 20 have unknown impact and attack vectors, aka BugId 6406003.... Read more

    Affected Products : java_se
    • EPSS Score: %1.15
    • Published: Aug. 10, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4796

    The _httpsrequest function (Snoopy/Snoopy.class.php) in Snoopy 1.2.3 and earlier, as used in (1) ampache, (2) libphp-snoopy, (3) mahara, (4) mediamate, (5) opendb, (6) pixelpost, and possibly other products, allows remote attackers to execute arbitrary co... Read more

    Affected Products : debian_linux nagios wordpress snoopy
    • EPSS Score: %1.09
    • Published: Oct. 30, 2008
    • Modified: Apr. 09, 2025
Showing 20 of 291275 Results