Latest CVE Feed
-
10.0
HIGHCVE-2014-2866
PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspecified operations by modifying this code.... Read more
Affected Products : commonspot_content_server- EPSS Score: %1.06
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-2864
Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequences.... Read more
Affected Products : commonspot_content_server- EPSS Score: %0.65
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-2863
Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.... Read more
Affected Products : commonspot_content_server- EPSS Score: %0.90
- Published: Apr. 15, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-2648
Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.... Read more
- EPSS Score: %22.35
- Published: Oct. 10, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2014-1776
Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploit... Read more
Affected Products : windows_7 windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 internet_explorer windows_server_2003 windows_vista windows_xp windows_8 +1 more products- Actively Exploited
- EPSS Score: %78.23
- Published: Apr. 27, 2014
- Modified: May. 29, 2025
-
10.0
HIGHCVE-2014-1379
Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a 32-bit executable file for a crafted application.... Read more
- EPSS Score: %0.50
- Published: Jul. 01, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2018-18068
The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging. With a debug host proces... Read more
- EPSS Score: %1.92
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-17916
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, a... Read more
- EPSS Score: %9.84
- Published: Nov. 02, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-17930
A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution.... Read more
Affected Products : sherlock- EPSS Score: %13.21
- Published: Nov. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-17932
JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, which could allow attackers to replay commands, control the device, view commands, or cause the device to stop running.... Read more
- EPSS Score: %0.24
- Published: Nov. 02, 2020
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2014-0513
Stack-based buffer overflow in Adobe Illustrator CS6 before 16.0.5 and 16.2.x before 16.2.2 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more
Affected Products : illustrator- EPSS Score: %17.08
- Published: May. 14, 2014
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2018-17914
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the Indu... Read more
- EPSS Score: %3.90
- Published: Nov. 02, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2003-0196
Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.... Read more
- EPSS Score: %6.78
- Published: May. 05, 2003
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-17565
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.... Read more
Affected Products : gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware gxp1610 gxp1615 gxp1620 gxp1625 +2 more products- EPSS Score: %0.52
- Published: Apr. 01, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-17532
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute a... Read more
- EPSS Score: %53.77
- Published: Oct. 15, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2003-0170
Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.... Read more
Affected Products : aix- EPSS Score: %1.18
- Published: Mar. 29, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2013-5558
The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238... Read more
Affected Products : telepresence_vx_clinical_assistant- EPSS Score: %1.14
- Published: Nov. 08, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-5327
MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more
Affected Products : robohelp- EPSS Score: %10.80
- Published: Oct. 09, 2013
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-5033
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE-2013-5034.... Read more
Affected Products : atmail- EPSS Score: %0.38
- Published: Jan. 12, 2014
- Modified: Apr. 11, 2025
-
10.0
HIGHCVE-2013-5032
Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE-2013-5034.... Read more
Affected Products : atmail- EPSS Score: %0.38
- Published: Jan. 12, 2014
- Modified: Apr. 11, 2025