Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2009-1172

    The JAX-RPC WS-Security runtime in the Web Services Security component in IBM WebSphere Application Server (WAS) 6.1 before 6.1.0.23 and 7.0 before 7.0.0.3, when APAR PK41002 is installed, does not properly validate UsernameToken objects, which has unknow... Read more

    Affected Products : websphere_application_server
    • Published: Mar. 31, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0916

    Unspecified vulnerability in Opera before 9.64 has unknown impact and attack vectors, related to a "moderately severe issue."... Read more

    Affected Products : opera_browser
    • Published: Mar. 16, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0771

    The layout engine in Mozilla Firefox before 3.0.7, Thunderbird before 2.0.0.21, and SeaMonkey 1.1.15 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via certain vectors that trigger memory corruption and as... Read more

    Affected Products : firefox thunderbird seamonkey
    • Published: Mar. 05, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0650

    Stack-based buffer overflow in the GetStatsFromLine function in TPTEST 3.1.7 and earlier, and possibly 5.02, allows remote attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a STATS line with a long pwd fiel... Read more

    Affected Products : tptest
    • Published: Feb. 20, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0544

    Buffer overflow in the PyCrypto ARC2 module 2.0.1 allows remote attackers to cause a denial of service and possibly execute arbitrary code via a large ARC2 key length.... Read more

    Affected Products : arc2
    • Published: Feb. 12, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0258

    The Indexed Search Engine (indexed_search) system extension in TYPO3 4.0.0 through 4.0.9, 4.1.0 through 4.1.7, and 4.2.0 through 4.2.3 allows remote attackers to execute arbitrary commands via a crafted filename containing shell metacharacters, which is n... Read more

    Affected Products : typo3
    • Published: Jan. 22, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2009-0208

    Unspecified vulnerability in HP Virtual Rooms Client before 7.0.1, when running on Windows, allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : virtual_rooms
    • Published: Feb. 26, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2019-16932

    A blind SSRF vulnerability exists in the Visualizer plugin before 3.3.1 for WordPress via wp-json/visualizer/v1/upload-data.... Read more

    Affected Products : visualizer
    • Published: Sep. 30, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2008-6821

    Buffer overflow in the DAS server in IBM DB2 8 before FP17, 9.1 before FP5, and 9.5 before FP2 might allow attackers to execute arbitrary code or cause a denial of service (application crash) via unspecified vectors, a different vulnerability than CVE-200... Read more

    Affected Products : db2
    • Published: Jun. 03, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-5557

    Heap-based buffer overflow in ext/mbstring/libmbfl/filters/mbfilter_htmlent.c in the mbstring extension in PHP 4.3.0 through 5.2.6 allows context-dependent attackers to execute arbitrary code via a crafted string containing an HTML entity, which is not pr... Read more

    Affected Products : php
    • Published: Dec. 23, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4869

    FFmpeg 0.4.9, as used by MPlayer, allows context-dependent attackers to cause a denial of service (memory consumption) via unknown vectors, aka a "Tcp/udp memory leak."... Read more

    Affected Products : mplayer ffmpeg
    • Published: Nov. 01, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2008-4835

    SMB in the Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, and Server 2008 allows remote attackers to execute arbitrary code via malformed values of unspecified "fields inside the SMB packets" in ... Read more

    • Published: Jan. 14, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2019-16737

    The processCommandSetMac() function of libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.... Read more

    • Published: Dec. 13, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2019-16733

    processCommandSetUid() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.... Read more

    • Published: Dec. 13, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2008-4062

    Multiple unspecified vulnerabilities in Mozilla Firefox before 2.0.0.17 and 3.x before 3.0.2, Thunderbird before 2.0.0.17, and SeaMonkey before 1.1.12 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibl... Read more

    • Published: Sep. 24, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2019-16730

    processCommandUpgrade() in libcommon.so in Petwant PF-103 firmware 4.22.2.42 and Petalk AI 3.2.2.30 allows remote attackers to execute arbitrary system commands as the root user.... Read more

    • Published: Dec. 13, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2019-16649

    On Supermicro H11, H12, M11, X9, X10, and X11 products, a combination of encryption and authentication problems in the virtual media service allows capture of BMC credentials and data transferred over virtual media devices. Attackers can use captured cred... Read more

    • Published: Sep. 21, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-2418

    media/libmedia/IOMX.cpp in mediaserver in Android 6.x before 2016-04-01 does not initialize certain metadata buffer pointers, which allows attackers to obtain sensitive information from process memory, and consequently bypass an unspecified protection mec... Read more

    Affected Products : android
    • Published: Apr. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2008-2438

    Integer overflow in ovalarmsrv.exe in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via a crafted command to TCP port 2954, which triggers a heap-based buffer overflow.... Read more

    Affected Products : openview_network_node_manager
    • Published: Apr. 28, 2009
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2019-16453

    Adobe Acrobat and Reader versions , 2019.021.20056 and earlier, 2017.011.30152 and earlier, 2017.011.30155 and earlier version, 2017.011.30152 and earlier, and 2015.006.30505 and earlier have a security bypass vulnerability. Successful exploitation could ... Read more

    • Published: Dec. 19, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 293509 Results