Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2013-4437

    Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."... Read more

    Affected Products : salt
    • EPSS Score: %0.68
    • Published: Nov. 05, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4290

    Stack-based buffer overflow in OpenJPEG before 1.5.2 allows remote attackers to have unspecified impact via unknown vectors to (1) lib/openjp3d/opj_jp3d_compress.c, (2) bin/jp3d/convert.c, or (3) lib/openjp3d/event.c.... Read more

    Affected Products : openjpeg
    • EPSS Score: %1.71
    • Published: Apr. 18, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2013-4267

    Ajaxeplorer before 5.0.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) archive_name parameter to the Power FS module (plugins/action.powerfs/class.PowerFSController.php), a (2) file name to the getTrustSizeOnFil... Read more

    Affected Products : pydio
    • EPSS Score: %7.06
    • Published: Feb. 11, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-4265

    The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.40
    • Published: Nov. 23, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3359

    Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3360.... Read more

    Affected Products : shockwave_player
    • EPSS Score: %11.43
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3354

    Adobe Reader and Acrobat before 10.1.8 and 11.x before 11.0.04 on Windows and Mac OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3352 and CVE... Read more

    Affected Products : mac_os_x acrobat acrobat_reader windows
    • EPSS Score: %26.10
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3350

    Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.... Read more

    Affected Products : coldfusion
    • EPSS Score: %1.61
    • Published: Jul. 10, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3195

    The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT do... Read more

    • EPSS Score: %59.62
    • Published: Oct. 09, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2343

    Unspecified vulnerability on the HP LeftHand Virtual SAN Appliance hydra with software before 10.0 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1510.... Read more

    • EPSS Score: %75.60
    • Published: Jul. 02, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2340

    Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary cod... Read more

    • EPSS Score: %27.05
    • Published: Jul. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2335

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1733.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %53.18
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2330

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1638.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %53.18
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2328

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1636.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %53.18
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2324

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1629.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %64.73
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2278

    Unspecified vulnerability in War FTP Daemon (warftpd) 1.82, when running as a Windows service, allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via unknown vectors related to log messages and the "internal l... Read more

    Affected Products : warftpd
    • EPSS Score: %8.92
    • Published: Apr. 01, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2013-2250

    Apache Open For Business Project (aka OFBiz) 10.04.01 through 10.04.05, 11.04.01 through 11.04.02, and 12.04.01 allows remote attackers to execute arbitrary Unified Expression Language (UEL) functions via JUEL metacharacters in unspecified parameters, rel... Read more

    Affected Products : ofbiz open_for_business_project
    • EPSS Score: %12.63
    • Published: Aug. 15, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-1751

    TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.... Read more

    Affected Products : twiki
    • EPSS Score: %4.69
    • Published: Nov. 07, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-1534

    Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : database_server
    • EPSS Score: %2.47
    • Published: Apr. 17, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-1483

    Unspecified vulnerability in the JavaFX component in Oracle Java SE JavaFX 2.2.4 and earlier allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors, a different vulnerability than other CVEs listed in the Februa... Read more

    Affected Products : javafx
    • EPSS Score: %1.47
    • Published: Feb. 02, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-1322

    Microsoft Publisher 2003 SP3 does not properly check table range data, which allows remote attackers to execute arbitrary code via a crafted Publisher file, aka "Publisher Invalid Range Check Vulnerability."... Read more

    Affected Products : publisher
    • EPSS Score: %59.35
    • Published: May. 15, 2013
    • Modified: Apr. 11, 2025
Showing 20 of 291526 Results