Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2016-6818

    SQL injection vulnerability in SAP Business Intelligence platform before January 2017 allows remote attackers to obtain sensitive information, modify data, cause a denial of service (data deletion), or launch administrative operations or possibly OS comma... Read more

    Affected Products : business_intelligence_platform
    • EPSS Score: %1.51
    • Published: Apr. 13, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    CRITICAL
    CVE-2021-23594

    All versions of package realms-shim are vulnerable to Sandbox Bypass via a Prototype Pollution attack vector.... Read more

    Affected Products : realms-shim
    • EPSS Score: %0.56
    • Published: Jan. 10, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-6726

    Unspecified vulnerability in Qualcomm components in Android on Nexus 6 and Android One devices.... Read more

    Affected Products : android
    • EPSS Score: %0.11
    • Published: Apr. 17, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-6727

    The Qualcomm GPS subsystem in Android on Android One devices allows remote attackers to execute arbitrary code.... Read more

    Affected Products : android
    • EPSS Score: %5.74
    • Published: Apr. 17, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-1558

    Buffer overflow in D-Link DAP-2310 2.06 and earlier, DAP-2330 1.06 and earlier, DAP-2360 2.06 and earlier, DAP-2553 H/W ver. B1 3.05 and earlier, DAP-2660 1.11 and earlier, DAP-2690 3.15 and earlier, DAP-2695 1.16 and earlier, DAP-3320 1.00 and earlier, a... Read more

    • EPSS Score: %14.87
    • Published: Apr. 21, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    CRITICAL
    CVE-2017-2320

    A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, ... Read more

    Affected Products : northstar_controller
    • EPSS Score: %0.49
    • Published: Apr. 24, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2017-2096

    smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more

    Affected Products : smalruby-editor
    • EPSS Score: %6.84
    • Published: Apr. 28, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2017-4982

    EMC Mainframe Enablers ResourcePak Base versions 7.6.0, 8.0.0, and 8.1.0 contains a fix for a privilege management vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more

    • EPSS Score: %0.97
    • Published: May. 08, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-10372

    The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the W... Read more

    Affected Products : d1000_modem_firmware d1000_modem
    • EPSS Score: %91.97
    • Published: May. 16, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-0761

    Cloud Foundry Garden-Linux versions prior to v0.333.0 and Elastic Runtime 1.6.x version prior to 1.6.17 contain a flaw in managing container files during Docker image preparation that could be used to delete, corrupt or overwrite host files and directorie... Read more

    • EPSS Score: %0.55
    • Published: May. 25, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2017-9034

    Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to write to arbitrary files and consequently execute arbitrary code with root privileges by leveraging failure to validate software updates.... Read more

    Affected Products : serverprotect
    • EPSS Score: %7.39
    • Published: May. 26, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2021-45733

    TOTOLINK X5000R v9.1.0u.6118_B20201102 was discovered to contain a command injection vulnerability in the function NTPSyncWithHost. This vulnerability allows attackers to execute arbitrary commands via the parameter host_time.... Read more

    Affected Products : x5000r_firmware x5000r
    • EPSS Score: %25.81
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2021-29393

    Remote Code Execution in cominput.jsp and comoutput.jsp in Northstar Technologies Inc NorthStar Club Management 6.3 allows remote unauthenticated users to inject and execute arbitrary system commands via the unsanitized user-controlled "command" and "comm... Read more

    Affected Products : northstar_club_management
    • EPSS Score: %14.16
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2021-21961

    A stack-based buffer overflow vulnerability exists in the NBNS functionality of Sealevel Systems, Inc. SeaConnect 370W v1.3.34. A specially-crafted network packet can lead to remote code execution. An attacker can send a malicious packet to trigger this v... Read more

    • EPSS Score: %1.88
    • Published: Feb. 04, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2020-11140

    Out of bound memory access during music playback with ALAC modified content due to improper validation in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, ... Read more

    Affected Products : apq8017 apq8037 apq8052 apq8053 apq8056 apq8062 apq8064au apq8076 apq8084 apq8096au +439 more products
    • EPSS Score: %0.33
    • Published: Jan. 21, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-7806

    I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more

    Affected Products : wfs-sr01_firmware wfs-sr01
    • EPSS Score: %11.02
    • Published: Jun. 09, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2016-7836

    SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program.... Read more

    Affected Products : skysea_client_view
    • EPSS Score: %37.70
    • Published: Jun. 09, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2017-6667

    A vulnerability in the update process for the dynamic JAR file of the Cisco Context Service software development kit (SDK) could allow an unauthenticated, remote attacker to execute arbitrary code on the affected device with the privileges of the web serv... Read more

    Affected Products : context_service_development_kit
    • EPSS Score: %3.35
    • Published: Jun. 13, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2022-21143

    MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary co... Read more

    • EPSS Score: %0.23
    • Published: Feb. 18, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2022-21215

    This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker... Read more

    • EPSS Score: %0.24
    • Published: Feb. 18, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 290981 Results