Latest CVE Feed
-
10.0
HIGHCVE-2020-8000
Intellian Aptus Web 1.24 has a hardcoded password of 12345678 for the intellian account.... Read more
Affected Products : aptus_web- EPSS Score: %0.81
- Published: Jan. 27, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-8439
Adobe Flash Player before 13.0.0.258 and 14.x and 15.x before 15.0.0.239 on Windows and OS X and before 11.2.202.424 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to ... Read more
Affected Products : linux_kernel macos flash_player mac_os_x windows air air_sdk air_sdk_\&_compiler air_sdk_and_compiler- Actively Exploited
- EPSS Score: %31.48
- Published: Nov. 25, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2021-34235
Tokheim Profleet DiaLOG 11.005.02 is affected by SQL Injection. The component is the Field__UserLogin parameter on the logon page.... Read more
Affected Products : tokheim_profleet_dialog- EPSS Score: %0.32
- Published: Feb. 11, 2022
- Modified: Feb. 06, 2025
-
10.0
HIGHCVE-2016-10312
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arbitrary commands via shell metacharacters to certai... Read more
- EPSS Score: %5.58
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2018-1164
This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numero... Read more
- EPSS Score: %29.79
- Published: Feb. 21, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-2428
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ... Read more
- EPSS Score: %3.53
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2555
Integer overflow in Adobe Flash Player before 10.3.183.75 and 11.x before 11.7.700.169 on Windows and Mac OS X, before 10.3.183.75 and 11.x before 11.2.202.280 on Linux, before 11.1.111.50 on Android 2.x and 3.x, and before 11.1.115.54 on Android 4.x; Ado... Read more
Affected Products : android linux_kernel enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus macos enterprise_linux_eus flash_player opensuse +3 more products- EPSS Score: %5.98
- Published: Mar. 11, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2012-4176
Array index error in Adobe Shockwave Player before 11.6.8.638 allows attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : shockwave_player- EPSS Score: %5.08
- Published: Oct. 23, 2012
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2021-22941
Improper Access Control in Citrix ShareFile storage zones controller before 5.11.20 may allow an unauthenticated attacker to remotely compromise the storage zones controller.... Read more
Affected Products : sharefile_storagezones_controller- Actively Exploited
- EPSS Score: %88.62
- Published: Sep. 23, 2021
- Modified: Mar. 13, 2025
-
10.0
HIGHCVE-2011-3937
The H.263 codec (libavcodec/h263dec.c) in FFmpeg 0.7.x before 0.7.12, 0.8.x before 0.8.11, and unspecified versions before 0.10, and in Libav 0.5.x before 0.5.9, 0.6.x before 0.6.6, 0.7.x before 0.7.5, and 0.8.x before 0.8.1 has unspecified impact and att... Read more
- EPSS Score: %0.69
- Published: Jan. 05, 2013
- Modified: Apr. 11, 2025
-
10.0
CRITICALCVE-2018-14721
FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.... Read more
- EPSS Score: %9.90
- Published: Jan. 02, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2010-1121
Mozilla Firefox 3.6.x before 3.6.3 does not properly manage the scopes of DOM nodes that are moved from one document to another, which allows remote attackers to conduct use-after-free attacks and execute arbitrary code via unspecified vectors involving i... Read more
Affected Products : firefox- EPSS Score: %5.54
- Published: Mar. 25, 2010
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2015-5903
The kernel in Apple iOS before 9 allows local users to gain privileges or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-5868 and CVE-2015-5896.... Read more
- EPSS Score: %2.02
- Published: Sep. 18, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2010-4325
Buffer overflow in gwwww1.dll in GroupWise Internet Agent (GWIA) in Novell GroupWise before 8.02HP2 allows remote attackers to execute arbitrary code via a crafted TZID variable in a VCALENDAR message.... Read more
Affected Products : groupwise- EPSS Score: %19.92
- Published: Jan. 28, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2007-6532
Double free vulnerability in the Widget Library (libxfcegui4) in Xfce before 4.4.2 might allow remote attackers to execute arbitrary code via unknown vectors related to the "cliend id, program name and working directory in session management."... Read more
Affected Products : xfce- EPSS Score: %3.09
- Published: Jan. 09, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2014-3984
Multiple unspecified vulnerabilities in Libav before 0.8.12 allow remote attackers to have unknown impact and vectors.... Read more
Affected Products : libav- EPSS Score: %10.16
- Published: Jun. 06, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2015-6988
The kernel in Apple iOS before 9.1 and OS X before 10.11.1 does not initialize an unspecified data structure, which allows remote attackers to execute arbitrary code via vectors involving an unknown network-connectivity requirement.... Read more
- EPSS Score: %11.01
- Published: Oct. 23, 2015
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2020-12284
cbs_jpeg_split_fragment in libavcodec/cbs_jpeg.c in FFmpeg 4.1 and 4.2.2 has a heap-based buffer overflow during JPEG_MARKER_SOS handling because of a missing length check.... Read more
- EPSS Score: %5.13
- Published: Apr. 28, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2013-1719
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 24.0, Thunderbird before 24.0, and SeaMonkey before 2.21 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute... Read more
- EPSS Score: %2.38
- Published: Sep. 18, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-2427
Unspecified vulnerability in the Java Runtime Environment (JRE) component in Oracle Java SE 7 Update 17 and earlier and JavaFX 2.2.7 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors related to ... Read more
- EPSS Score: %1.26
- Published: Apr. 17, 2013
- Modified: Apr. 11, 2025