Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2009-2471

    The setTimeout function in Mozilla Firefox before 3.0.12 does not properly preserve object wrapping, which allows remote attackers to execute arbitrary JavaScript with chrome privileges via a crafted call, related to XPCNativeWrapper.... Read more

    Affected Products : firefox
    • EPSS Score: %2.24
    • Published: Jul. 22, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2011-0464

    Unspecified vulnerability in Novell Vibe OnPrem 3.0 before Hot Patch 1 allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : vibe_onprem
    • EPSS Score: %10.28
    • Published: Mar. 09, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2020-15490

    An issue was discovered on Wavlink WL-WN530HG4 M30HG4.V5030.191116 devices. Multiple buffer overflow vulnerabilities exist in CGI scripts, leading to remote code execution with root privileges. (The set of affected scripts is similar to CVE-2020-12266.)... Read more

    Affected Products : wl-wn530hg4_firmware wl-wn530hg4
    • EPSS Score: %3.84
    • Published: Jul. 01, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2011-0385

    The administrative web interface on Cisco TelePresence Recording Server devices with software 1.6.x and Cisco TelePresence Multipoint Switch (CTMS) devices with software 1.0.x, 1.1.x, 1.5.x, and 1.6.x allows remote attackers to create or overwrite arbitra... Read more

    • EPSS Score: %5.03
    • Published: Feb. 25, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3568

    Unspecified vulnerability in the Java Runtime Environment component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, and 1.4.2_27 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE:... Read more

    Affected Products : jre sdk jdk
    • EPSS Score: %9.13
    • Published: Oct. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-0382

    The CGI subsystem on Cisco TelePresence Recording Server devices with software 1.6.x before 1.6.2 allows remote attackers to execute arbitrary commands via a request to TCP port 443, related to a "command injection vulnerability," aka Bug ID CSCtf97221.... Read more

    • EPSS Score: %5.30
    • Published: Feb. 25, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-0381

    Cisco TelePresence Manager 1.2.x through 1.6.x allows remote attackers to perform unspecified actions and consequently execute arbitrary code via a crafted request to the Java RMI interface, related to a "command injection vulnerability," aka Bug ID CSCtf... Read more

    Affected Products : telepresence_manager
    • EPSS Score: %2.49
    • Published: Feb. 25, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-0354

    The default configuration of Cisco Tandberg C Series Endpoints, and Tandberg E and EX Personal Video units, with software before TC4.0.0 has a blank password for the root account, which makes it easier for remote attackers to obtain access via an unspecif... Read more

    • EPSS Score: %11.75
    • Published: Feb. 03, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2020-15613

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_admin_apis.php. When p... Read more

    Affected Products : webpanel
    • EPSS Score: %2.07
    • Published: Jul. 28, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2009-3380

    Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via u... Read more

    Affected Products : firefox
    • EPSS Score: %3.35
    • Published: Oct. 29, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2011-0334

    Stack-based buffer overflow in gwia.exe in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a long HTTP request for a .css file.... Read more

    Affected Products : groupwise
    • EPSS Score: %22.25
    • Published: Oct. 08, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2020-15426

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_migration_cpanel.php. ... Read more

    Affected Products : webpanel
    • EPSS Score: %2.07
    • Published: Jul. 28, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2011-0342

    Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute arbitrary code via a long parameter to the (1) Open, (2) Close, or (3) SetCur... Read more

    Affected Products : web_studio indusoft_web_studio
    • EPSS Score: %9.34
    • Published: Sep. 02, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    CRITICAL
    CVE-2019-18253

    An attacker could use specially crafted paths in a specific request to read or delete files from Relion 670 Series (versions 1p1r26, 1.2.3.17, 2.0.0.10, RES670 2.0.0.4, 2.1.0.1, and prior) outside the intended directory.... Read more

    Affected Products : relion_670_firmware relion_670
    • EPSS Score: %0.39
    • Published: Nov. 27, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2011-0333

    Heap-based buffer overflow in the NgwiCalVTimeZoneBody::ParseSelf function in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise 8.0 before HP3 allows remote attackers to execute arbitrary code via a crafted TZNAME variable in a VCALENDAR a... Read more

    Affected Products : groupwise
    • EPSS Score: %7.29
    • Published: Oct. 08, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2009-3739

    Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controllers allow remote attackers to obtain privileged access or cause a denial of service (halt) via unknown vectors.... Read more

    • EPSS Score: %0.06
    • Published: Jan. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2020-15424

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. When... Read more

    Affected Products : webpanel
    • EPSS Score: %2.07
    • Published: Jul. 28, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-15428

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_crons.php. When parsin... Read more

    Affected Products : webpanel
    • EPSS Score: %2.07
    • Published: Jul. 28, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-15425

    This vulnerability allows remote attackers to execute arbitrary code on affected installations of CentOS Web Panel cwp-e17.0.9.8.923. Authentication is not required to exploit this vulnerability. The specific flaw exists within ajax_mod_security.php. The ... Read more

    Affected Products : webpanel
    • EPSS Score: %1.98
    • Published: Jul. 28, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2011-0276

    HP OpenView Performance Insight Server 5.2, 5.3, 5.31, 5.4, and 5.41 contains a "hidden account" in the com.trinagy.security.XMLUserManager Java class, which allows remote attackers to execute arbitrary code via the doPost method in the com.trinagy.servle... Read more

    Affected Products : openview_performance_insight
    • EPSS Score: %85.73
    • Published: Feb. 02, 2011
    • Modified: Apr. 11, 2025
Showing 20 of 292485 Results