Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2014-2866

    PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 relies on client JavaScript code for access restrictions, which allows remote attackers to perform unspecified operations by modifying this code.... Read more

    Affected Products : commonspot_content_server
    • EPSS Score: %1.06
    • Published: Apr. 15, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-2864

    Multiple directory traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a filename parameter containing directory traversal sequences.... Read more

    Affected Products : commonspot_content_server
    • EPSS Score: %0.65
    • Published: Apr. 15, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-2863

    Multiple absolute path traversal vulnerabilities in PaperThin CommonSpot before 7.0.2 and 8.x before 8.0.3 allow remote attackers to have an unspecified impact via a full pathname in a parameter.... Read more

    Affected Products : commonspot_content_server
    • EPSS Score: %0.90
    • Published: Apr. 15, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-2648

    Unspecified vulnerability in HP Operations Manager 9.10 and 9.11 on UNIX allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : operations_manager unix
    • EPSS Score: %22.35
    • Published: Oct. 10, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-1776

    Use-after-free vulnerability in Microsoft Internet Explorer 6 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via vectors related to the CMarkup::IsConnectedToPrimaryMarkup function, as exploit... Read more

    • Actively Exploited
    • EPSS Score: %78.23
    • Published: Apr. 27, 2014
    • Modified: May. 29, 2025
  • 10.0

    HIGH
    CVE-2014-1379

    Graphics Drivers in Apple OS X before 10.9.4 allows attackers to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via a 32-bit executable file for a crafted application.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.50
    • Published: Jul. 01, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2018-18068

    The ARM-based hardware debugging feature on Raspberry Pi 3 module B+ and possibly other devices allows non-secure EL1 code to read/write any EL3 (the highest privilege level in ARMv8) memory/register via inter-processor debugging. With a debug host proces... Read more

    • EPSS Score: %1.92
    • Published: Apr. 04, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-17916

    InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, a... Read more

    • EPSS Score: %9.84
    • Published: Nov. 02, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-17930

    A stack-based buffer overflow vulnerability has been identified in Teledyne DALSA Sherlock Version 7.2.7.4 and prior, which may allow remote code execution.... Read more

    Affected Products : sherlock
    • EPSS Score: %13.21
    • Published: Nov. 28, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-17932

    JUUKO K-800 (Firmware versions prior to numbers ending ...9A, ...9B, ...9C, etc.) is vulnerable to a replay attack and command forgery, which could allow attackers to replay commands, control the device, view commands, or cause the device to stop running.... Read more

    Affected Products : k-800_firmware k-800
    • EPSS Score: %0.24
    • Published: Nov. 02, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2014-0513

    Stack-based buffer overflow in Adobe Illustrator CS6 before 16.0.5 and 16.2.x before 16.2.2 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : illustrator
    • EPSS Score: %17.08
    • Published: May. 14, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2018-17914

    InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the Indu... Read more

    • EPSS Score: %3.90
    • Published: Nov. 02, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2003-0196

    Multiple buffer overflows in Samba before 2.2.8a may allow remote attackers to execute arbitrary code or cause a denial of service, as discovered by the Samba team and a different vulnerability than CVE-2003-0201.... Read more

    • EPSS Score: %6.78
    • Published: May. 05, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-17565

    Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.... Read more

    • EPSS Score: %0.52
    • Published: Apr. 01, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-17532

    Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input sanitization. This allows remote attackers to execute a... Read more

    • EPSS Score: %53.77
    • Published: Oct. 15, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2003-0170

    Unknown vulnerability in ftpd in IBM AIX 5.2, when configured to use Kerberos 5 for authentication, allows remote attackers to gain privileges via unknown attack vectors.... Read more

    Affected Products : aix
    • EPSS Score: %1.18
    • Published: Mar. 29, 2004
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2013-5558

    The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238... Read more

    • EPSS Score: %1.14
    • Published: Nov. 08, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-5327

    MDBMS.dll in Adobe RoboHelp 10 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : robohelp
    • EPSS Score: %10.80
    • Published: Oct. 09, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-5033

    Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5032, and CVE-2013-5034.... Read more

    Affected Products : atmail
    • EPSS Score: %0.38
    • Published: Jan. 12, 2014
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-5032

    Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE-2013-5034.... Read more

    Affected Products : atmail
    • EPSS Score: %0.38
    • Published: Jan. 12, 2014
    • Modified: Apr. 11, 2025
Showing 20 of 292495 Results