Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2018-14009

    Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.... Read more

    Affected Products : codiad
    • EPSS Score: %55.16
    • Published: Jul. 12, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2010-3635

    Adobe Flash Media Server (FMS) 3.0.x before 3.0.7, 3.5.x before 3.5.5, and 4.0.x before 4.0.1 allows attackers to execute arbitrary code via unspecified vectors, related to a "segmentation fault vulnerability."... Read more

    Affected Products : flash_media_server
    • EPSS Score: %7.83
    • Published: Nov. 10, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2002-1974

    The FTP service in Zaurus PDAs SL-5000D and SL-5500 does not require authentication, which allows remote attackers to access the file system as root.... Read more

    Affected Products : zaurus
    • EPSS Score: %1.83
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1993

    webbbs_post.pl in WebBBS 4 and 5.0 allows remote attackers to execute arbitrary commands via shell metacharacters in the followup parameter.... Read more

    • EPSS Score: %6.56
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2002-1971

    The ping utility in networking_utils.php in Sourcecraft Networking_Utils 1.0 allows remote attackers to read arbitrary files via shell metacharacters in the Domain name or IP address argument.... Read more

    Affected Products : networking_utils
    • EPSS Score: %1.64
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2010-3036

    Multiple buffer overflows in the authentication functionality in the web-server module in Cisco CiscoWorks Common Services before 4.0 allow remote attackers to execute arbitrary code via a session on TCP port (1) 443 or (2) 1741, aka Bug ID CSCti41352.... Read more

    • EPSS Score: %28.40
    • Published: Oct. 29, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2018-13861

    Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allows unauthorized remote attackers to reboot or execute other functions via the "/xml/system/control.xml" URL, using the GET request "?action=reboot" for example.... Read more

    • EPSS Score: %1.87
    • Published: Jul. 17, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2010-2902

    The SVG implementation in Google Chrome before 5.0.375.125 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via unknown vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %1.05
    • Published: Jul. 28, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2002-2017

    sastcpd in SAS/Base 8.0 allows local users to execute arbitrary code by setting the authprog environment variable to reference a malicious program, which is then executed by sastcpd.... Read more

    Affected Products : base integration_technologies
    • EPSS Score: %0.82
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2010-2299

    The Clipboard::DispatchObject function in app/clipboard/clipboard.cc in Google Chrome before 5.0.375.70 does not properly handle CBF_SMBITMAP objects in a ViewHostMsg_ClipboardWriteObjectsAsync message, which might allow remote attackers to execute arbitr... Read more

    Affected Products : chrome
    • EPSS Score: %3.88
    • Published: Jun. 15, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1573

    Linksys WAP54Gv3 firmware 3.04.03 and earlier uses a hard-coded username (Gemtek) and password (gemtekswd) for a debug interface for certain web pages, which allows remote attackers to execute arbitrary commands via the (1) data1, (2) data2, or (3) data3 ... Read more

    Affected Products : wap54g_firmware wap54g
    • EPSS Score: %14.39
    • Published: Jun. 10, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1549

    Unspecified vulnerability in the Agent in HP LoadRunner before 9.50 and HP Performance Center before 9.50 allows remote attackers to execute arbitrary code via unknown vectors.... Read more

    Affected Products : windows performance_center loadrunner
    • EPSS Score: %88.81
    • Published: May. 07, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1319

    Integer overflow in the AgentX::receive_agentx function in AgentX++ 1.4.16, as used in RealNetworks Helix Server and Helix Mobile Server 11.x through 13.x and other products, allows remote attackers to execute arbitrary code via a request with a crafted p... Read more

    • EPSS Score: %4.62
    • Published: Apr. 20, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1229

    The sandbox infrastructure in Google Chrome before 4.1.249.1036 does not properly use pointers, which has unspecified impact and attack vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %0.43
    • Published: Apr. 01, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-1122

    Unspecified vulnerability in Mozilla Firefox 3.5.x through 3.5.8 allows remote attackers to cause a denial of service (memory corruption and application crash) and possibly have unknown other impact via vectors that might involve compressed data, a differ... Read more

    Affected Products : firefox
    • EPSS Score: %0.86
    • Published: Mar. 25, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0580

    Unspecified vulnerability in the SIP implementation in Cisco IOS 12.3 and 12.4 allows remote attackers to execute arbitrary code via a malformed SIP message, aka Bug ID CSCsz48680, the "SIP Message Processing Arbitrary Code Execution Vulnerability."... Read more

    Affected Products : ios
    • EPSS Score: %3.86
    • Published: Mar. 25, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0219

    Apache Axis2, as used in dswsbobje.war in SAP BusinessObjects Enterprise XI 3.2, CA ARCserve D2D r15, and other products, has a default password of axis2 for the admin account, which makes it easier for remote attackers to execute arbitrary code by upload... Read more

    Affected Products : businessobjects axis2
    • EPSS Score: %93.45
    • Published: Oct. 18, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2002-1918

    Buffer overflow in Microsoft Active Data Objects (ADO) in Microsoft MDAC 2.5 through 2.7 allows remote attackers to have unknown impact with unknown attack vectors. NOTE: due to the lack of details available regarding this issue, perhaps it should be REJ... Read more

    Affected Products : data_access_components
    • EPSS Score: %32.48
    • Published: Dec. 31, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2010-0073

    Unspecified vulnerability in the WebLogic Server in Oracle WebLogic Server 7.0 SP7, 8.1 SP6, 9.0, 9.1, 9.2 MP3, 10.0 MP2, and 10.3.2 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : weblogic_server
    • EPSS Score: %2.93
    • Published: Apr. 14, 2010
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-2010-0071

    Unspecified vulnerability in the Listener component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, 10.2.0.4, and 11.1.0.7 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more

    Affected Products : database_server
    • EPSS Score: %12.52
    • Published: Jan. 13, 2010
    • Modified: Apr. 09, 2025
Showing 20 of 292495 Results