Latest CVE Feed
-
10.0
HIGHCVE-2018-11138
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.... Read more
- Actively Exploited
- EPSS Score: %88.08
- Published: May. 31, 2018
- Modified: Mar. 14, 2025
-
10.0
HIGHCVE-2009-4335
Multiple unspecified vulnerabilities in bundled stored procedures in the Spatial Extender component in IBM DB2 9.5 before FP5 have unknown impact and remote attack vectors, related to "remote exploits."... Read more
Affected Products : db2- EPSS Score: %1.73
- Published: Dec. 16, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-3792
Directory traversal vulnerability in Adobe Flash Media Server (FMS) before 3.5.3 allows attackers to load arbitrary DLL files via unspecified vectors.... Read more
Affected Products : flash_media_server- EPSS Score: %0.40
- Published: Dec. 21, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-1641
Multiple buffer overflows in Oracle Web Cache for Oracle 9i Application Server (9iAS) allow remote attackers to execute arbitrary code via unknown vectors.... Read more
- EPSS Score: %13.22
- Published: May. 27, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2002-1659
user_profile.asp in PortalApp 2.2 allows local users to gain privileges by modifying the user_id variable.... Read more
Affected Products : portalapp- EPSS Score: %0.35
- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-13338
System command injection in ajaxdata.php in TerraMaster TOS version 3.1.03 allows attackers to execute system commands via the "username" parameter during user creation.... Read more
- EPSS Score: %12.49
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-13306
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "ftpUser" POST parameter.... Read more
- EPSS Score: %15.30
- Published: Nov. 27, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-13311
System command injection in formDlna in TOTOLINK A3002RU version 1.0.8 allows attackers to execute system commands via the "sambaUser" POST parameter.... Read more
- EPSS Score: %5.05
- Published: Nov. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-2685
Stack-based buffer overflow in the login form in the management web server in HP Power Manager allows remote attackers to execute arbitrary code via the Login variable.... Read more
Affected Products : power_manager- EPSS Score: %76.74
- Published: Nov. 06, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2002-1582
compose.cgi in Mailreader.com 2.3.30 and 2.3.31, when using Sendmail as the Mail Transfer Agent, allows remote attackers to execute arbitrary commands via shell metacharacters in the RealEmail configuration variable, which is used to call Sendmail in netw... Read more
Affected Products : mailreader.com- EPSS Score: %1.48
- Published: Dec. 06, 2004
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2009-2452
Multiple unspecified vulnerabilities in Citrix Licensing 11.5 have unknown impact and attack vectors, related to "underlying components of the License Management Console."... Read more
Affected Products : licensing- EPSS Score: %0.60
- Published: Jul. 14, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1985
Unspecified vulnerability in the Network Authentication component in Oracle Database 9.2.0.8, 9.2.0.8DV, 10.1.0.5, and 10.2.0.4 allows remote attackers to affect confidentiality, integrity, and availability via unknown vectors.... Read more
Affected Products : database_server- EPSS Score: %3.20
- Published: Oct. 22, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1628
Stack-based buffer overflow in mnet.exe in Unisys Business Information Server (BIS) 10 and 10.1 on Windows allows remote attackers to execute arbitrary code via a crafted TCP packet.... Read more
- EPSS Score: %3.91
- Published: Jun. 26, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2018-13101
KioskSimpleService.exe in RedSwimmer KioskSimple 1.4.7.0 suffers from a privilege escalation vulnerability in the WCF endpoint. The exposed methods allow read and write access to the Windows registry and control of services. These methods may be abused to... Read more
Affected Products : kiosksimple- EPSS Score: %0.73
- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2009-1350
Unspecified vulnerability in xtagent.exe in Novell NetIdentity Client before 1.2.4 allows remote attackers to execute arbitrary code by establishing an IPC$ connection to the XTIERRPCPIPE named pipe, and sending RPC messages that trigger a dereference of ... Read more
Affected Products : netidentity_client1.2.3- EPSS Score: %75.46
- Published: Apr. 21, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-1231
Unspecified vulnerability in the eClient in IBM DB2 Content Manager 8.4.1 before 8.4.1.1 has unknown impact and attack vectors.... Read more
Affected Products : db2_content_manager- EPSS Score: %0.51
- Published: Apr. 02, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0896
Buffer overflow in the queue manager in IBM WebSphere MQ 6.x before 6.0.2.7 and 7.x before 7.0.1.0 allows remote attackers to execute arbitrary code via a crafted request.... Read more
Affected Products : websphere_mq- EPSS Score: %25.84
- Published: Jun. 03, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0837
Stack-based buffer overflow in Foxit Reader 3.0 before Build 1506, including 1120 and 1301, allows remote attackers to execute arbitrary code via a long (1) relative path or (2) absolute path in the filename argument in an action, as demonstrated by the "... Read more
Affected Products : reader3.0- EPSS Score: %83.22
- Published: Mar. 10, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0720
Unspecified vulnerability in HP OpenView Network Node Manager (OV NNM) 7.01, 7.51, and 7.53 allows remote attackers to execute arbitrary code via unknown vectors.... Read more
Affected Products : openview_network_node_manager- EPSS Score: %6.53
- Published: May. 05, 2009
- Modified: Apr. 09, 2025
-
10.0
HIGHCVE-2009-0517
Eval injection vulnerability in index.php in phpSlash 0.8.1.1 and earlier allows remote attackers to execute arbitrary PHP code via the fields parameter, which is supplied to an eval function call within the generic function in include/class/tz_env.class.... Read more
Affected Products : phpslash- EPSS Score: %61.62
- Published: Feb. 11, 2009
- Modified: Apr. 09, 2025