Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2018-10698

    An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an att... Read more

    Affected Products : awk-3121_firmware awk-3121
    • Published: Jun. 07, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-10682

    An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration prese... Read more

    Affected Products : wildfly
    • Published: May. 09, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-10660

    An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.... Read more

    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2005-2247

    Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.... Read more

    Affected Products : moodle
    • Published: Jul. 12, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1078

    Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6... Read more

    Affected Products : extremail
    • Published: Jun. 21, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1061

    Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.... Read more

    Affected Products : aix
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-10661

    An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.... Read more

    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-10662

    An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.... Read more

    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2001-1025

    PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.... Read more

    Affected Products : php-nuke
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1011

    index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.... Read more

    Affected Products : mambo_site_server
    • Published: Jul. 25, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    CRITICAL
    CVE-2018-10718

    Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.... Read more

    Affected Products : call_of_duty_modern_warfare_2
    • Published: May. 03, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-10630

    For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access... Read more

    • Published: Aug. 10, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2001-0972

    Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."... Read more

    Affected Products : asp_forum
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0968

    Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.... Read more

    Affected Products : arkeia
    • Published: Aug. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-10635

    In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execute the code. This enables a remote attacker who has access to the ports to remotely execute code that may ... Read more

    Affected Products : cb3.1_firmware cb3.1
    • Published: Jul. 11, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2001-0808

    gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.... Read more

    Affected Products : gnatsweb
    • Published: Dec. 06, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0789

    Format string vulnerability in avpkeeper in Kaspersky KAV 3.5.135.2 for Sendmail allows remote attackers to cause a denial of service or possibly execute arbitrary code via a malformed mail message.... Read more

    Affected Products : kaspersky_anti-virus
    • Published: Oct. 18, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-10592

    Yokogawa STARDOM FCJ controllers R4.02 and prior, FCN-100 controllers R4.02 and prior, FCN-RTU controllers R4.02 and prior, and FCN-500 controllers R4.02 and prior utilize hard-coded credentials that could allow an attacker to gain unauthorized administra... Read more

    • Published: Jul. 31, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2001-0671

    Buffer overflows in (1) send_status, (2) kill_print, and (3) chk_fhost in lpd in AIX 4.3 and 5.1 allow remote attackers to gain root privileges.... Read more

    Affected Products : aix
    • Published: Dec. 06, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-0679

    A buffer overflow in InterScan VirusWall 3.23 and 3.3 allows a remote attacker to execute arbitrary code by sending a long HELO command to the server.... Read more

    Affected Products : interscan_viruswall
    • Published: Nov. 08, 1999
    • Modified: Apr. 03, 2025
Showing 20 of 293259 Results