Latest CVE Feed
-
10.0
HIGHCVE-2007-5769
Double free vulnerability in the getreply function in ftp.c in netkit ftp (netkit-ftp) 0.17 20040614 and later allows remote FTP servers to cause a denial of service (application crash) and possibly have unspecified other impact via some types of FTP prot... Read more
Affected Products : netkit_ftp- Published: Dec. 06, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-5767
Heap-based buffer overflow in the Client Trust application (clntrust.exe) in Novell BorderManager 3.8 before Update 1.5 allows remote attackers to execute arbitrary code via a validation request in which the Novell tree name is not properly delimited with... Read more
Affected Products : bordermanager- Published: Nov. 02, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2024-3094
Malicious code was discovered in the upstream tarballs of xz, starting with version 5.6.0. Through a series of complex obfuscations, the liblzma build process extracts a prebuilt object file from a disguised test file existing in the source code, which ... Read more
Affected Products : xz- Published: Mar. 29, 2024
- Modified: Aug. 19, 2025
-
10.0
CRITICALCVE-2024-20253
A vulnerability in multiple Cisco Unified Communications and Contact Center Solutions products could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device. This vulnerability is due to the improper processing of user-pr... Read more
- Published: Jan. 26, 2024
- Modified: May. 29, 2025
-
10.0
HIGHCVE-2019-15958
A vulnerability in the REST API of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an unauthenticated remote attacker to execute arbitrary code with root privileges on the underlying operating system. The ... Read more
- Published: Nov. 26, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5689
The Java Virtual Machine (JVM) in Sun Java Runtime Environment (JRE) in SDK and JRE 1.3.x through 1.3.1_20 and 1.4.x through 1.4.2_15, and JDK and JRE 5.x through 5.0 Update 12 and 6.x through 6 Update 2, allows remote attackers to execute arbitrary progr... Read more
- Published: Oct. 29, 2007
- Modified: Apr. 09, 2025
-
10.0
CRITICALCVE-2023-43654
TorchServe is a tool for serving and scaling PyTorch models in production. TorchServe default configuration lacks proper input validation, enabling third parties to invoke remote HTTP download requests and write files to the disk. This issue could be take... Read more
Affected Products : torchserve- Published: Sep. 28, 2023
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5655
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to execute arbitrary code via crafted requests containing values that are used as pointers.... Read more
- Published: Jan. 16, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2007-5656
TIBCO SmartSockets RTserver 6.8.0 and earlier, RTworks before 4.0.4, and Enterprise Message Service (EMS) 4.0.0 through 4.4.1 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via crafted requests that contro... Read more
- Published: Jan. 16, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2016-10174
The NETGEAR WNR2000v5 router contains a buffer overflow in the hidden_lang_avi parameter when invoking the URL /apply.cgi?/lang_check.html. This buffer overflow can be exploited by an unauthenticated attacker to achieve remote code execution.... Read more
Affected Products : d7000_firmware r6220_firmware d7800_firmware r7500_firmware r7500v2_firmware wnr2000v5_firmware wnr2020_firmware d6100_firmware jnr1010v2_firmware jwnr2010v5_firmware +46 more products- Actively Exploited
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2023-35082
An authentication bypass vulnerability in Ivanti EPMM 11.10 and older, allows unauthorized users to access restricted functionality or resources of the application without proper authentication. This vulnerability is unique to CVE-2023-35078 announced ear... Read more
Affected Products : endpoint_manager_mobile- Actively Exploited
- Published: Aug. 15, 2023
- Modified: Dec. 26, 2024
-
10.0
HIGHCVE-2019-15310
An issue was discovered on various devices via the Linkplay firmware. There is WAN remote code execution without user interaction. An attacker could retrieve the AWS key from the firmware and obtain full control over Linkplay's AWS estate, including S3 bu... Read more
Affected Products : linkplay- Published: Jul. 01, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-10188
utility.c in telnetd in netkit telnet through 0.17 allows remote attackers to execute arbitrary code via short writes or urgent data, because of a buffer overflow involving the netclear and nextitem functions.... Read more
Affected Products : fedora debian_linux junos eos communications_performance_intelligence_center netkit_telnet- Published: Mar. 06, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-17006
In Network Security Services (NSS) before 3.46, several cryptographic primitives had missing length checks. In cases where the application calling the library did not perform a sanity check on the inputs it could result in a crash due to a buffer overflow... Read more
- Published: Oct. 22, 2020
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-52218
Deserialization of Untrusted Data vulnerability in Anton Bond Woocommerce Tranzila Payment Gateway.This issue affects Woocommerce Tranzila Payment Gateway: from n/a through 1.0.8. ... Read more
Affected Products : woocommerce_tranzila_payment_gateway- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-15260
A vulnerability in Cisco Aironet Access Points (APs) Software could allow an unauthenticated, remote attacker to gain unauthorized access to a targeted device with elevated privileges. The vulnerability is due to insufficient access control for certain UR... Read more
- Published: Oct. 16, 2019
- Modified: Nov. 21, 2024
-
10.0
CRITICALCVE-2023-52225
Deserialization of Untrusted Data vulnerability in Tagbox Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics.This issue affects Tagbox – UGC Galleries, Social Media Widgets, User Reviews & Analytics: from n/a through 3.1. ... Read more
Affected Products : taggbox- Published: Jan. 08, 2024
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5635
Multiple unspecified vulnerabilities in Salford Software Support Incident Tracker (SiT!) before 3.30 have unknown impact and attack vectors.... Read more
Affected Products : support_incident_tracker- Published: Oct. 23, 2007
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-5151
Memory safety bugs were reported in Firefox 59. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 60.... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2007-5617
Unspecified vulnerability in VMware Player 1.0.x before 1.0.5 and 2.0 before 2.0.1, and Workstation 5.x before 5.5.5 and 6.x before 6.0.1, prevents it from launching, which has unspecified impact, related to untrusted virtual machine images.... Read more
- Published: Oct. 21, 2007
- Modified: Apr. 09, 2025