Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2010-2302

    Use-after-free vulnerability in WebCore in WebKit in Google Chrome before 5.0.375.70 allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via vectors involving remote fonts in conjunction with shadow ... Read more

    • EPSS Score: %5.16
    • Published: Jun. 15, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-2299

    The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitr... Read more

    Affected Products : chrome
    • EPSS Score: %3.88
    • Published: Jun. 15, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-2217

    Adobe Flash Media Server (FMS) before 3.0.6, and 3.5.x before 3.5.4, allows attackers to execute arbitrary code via unspecified vectors, related to a "JS method vulnerability."... Read more

    • EPSS Score: %5.97
    • Published: Aug. 11, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-2105

    Google Chrome before 5.0.375.55 does not properly follow the Safe Browsing specification's requirements for canonicalization of URLs, which has unspecified impact and remote attack vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %0.35
    • Published: May. 28, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1663

    The Google URL Parsing Library (aka google-url or GURL) in Google Chrome before 4.1.249.1064 allows remote attackers to bypass the Same Origin Policy via unspecified vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %7.39
    • Published: May. 03, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1574

    IOS 12.2(52)SE and 12.2(52)SE1 on Cisco Industrial Ethernet (IE) 3000 series switches has (1) a community name of public for RO access and (2) a community name of private for RW access, which makes it easier for remote attackers to modify the configuratio... Read more

    Affected Products : ios industrial_ethernet_3000
    • EPSS Score: %3.10
    • Published: Jul. 08, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1573

    Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 ... Read more

    Affected Products : wap54g_firmware wap54g
    • EPSS Score: %14.74
    • Published: Jun. 10, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1549

    Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : windows performance_center loadrunner
    • EPSS Score: %88.81
    • Published: May. 07, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1505

    Google Chrome before 4.1.249.1059 does not prevent pages from loading with the New Tab page's privileges, which has unknown impact and attack vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %1.12
    • Published: Apr. 23, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1319

    Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted p... Read more

    • EPSS Score: %4.62
    • Published: Apr. 20, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1318

    Stack-based buffer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via unspecified vec... Read more

    • EPSS Score: %77.59
    • Published: Apr. 20, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1229

    The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %0.43
    • Published: Apr. 01, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1122

    Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a differ... Read more

    Affected Products : firefox
    • EPSS Score: %0.86
    • Published: Mar. 25, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1120

    Unspecified vulnerability in Safari 4 on Apple Mac OS X 10.6 allows remote attackers to execute arbitrary code via unknown vectors, as demonstrated by Charlie Miller during a Pwn2Own competition at CanSecWest 2010.... Read more

    Affected Products : mac_os_x safari
    • EPSS Score: %3.03
    • Published: Mar. 25, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0646

    Multiple integer signedness errors in factory.cc in Google V8 before r3560, as used in Google Chrome before 4.0.249.89, allow remote attackers to execute arbitrary code in the Chrome sandbox via crafted use of JavaScript arrays.... Read more

    Affected Products : chrome
    • EPSS Score: %10.91
    • Published: Feb. 18, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0580

    Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."... Read more

    Affected Products : ios
    • EPSS Score: %3.86
    • Published: Mar. 25, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0219

    Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by upload... Read more

    Affected Products : businessobjects axis2
    • EPSS Score: %93.45
    • Published: Oct. 18, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0145

    Unspecified vulnerability in the embedded HTTPS server on the Cisco IronPort Encryption Appliance 6.2.x before 6.2.9.1 and 6.5.x before 6.5.2, and the IronPort PostX MAP before 6.2.9.1, allows remote attackers to execute arbitrary code via unknown vectors... Read more

    • EPSS Score: %1.36
    • Published: Feb. 11, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0121

    The cook codec in RealNetworks RealPlayer 11.0 through 11.1, RealPlayer SP 1.0 through 1.1.5, Mac RealPlayer 11.0 through 12.0.0.1444, and Linux RealPlayer 11.0.2.1744 does not properly perform initialization, which has unspecified impact and attack vecto... Read more

    • EPSS Score: %0.40
    • Published: Dec. 14, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0073

    Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %2.93
    • Published: Apr. 14, 2010
    • Modified: Apr. 11, 2025
Showing 20 of 291526 Results