Latest CVE Feed
-
10.0
HIGHCVE-2020-9864
A logic issue was addressed with improved restrictions. This issue is fixed in macOS Catalina 10.15.6. An application may be able to execute arbitrary code with kernel privileges.... Read more
- EPSS Score: %1.14
- Published: Oct. 16, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2008-3159
Integer overflow in ds.dlm, as used by dhost.exe, in Novell eDirectory 8.7.3.10 before 8.7.3 SP10b and 8.8 before 8.8.2 ftf2 allows remote attackers to execute arbitrary code via unspecified vectors that trigger a stack-based buffer overflow, related to "... Read more
Affected Products : edirectory- EPSS Score: %15.11
- Published: Jul. 14, 2008
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2020-13839
An issue was discovered on LG mobile devices with Android OS 7.2, 8.0, 8.1, 9, and 10 (MTK chipsets). Code execution can occur via a custom AT command handler buffer overflow. The LG ID is LVE-SMP-200007 (June 2020).... Read more
- EPSS Score: %0.23
- Published: Jun. 05, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8599
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit t... Read more
- Actively Exploited
- EPSS Score: %58.42
- Published: Mar. 18, 2020
- Modified: Feb. 12, 2025
-
10.0
HIGHCVE-2020-8598
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges.... Read more
- EPSS Score: %8.46
- Published: Mar. 18, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-8515
DrayTek Vigor2960 1.3.1_Beta, Vigor3900 1.4.4_Beta, and Vigor300B 1.3.3_Beta, 1.4.2.1_Beta, and 1.4.4_Beta devices allow remote code execution as root (without authentication) via shell metacharacters to the cgi-bin/mainfunction.cgi URI. This issue has be... Read more
Affected Products : vigor2960_firmware vigor300b_firmware vigor3900_firmware vigor2960 vigor300b vigor3900- Actively Exploited
- EPSS Score: %94.36
- Published: Feb. 01, 2020
- Modified: Feb. 04, 2025
-
10.0
HIGHCVE-2020-8465
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to manipulate system updates using a combination of CSRF bypass (CVE-2020-8461) and authentication bypass (CVE-2020-8464) to execute code as user root.... Read more
Affected Products : interscan_web_security_virtual_appliance- EPSS Score: %0.18
- Published: Dec. 17, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-5391
A stack buffer overflow vulnerability was identified in HPE Intelligent Management Center (IMC) PLAT earlier than version 7.3 E0506P09.... Read more
Affected Products : intelligent_management_center- EPSS Score: %0.99
- Published: Jun. 05, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2019-9120
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attacker... Read more
- EPSS Score: %9.27
- Published: Mar. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-7199
A security vulnerability has been identified in the HPE Edgeline Infrastructure Manager, also known as HPE Edgeline Infrastructure Management Software. The vulnerability could be remotely exploited to bypass remote authentication leading to execution of a... Read more
Affected Products : edgeline_infrastructure_manager- EPSS Score: %8.34
- Published: Dec. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-7115
The ClearPass Policy Manager web interface is affected by a vulnerability that leads to authentication bypass. Upon successful bypass an attacker could then execute an exploit that would allow to remote command execution in the underlying operating system... Read more
Affected Products : clearpass_policy_manager- EPSS Score: %60.70
- Published: Jun. 03, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-4682
IBM MQ 7.5, 8.0, 9.0, 9.1, 9.2 LTS, and 9.2 CD could allow a remote attacker to execute arbitrary code on the system, caused by an unsafe deserialization of trusted data. An attacker could exploit this vulnerability to execute arbitrary code on the system... Read more
- EPSS Score: %2.99
- Published: Jan. 28, 2021
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-4589
IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to execute arbitrary code on the system with a specially-crafted sequence of serialized objects from untrusted sources. IBM X-Force ID: 184585.... Read more
Affected Products : websphere_application_server- EPSS Score: %6.77
- Published: Aug. 13, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3847
An out-of-bounds read was addressed with improved input validation. This issue is fixed in macOS Catalina 10.15.3. A remote attacker may be able to leak memory.... Read more
- EPSS Score: %1.34
- Published: Apr. 01, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2011-2092
Adobe LiveCycle Data Services 3.1 and earlier, LiveCycle 9.0.0.2 and earlier, and BlazeDS 4.0.1 and earlier do not properly restrict creation of classes during deserialization of (1) AMF and (2) AMFX data, which allows attackers to have an unspecified imp... Read more
- EPSS Score: %2.27
- Published: Jun. 16, 2011
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2020-3760
Adobe Digital Editions versions 4.5.10 and below have a command injection vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- EPSS Score: %14.83
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3740
Adobe Framemaker versions 2019.0.4 and below have a memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- EPSS Score: %8.03
- Published: Feb. 13, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3470
Multiple vulnerabilities in the API subsystem of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to execute arbitrary code with root privileges. The vulnerabilities are due to improper boundary checks for certa... Read more
- EPSS Score: %3.20
- Published: Nov. 18, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3375
A vulnerability in Cisco SD-WAN Solution Software could allow an unauthenticated, remote attacker to cause a buffer overflow on an affected device. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by ... Read more
- EPSS Score: %1.99
- Published: Jul. 31, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2020-3357
A vulnerability in the Secure Sockets Layer (SSL) VPN feature of Cisco Small Business RV340, RV340W, RV345, and RV345P Dual WAN Gigabit VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device or cause th... Read more
Affected Products : small_business_rv_series_router_firmware rv340_dual_wan_gigabit_vpn_router_firmware rv340w_dual_wan_gigabit_wireless-ac_vpn_router_firmware rv345_dual_wan_gigabit_vpn_router_firmware rv345p_dual_wan_gigabit_poe_vpn_router_firmware rv340_dual_wan_gigabit_vpn_router rv340w_dual_wan_gigabit_wireless-ac_vpn_router rv345_dual_wan_gigabit_vpn_router rv345p_dual_wan_gigabit_poe_vpn_router- EPSS Score: %4.12
- Published: Jul. 16, 2020
- Modified: Nov. 21, 2024