Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2006-3100

    termpkg 3.3 suffers from buffer overflow.... Read more

    Affected Products : termpkg
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-12419

    Apache CXF before 3.3.4 and 3.2.11 provides all of the components that are required to build a fully fledged OpenId Connect service. There is a vulnerability in the access token services, where it does not validate that the authenticated principal is equa... Read more

    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2010-2476

    syscp 1.4.2.1 allows attackers to add arbitrary paths via the documentroot of a domain by appending a colon to it and setting the open basedir path to use that domain documentroot.... Read more

    Affected Products : syscp
    • Published: Nov. 07, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2007-6745

    clamav 0.91.2 suffers from a floating point exception when using ScanOLE2.... Read more

    Affected Products : debian_linux clamav
    • Published: Nov. 07, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-12719

    An issue was discovered in Picture_Manage_mvc.aspx in AUO SunVeillance Monitoring System before v1.1.9e. There is an incorrect access control vulnerability that can allow an unauthenticated user to upload files via a modified authority parameter.... Read more

    • Published: Nov. 12, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-18952

    SibSoft Xfilesharing through 2.5.1 allows cgi-bin/up.cgi arbitrary file upload. This can be combined with CVE-2019-18951 to achieve remote code execution via a .html file, containing short codes, that is served over HTTP.... Read more

    Affected Products : xfilesharing
    • Published: Nov. 13, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-14345

    TemaTres 3.0 allows remote unprivileged users to create an administrator account... Read more

    Affected Products : tematres
    • Published: Nov. 15, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000006

    hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.... Read more

    Affected Products : hhvm
    • Published: Nov. 19, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-0824

    gnusound 0.7.5 has format string issue... Read more

    Affected Products : gnusound
    • Published: Nov. 19, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2013-2091

    SQL injection vulnerability in Dolibarr ERP/CRM 3.3.1 allows remote attackers to execute arbitrary SQL commands via the 'pays' parameter in fiche.php.... Read more

    Affected Products : dolibarr_erp\/crm
    • Published: Nov. 20, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-3460

    cumin: At installation postgresql database user created without password... Read more

    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-3700

    eDeploy through at least 2014-10-14 has remote code execution due to eval() of untrusted data... Read more

    Affected Products : jboss_enterprise_web_server edeploy
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-16340

    Belkin Linksys Velop 1.1.8.192419 devices allows remote attackers to discover the recovery key via a direct request for the /sysinfo_json.cgi URI.... Read more

    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-11325

    An issue was discovered in Symfony before 4.2.12 and 4.3.x before 4.3.8. The VarExport component incorrectly escapes strings, allowing some specially crafted ones to escalate to execution of arbitrary PHP code. This is related to symfony/var-exporter.... Read more

    Affected Products : symfony
    • Published: Nov. 21, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2014-6310

    Buffer overflow in CHICKEN 4.9.0 and 4.9.0.1 may allow remote attackers to execute arbitrary code via the 'select' function.... Read more

    Affected Products : debian_linux chicken
    • Published: Nov. 22, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-5582

    opendnssec misuses libcurl API... Read more

    Affected Products : opendnssec
    • Published: Nov. 25, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-19250

    OpenTrade before 2019-11-23 allows SQL injection, related to server/modules/api/v1.js and server/utils.js.... Read more

    Affected Products : opentrade
    • Published: Nov. 25, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-19492

    FreeSWITCH 1.6.10 through 1.10.1 has a default password in event_socket.conf.xml.... Read more

    Affected Products : freeswitch
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-12394

    Anviz access control devices allow unverified password change which allows remote attackers to change the administrator password without prior authentication.... Read more

    Affected Products : management_system
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2019-19021

    An issue was discovered in TitanHQ WebTitan before 5.18. It has a hidden support account (with a hard-coded password) in the web administration interface, with administrator privileges. Anybody can log in with this account.... Read more

    Affected Products : webtitan
    • Published: Dec. 02, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292803 Results