Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2016-3607

    Unspecified vulnerability in the Oracle GlassFish Server component in Oracle Fusion Middleware 3.0.1 and 3.1.2 allows remote attackers to affect confidentiality, integrity, and availability via vectors related to Web Container.... Read more

    Affected Products : glassfish_server
    • Published: Jul. 21, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-3266

    The kernel-mode drivers in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 allow local users to gain privileges via a crafted... Read more

    • Published: Oct. 14, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2018-20334

    An issue was discovered in ASUSWRT 3.0.0.4.384.20308. When processing the /start_apply.htm POST data, there is a command injection issue via shell metacharacters in the fb_email parameter. By using this issue, an attacker can control the router and get sh... Read more

    • Published: Mar. 20, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-20218

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform comman... Read more

    • Published: Mar. 21, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-2385

    Heap-based buffer overflow in the encode_msg function in encode_msg.c in the SEAS module in Kamailio (formerly OpenSER and SER) before 4.3.5 allows remote attackers to cause a denial of service (memory corruption and process crash) or possibly execute arb... Read more

    Affected Products : debian_linux kamailio
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2006

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3353.... Read more

    Affected Products : data_protector
    • Published: Apr. 21, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2005

    HPE Data Protector before 7.03_108, 8.x before 8.15, and 9.x before 9.06 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-3352.... Read more

    Affected Products : data_protector
    • Published: Apr. 21, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2003-0432

    Ethereal 0.9.12 and earlier does not handle certain strings properly, with unknown consequences, in the (1) BGP, (2) WTP, (3) DNS, (4) 802.11, (5) ISAKMP, (6) WSP, (7) CLNP, (8) ISIS, and (9) RMI dissectors.... Read more

    Affected Products : linux ethereal
    • Published: Jul. 24, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-20114

    On D-Link DIR-818LW Rev.A 2.05.B03 and DIR-860L Rev.B 2.03.B03 devices, unauthenticated remote OS command execution can occur in the soap.cgi service of the cgibin binary via an "&&" substring in the service parameter. NOTE: this issue exists because of ... Read more

    • Published: Jan. 02, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-20122

    The web interface on FASTGate Fastweb devices with firmware through 0.00.47_FW_200_Askey 2017-05-17 (software through 1.0.1b) exposed a CGI binary that is vulnerable to a command injection vulnerability that can be exploited to achieve remote code executi... Read more

    Affected Products : fastgate_firmware fastgate
    • Published: Feb. 21, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-1741

    The NVIDIA driver in the Graphics Drivers subsystem in Apple OS X before 10.11.4 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more

    Affected Products : mac_os_x mac_os_x
    • Published: Mar. 24, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1580

    The setup_snappy_os_mounts function in the ubuntu-core-launcher package before 1.0.27.1 improperly determines the mount point of bind mounts when using snaps, which might allow remote attackers to obtain sensitive information or gain privileges via a snap... Read more

    Affected Products : ubuntu_linux ubuntu-core-launcher
    • Published: May. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2003-0426

    The installation of Apple QuickTime / Darwin Streaming Server before 4.1.3f starts the administration server with a "Setup Assistant" page that allows remote attackers to set the administrator password and gain privileges before the real administrator.... Read more

    Affected Products : darwin_streaming_server
    • Published: Aug. 27, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2016-0954

    Adobe Digital Editions before 4.5.1 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : digital_editions
    • Published: Mar. 09, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2003-0421

    Apple QuickTime / Darwin Streaming Server before 4.1.3f allows remote attackers to cause a denial of service (crash) via an MS-DOS device name (e.g. AUX) in a request to HTTP port 1220, a different vulnerability than CVE-2003-0502.... Read more

    Affected Products : darwin_streaming_server
    • Published: Aug. 27, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-1469

    IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.... Read more

    Affected Products : api_connect
    • Published: Apr. 04, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2003-0407

    Buffer overflow in gbnserver for Gnome Batalla Naval 1.0.4 allows remote attackers to execute arbitrary code via a long connection string.... Read more

    Affected Products : batalla_naval
    • Published: Jun. 30, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    CRITICAL
    CVE-2015-8396

    Integer overflow in the ImageRegionReader::ReadIntoBuffer function in MediaStorageAndFileFormat/gdcmImageRegionReader.cxx in Grassroots DICOM (aka GDCM) before 2.6.2 allows attackers to execute arbitrary code via crafted header dimensions in a DICOM image... Read more

    Affected Products : grassroots_dicom grassroots_dicom
    • Published: Jan. 12, 2016
    • Modified: Aug. 21, 2025
  • 10.0

    HIGH
    CVE-2015-8277

    Multiple buffer overflows in (1) lmgrd and (2) Vendor Daemon in Flexera FlexNet Publisher before 11.13.1.2 Security Update 1 allow remote attackers to execute arbitrary code via a crafted packet with opcode (a) 0x107 or (b) 0x10a.... Read more

    Affected Products : flexnet_publisher
    • Published: Feb. 24, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-8051

    The Adobe Premiere Clip app before 1.2.1 for iOS mishandles unspecified input, which has unknown impact and attack vectors.... Read more

    Affected Products : premiere_clip
    • Published: Nov. 18, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 293186 Results