Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2014-2955

    Raritan PX before 1.5.11 on DPXR20A-16 devices allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.... Read more

    Affected Products : px dpxr20a-16
    • EPSS Score: %1.26
    • Published: Jul. 14, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-2623

    Unspecified vulnerability in HP Storage Data Protector 8.x allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %89.84
    • Published: Jul. 18, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2013-4784

    The HP Integrated Lights-Out (iLO) BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.... Read more

    Affected Products : integrated_lights-out_bmc
    • EPSS Score: %58.33
    • Published: Jul. 08, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-4161

    The default configuration of the HP CM8060 Color MFP with Edgeline; Color LaserJet 3xxx, 4xxx, 5550, 9500, CMxxxx, CPxxxx, and Enterprise CPxxxx; Digital Sender 9200c and 9250c; LaserJet 4xxx, 5200, 90xx, Mxxxx, and Pxxxx; and LaserJet Enterprise 500 colo... Read more

    • EPSS Score: %9.57
    • Published: Dec. 01, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-0923

    The client in HP Data Protector does not properly validate EXEC_CMD arguments, which allows remote attackers to execute arbitrary Perl code via a crafted command, related to the "local bin directory."... Read more

    Affected Products : data_protector
    • EPSS Score: %89.89
    • Published: Feb. 09, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0888

    Unspecified vulnerability in the Sun Ray Server Software component in Oracle Sun Product Suite 4.0, 4.1, and 4.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to Device Services.... Read more

    Affected Products : sun_products_suite
    • EPSS Score: %3.08
    • Published: Apr. 13, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2009-4462

    Stack-based buffer overflow in the NetBiterConfig utility (NetBiterConfig.exe) 1.3.0 for Intellicom NetBiter WebSCADA allows remote attackers to execute arbitrary code via a long hn (hostname) parameter in a crafted HICP-protocol UDP packet.... Read more

    • EPSS Score: %50.67
    • Published: Dec. 30, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-4294

    Unspecified vulnerability in the Authentication Manager (aka utauthd) in Sun Ray Server Software 4.0 and 4.1 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors.... Read more

    Affected Products : ray_server_software
    • EPSS Score: %3.90
    • Published: Dec. 11, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2007-6507

    SpntSvc.exe daemon in Trend Micro ServerProtect 5.58 for Windows, before Security Patch 4, exposes unspecified dangerous sub-functions from StRpcSrv.dll in the DCE/RPC interface, which allows remote attackers to obtain "full file system access" and execut... Read more

    Affected Products : serverprotect serverprotect
    • EPSS Score: %71.36
    • Published: Dec. 20, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2004-0348

    SQL injection vulnerability in viewCart.asp in SpiderSales shopping cart software allows remote attackers to execute arbitrary SQL via the userId parameter.... Read more

    Affected Products : spidersales
    • EPSS Score: %0.56
    • Published: Nov. 23, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2003-1121

    Services in ScriptLogic 4.01, and possibly other versions before 4.14, process client requests at raised privileges, which allows remote attackers to (1) modify arbitrary registry entries via the ScriptLogic RPC service (SLRPC) or (2) modify arbitrary con... Read more

    Affected Products : scriptlogic
    • EPSS Score: %4.96
    • Published: Dec. 31, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0436

    sscd_suncourier.pl CGI script in the Sun Sunsolve CD pack allows remote attackers to execute arbitrary commands via shell metacharacters in the email address parameter.... Read more

    Affected Products : solaris sunos
    • EPSS Score: %3.93
    • Published: Jul. 26, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-0018

    In Microsoft Windows NT and Windows 2000, a trusting domain that receives authorization information from a trusted domain does not verify that the trusted domain is authoritative for all listed SIDs, which allows remote attackers to gain Domain Administra... Read more

    Affected Products : windows_2000 windows_nt
    • EPSS Score: %36.04
    • Published: Mar. 08, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-0800

    String parsing error in rpc.kstatd in the linuxnfs or knfsd packages in SuSE and possibly other Linux systems allows remote attackers to gain root privileges.... Read more

    Affected Products : suse_linux
    • EPSS Score: %2.88
    • Published: Oct. 20, 2000
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2000-0012

    Buffer overflow in w3-msql CGI program in miniSQL package allows remote attackers to execute commands.... Read more

    Affected Products : msql
    • EPSS Score: %4.58
    • Published: Dec. 27, 1999
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-0042

    Buffer overflow in University of Washington's implementation of IMAP and POP servers.... Read more

    Affected Products : aix imap linux bsd_os openlinux pop
    • EPSS Score: %5.49
    • Published: Apr. 07, 1997
    • Modified: Apr. 03, 2025
  • 10.0

    CRITICAL
    CVE-2024-42472

    Flatpak is a Linux application sandboxing and distribution framework. Prior to versions 1.14.0 and 1.15.10, a malicious or compromised Flatpak app using persistent directories could access and write files outside of what it would otherwise have access to,... Read more

    Affected Products : debian_linux flatpak
    • Published: Aug. 15, 2024
    • Modified: Aug. 19, 2025
  • 10.0

    HIGH
    CVE-2011-3548

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier, and 1.4.2_33 and earlier allows remote untrusted Java Web Start applications and untrusted Java applet... Read more

    Affected Products : jre jdk
    • EPSS Score: %2.42
    • Published: Oct. 19, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-3554

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE JDK and JRE 7, 6 Update 27 and earlier, 5.0 Update 31 and earlier allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentialit... Read more

    Affected Products : jre jdk
    • EPSS Score: %2.86
    • Published: Oct. 19, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2007-0063

    Integer underflow in the DHCP server in EMC VMware Workstation before 5.5.5 Build 56455 and 6.x before 6.0.1 Build 55017, Player before 1.0.5 Build 56455 and Player 2 before 2.0.1 Build 55017, ACE before 1.0.3 Build 54075 and ACE 2 before 2.0.1 Build 5501... Read more

    • EPSS Score: %7.59
    • Published: Sep. 21, 2007
    • Modified: Apr. 09, 2025
Showing 20 of 292099 Results