Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2012-1166

    The default keybindings for wwm in LTSP Display Manager (ldm) 2.2.x before 2.2.7 allow remote attackers to execute arbitrary commands via the KP_RETURN keybinding, which launches a terminal window.... Read more

    Affected Products : ubuntu_linux ltsp_display_manager
    • EPSS Score: %4.37
    • Published: May. 21, 2014
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2002-2402

    SURECOM broadband router EP-4501 uses a default SNMP read community string of "public" and a default SNMP read/write community string of "secret," which allows remote attackers to read and modify router configuration information.... Read more

    Affected Products : ep-4501
    • EPSS Score: %0.70
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-15555

    On Telus Actiontec WEB6000Q v1.1.02.22 devices, an attacker can login with root level access with the user "root" and password "admin" by using the enabled onboard UART headers.... Read more

    Affected Products : web6000q_firmware web6000q
    • EPSS Score: %1.16
    • Published: Jun. 28, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2012-0780

    Adobe Illustrator before CS6 allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2012-2023, CVE-2012-2024, CVE-2012-2025, and CVE-2012-2026.... Read more

    Affected Products : illustrator illustrator_cs5.5
    • EPSS Score: %48.81
    • Published: May. 09, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2002-2365

    Simple WAIS (SWAIS) 1.11 allows remote attackers to execute arbitrary commands via the shell metacharacters in the search field, as demonstrated using the "|" (pipe) character.... Read more

    Affected Products : simple_wais
    • EPSS Score: %1.59
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2012-0697

    HP StorageWorks P2000 G3 MSA array systems have a default account, which makes it easier for remote attackers to perform administrative tasks via unspecified vectors, a different vulnerability than CVE-2011-4788.... Read more

    Affected Products : storageworks_p2000_g3_msa
    • EPSS Score: %3.39
    • Published: Jan. 13, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-15556

    The Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty password by using the enabled onboard UART headers.... Read more

    Affected Products : web6000q_firmware web6000q
    • EPSS Score: %2.54
    • Published: Jun. 27, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2012-0290

    Symantec pcAnywhere through 12.5.3, Altiris IT Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), Altiris Client Management Suite pcAnywhere Solution 7.0 (aka 12.5.x) and 7.1 (aka 12.6.x), and Altiris Deployment Solution Remote pc... Read more

    • EPSS Score: %2.61
    • Published: Feb. 06, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0264

    op5 Monitor and op5 Appliance before 5.5.0 do not properly manage session cookies, which allows remote attackers to have an unspecified impact via unspecified vectors.... Read more

    Affected Products : monitor
    • EPSS Score: %4.44
    • Published: Dec. 31, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0261

    license.php in system-portal before 1.6.2 in op5 Monitor and op5 Appliance before 5.5.3 allows remote attackers to execute arbitrary commands via shell metacharacters in the timestamp parameter for an install action.... Read more

    Affected Products : monitor system-portal
    • EPSS Score: %86.45
    • Published: Dec. 31, 2013
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-15427

    A vulnerability in Cisco Video Surveillance Manager (VSM) Software running on certain Cisco Connected Safety and Security Unified Computing System (UCS) platforms could allow an unauthenticated, remote attacker to log in to an affected system by using the... Read more

    • EPSS Score: %14.45
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2012-0123

    Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1498.... Read more

    Affected Products : data_protector_express
    • EPSS Score: %27.34
    • Published: Mar. 14, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2012-0122

    Unspecified vulnerability in HP Data Protector Express (aka DPX) 5.0.00 before build 59287 and 6.0.00 before build 11974 allows remote attackers to execute arbitrary code or cause a denial of service via unknown vectors, aka ZDI-CAN-1393.... Read more

    Affected Products : data_protector_express
    • EPSS Score: %25.06
    • Published: Mar. 14, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-15353

    A Buffer Overflow exploited through web interface by remote attacker can cause remote code execution in Kraftway 24F2XG Router firmware 3.5.30.1118.... Read more

    • EPSS Score: %3.62
    • Published: Aug. 17, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-15350

    Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router.... Read more

    • EPSS Score: %0.71
    • Published: Aug. 17, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2011-4255

    Unspecified vulnerability in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via an invalid codec name.... Read more

    Affected Products : realplayer
    • EPSS Score: %5.22
    • Published: Nov. 24, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-4253

    Unspecified vulnerability in the RV20 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : realplayer
    • EPSS Score: %5.22
    • Published: Nov. 24, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2011-4244

    Heap-based buffer overflow in the RealVideo renderer in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : realplayer
    • EPSS Score: %5.54
    • Published: Nov. 24, 2011
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2003-0143

    The pop_msg function in qpopper 4.0.x before 4.0.5fc2 does not null terminate a message buffer after a call to Qvsnprintf, which could allow authenticated users to execute arbitrary code via a buffer overflow in a mdef command with a long macro name.... Read more

    Affected Products : qpopper
    • EPSS Score: %9.13
    • Published: Mar. 18, 2003
    • Modified: Apr. 03, 2025
  • 10.0

    CRITICAL
    CVE-2023-22518

    All versions of Confluence Data Center and Server are affected by this unexploited vulnerability. This Improper Authorization vulnerability allows an unauthenticated attacker to reset Confluence and create a Confluence instance administrator account. Usin... Read more

    • Actively Exploited
    • EPSS Score: %94.38
    • Published: Oct. 31, 2023
    • Modified: Feb. 10, 2025
Showing 20 of 292522 Results