Latest CVE Feed
-
10.0
HIGHCVE-2005-2669
Computer Associates (CA) Message Queuing (CAM / CAFT) 1.05, 1.07 before Build 220_13, and 1.11 before Build 29_13 allows remote attackers to execute arbitrary commands via spoofed CAFT packets.... Read more
- Published: Aug. 23, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1220
D-Link DWL-1000AP Firmware 3.2.28 #483 Wireless LAN Access Point stores the administrative password in plaintext in the default Management Information Base (MIB), which allows remote attackers to gain administrative privileges.... Read more
Affected Products : dwl-1000ap- Published: Dec. 21, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1440
Unknown vulnerability in login for AIX 5.1L, when using loadable authentication modules, allows remote attackers to gain access to the system.... Read more
Affected Products : aix- Published: Dec. 21, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-10698
An issue was discovered on Moxa AWK-3121 1.14 devices. The device enables an unencrypted TELNET service by default. This allows an attacker who has been able to gain an MITM position to easily sniff the traffic between the device and the user. Also an att... Read more
- Published: Jun. 07, 2019
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10682
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automatically created. Once logged in, a misconfiguration prese... Read more
Affected Products : wildfly- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10660
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.... Read more
Affected Products : p1204_firmware a1001_firmware a8004-v_firmware a8105-e_firmware a9161_firmware a9188_firmware a9188-v_firmware c1004-e_firmware c2005_firmware c3003-e_firmware +770 more products- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2005-2247
Multiple unknown vulnerabilities in Moodle before 1.5.1 have unknown impact and attack vectors.... Read more
Affected Products : moodle- Published: Jul. 12, 2005
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1078
Format string vulnerability in flog function of eXtremail 1.1.9 and earlier allows remote attackers to gain root privileges via format specifiers in the SMTP commands (1) HELO, (2) EHLO, (3) MAIL FROM, or (4) RCPT TO, and the POP3 commands (5) USER and (6... Read more
Affected Products : extremail- Published: Jun. 21, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1061
Vulnerability in lsmcode in unknown versions of AIX, possibly related to a usage error.... Read more
Affected Products : aix- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-10661
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.... Read more
Affected Products : p1204_firmware a1001_firmware a8004-v_firmware a8105-e_firmware a9161_firmware a9188_firmware a9188-v_firmware c1004-e_firmware c2005_firmware c3003-e_firmware +770 more products- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10662
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.... Read more
Affected Products : p1204_firmware a1001_firmware a8004-v_firmware a8105-e_firmware a9161_firmware a9188_firmware a9188-v_firmware c1004-e_firmware c2005_firmware c3003-e_firmware +770 more products- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-1025
PHP-Nuke 5.x allows remote attackers to perform arbitrary SQL operations by modifying the "prefix" variable when calling any scripts that do not already define the prefix variable (e.g., by including mainfile.php), such as article.php.... Read more
Affected Products : php-nuke- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-1011
index2.php in Mambo Site Server 3.0.0 through 3.0.5 allows remote attackers to gain Mambo administrator privileges by setting the PHPSESSID parameter and providing the appropriate administrator information in other parameters.... Read more
Affected Products : mambo_site_server- Published: Jul. 25, 2001
- Modified: Apr. 03, 2025
-
10.0
CRITICALCVE-2018-10718
Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.... Read more
Affected Products : call_of_duty_modern_warfare_2- Published: May. 03, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10630
For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access... Read more
Affected Products : tsw-x60_firmware mc3_firmware tsw-1060-b-s tsw-1060-nc-b-s tsw-1060-nc-w-s tsw-1060-w-s tsw-560-b-s tsw-560-nc-b-s tsw-560-nc-w-s tsw-560-w-s +5 more products- Published: Aug. 10, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-0972
Surf-Net ASP Forum before 2.30 uses easily guessable cookies based on the UserID, which allows remote attackers to gain administrative privileges by calculating the value of the admin cookie (UserID 1), i.e. "0888888."... Read more
Affected Products : asp_forum- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0968
Knox Arkeia server 4.2, and possibly other versions, installs its root user with a null password by default, which allows local and remote users to gain privileges.... Read more
Affected Products : arkeia- Published: Aug. 31, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2018-10635
In Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100, ports 30001/TCP to 30003/TCP listen for arbitrary URScript code and execute the code. This enables a remote attacker who has access to the ports to remotely execute code that may ... Read more
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2001-0808
gnatsweb.pl in GNATS GnatsWeb 2.7 through 3.95 allows remote attackers to execute arbitrary commands via certain characters in the help_file parameter.... Read more
Affected Products : gnatsweb- Published: Dec. 06, 2001
- Modified: Apr. 03, 2025
-
10.0
HIGHCVE-2001-0789
Format string vulnerability in avpkeeper in Kaspersky KAV 3.5.135.2 for Sendmail allows remote attackers to cause a denial of service or possibly execute arbitrary code via a malformed mail message.... Read more
Affected Products : kaspersky_anti-virus- Published: Oct. 18, 2001
- Modified: Apr. 03, 2025