Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2010-4581

    Unspecified vulnerability in Opera before 11.00 has unknown impact and attack vectors, related to "a high severity issue."... Read more

    Affected Products : opera_browser
    • Published: Dec. 22, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-4469

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more

    Affected Products : jre sdk jdk
    • Published: Feb. 17, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-4465

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 23 and earlier, 5.0 Update 27 and earlier, and 1.4.2_29 and earlier allows remote untrusted Java Web Start applications and untrusted Java app... Read more

    Affected Products : jre sdk jdk
    • Published: Feb. 17, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-4463

    Unspecified vulnerability in the Java Runtime Environment (JRE) in Oracle Java SE and Java for Business 6 Update 21 through 6 Update 23 allows remote untrusted Java Web Start applications and untrusted Java applets to affect confidentiality, integrity, an... Read more

    Affected Products : jre jdk
    • Published: Feb. 17, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-4233

    The Linux installation on the Camtron CMNC-200 Full HD IP Camera and TecVoz CMNC-200 Megapixel IP Camera with firmware 1.102A-008 has a default password of m for the root account, and a default password of merlin for the mg3500 account, which makes it eas... Read more

    • Published: Nov. 17, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2019-18189

    A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulne... Read more

    • Published: Oct. 28, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2010-3912

    The supportconfig script in supportutils in SUSE Linux Enterprise 11 SP1 and 10 SP3 does not "disguise passwords" in configuration files, which has unknown impact and attack vectors.... Read more

    Affected Products : suse_linux
    • Published: Jan. 13, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2019-18184

    Crestron DMC-STRO 1.0 devices allow remote command execution as root via shell metacharacters to the ping function.... Read more

    Affected Products : dmc-stro_firmware dmc-stro
    • Published: Nov. 27, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2010-3731

    Stack-based buffer overflow in the validateUser implementation in the com.ibm.db2.das.core.DasSysCmd function in db2dasrrm in the DB2 Administration Server (DAS) component in IBM DB2 9.1 before FP10, 9.5 before FP6a, and 9.7 before FP3 allows remote attac... Read more

    Affected Products : db2
    • Published: Oct. 05, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3572

    Unspecified vulnerability in the Sound component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : jre sdk jdk
    • Published: Oct. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3562

    Unspecified vulnerability in the 2D component in Oracle Java SE and Java for Business 6 Update 21, 5.0 Update 25, 1.4.2_27, and 1.3.1_28 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors. NOTE: the previou... Read more

    Affected Products : jre sdk jdk
    • Published: Oct. 19, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3193

    Unspecified vulnerability in the DB2STST program in IBM DB2 9.1 before FP9, 9.5 before FP6, and 9.7 before FP2 has unknown impact and attack vectors.... Read more

    Affected Products : db2
    • Published: Aug. 31, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-3114

    The text-editing implementation in Google Chrome before 5.0.375.127, and webkitgtk before 1.2.6, does not check a node type before performing a cast, which has unspecified impact and attack vectors related to (1) DeleteSelectionCommand.cpp, (2) InsertLine... Read more

    Affected Products : ubuntu_linux chrome webkitgtk
    • Published: Aug. 24, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2019-17621

    The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connect... Read more

    • Actively Exploited
    • Published: Dec. 30, 2019
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2014-2632

    Unspecified vulnerability in the WebTier component in HP Service Manager (SM) 7.21 and 9.x before 9.34 allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : service_manager
    • Published: Aug. 23, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2010-2523

    Multiple buffer overflows in ha.c in the mipv6 daemon in UMIP 0.4 allow remote attackers to have an unspecified impact via a crafted (1) ND_OPT_PREFIX_INFORMATION or (2) ND_OPT_HOME_AGENT_INFO packet.... Read more

    Affected Products : umip
    • Published: Jul. 13, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2019-17509

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetMasterWLanSettings with shell metacharacters to /squashfs-root/www/HNAP1/control/Se... Read more

    Affected Products : dir-846_firmware dir-846
    • Published: Oct. 11, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2019-17510

    D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary OS commands as root by leveraging admin access and sending a /HNAP1/ request for SetWizardConfig with shell metacharacters to /squashfs-root/www/HNAP1/control/SetWizar... Read more

    Affected Products : dir-846_firmware dir-846
    • Published: Oct. 11, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2010-1763

    Unspecified vulnerability in WebKit in Apple iTunes before 9.2 on Windows has unknown impact and attack vectors, a different vulnerability than CVE-2010-1387 and CVE-2010-1769.... Read more

    • Published: Jun. 18, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1676

    Heap-based buffer overflow in Tor before 0.2.1.28 and 0.2.2.x before 0.2.2.20-alpha allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors.... Read more

    Affected Products : tor tor
    • Published: Dec. 22, 2010
    • Modified: Apr. 11, 2025
Showing 20 of 292883 Results