Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2013-5032

    Unspecified vulnerability in Atmail before 6.6.4, and 7.x before 7.1.2, has unknown impact and attack vectors, a different vulnerability than CVE-2013-5031, CVE-2013-5033, and CVE-2013-5034.... Read more

    Affected Products : atmail
    • EPSS Score: %0.38
    • Published: Jan. 12, 2014
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4841

    Unspecified vulnerability in dbd_manager in LeftHand OS before 11.0 in HP StoreVirtual 4000 and StoreVirtual VSA Software (formerly LeftHand Virtual SAN Appliance) allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1509.... Read more

    • EPSS Score: %28.40
    • Published: Feb. 26, 2014
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4810

    HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMXInvokerServlet, ... Read more

    • Actively Exploited
    • EPSS Score: %85.88
    • Published: Sep. 16, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4785

    The web interface on the Dell iDRAC6 with firmware before 1.95 allows remote attackers to modify the CLP interface for arbitrary users and possibly have other impact via a request to an unspecified form that is accessible from testurls.html. NOTE: the ve... Read more

    Affected Products : idrac6_firmware idrac6_firmware
    • EPSS Score: %2.01
    • Published: Jul. 08, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4782

    The Supermicro BMC implementation allows remote attackers to bypass authentication and execute arbitrary IPMI commands by using cipher suite 0 (aka cipher zero) and an arbitrary password.... Read more

    Affected Products : bmc
    • EPSS Score: %58.32
    • Published: Jul. 08, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4735

    The Digital Alert Systems DASDEC EAS device before 2.0-2 and the Monroe Electronics R189 One-Net EAS device before 2.0-2 have a default password for an administrative account, which makes it easier for remote attackers to obtain access via an IP network.... Read more

    Affected Products : dasdec_eas r189_one-net_eas
    • EPSS Score: %1.35
    • Published: Jun. 30, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-17157

    In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remote users with access to the NFS server may be able to ex... Read more

    Affected Products : freebsd
    • EPSS Score: %12.73
    • Published: Dec. 04, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-4437

    Unspecified vulnerability in salt-ssh in Salt (aka SaltStack) 0.17.0 has unspecified impact and vectors related to "insecure Usage of /tmp."... Read more

    Affected Products : salt
    • EPSS Score: %0.68
    • Published: Nov. 05, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-4265

    The av_reallocp_array function in libavutil/mem.c in FFmpeg before 2.0.1 has an unspecified impact and remote vectors related to a "wrong return code" and a resultant NULL pointer dereference.... Read more

    Affected Products : ffmpeg
    • EPSS Score: %0.40
    • Published: Nov. 23, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-17063

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters... Read more

    Affected Products : dir-816_a2_firmware dir-816_a2
    • EPSS Score: %14.54
    • Published: Sep. 15, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-17065

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address.... Read more

    Affected Products : dir-816_a2_firmware dir-816_a2
    • EPSS Score: %0.70
    • Published: Sep. 15, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-3359

    Adobe Shockwave Player before 12.0.4.144 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2013-3360.... Read more

    Affected Products : shockwave_player
    • EPSS Score: %11.43
    • Published: Sep. 12, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3350

    Adobe ColdFusion 10 before Update 11 allows remote attackers to call ColdFusion Components (CFC) public methods via WebSockets.... Read more

    Affected Products : coldfusion
    • EPSS Score: %1.61
    • Published: Jul. 10, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-3195

    The DSA_InsertItem function in Comctl32.dll in the Windows common control library in Microsoft Windows XP SP2, Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows Server 2012, and Windows RT do... Read more

    • EPSS Score: %59.62
    • Published: Oct. 09, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2335

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1733.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %53.18
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2328

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1636.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %53.18
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2013-2324

    Unspecified vulnerability in HP Storage Data Protector 6.20, 6.21, 7.00, and 7.01 allows remote attackers to execute arbitrary code via unknown vectors, aka ZDI-CAN-1629.... Read more

    Affected Products : storage_data_protector
    • EPSS Score: %64.73
    • Published: Jun. 06, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-16803

    In CIMTechniques CIMScan 6.x through 6.2, the SOAP WSDL parser allows attackers to execute SQL code.... Read more

    Affected Products : cimscan
    • EPSS Score: %0.62
    • Published: Jan. 10, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-1751

    TWiki before 5.1.4 allows remote attackers to execute arbitrary shell commands by sending a crafted '%MAKETEXT{}%' parameter value containing Perl backtick characters.... Read more

    Affected Products : twiki
    • EPSS Score: %4.69
    • Published: Nov. 07, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2013-1534

    Unspecified vulnerability in the Workload Manager component in Oracle Database Server 11.2.0.2 and 11.2.0.3, when used in RAC configurations, allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : database_server
    • EPSS Score: %2.47
    • Published: Apr. 17, 2013
    • Modified: Apr. 11, 2025
Showing 20 of 292510 Results