Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2017-1000214

    GitPHP by xiphux is vulnerable to OS Command Injections... Read more

    Affected Products : gitphp
    • EPSS Score: %7.22
    • Published: Nov. 27, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2020-7805

    An issue was discovered on KT Slim egg IML500 (R7283, R8112, R8424) and IML520 (R8112, R8368, R8411) wifi device. This issue is a command injection allowing attackers to execute arbitrary OS commands.... Read more

    • EPSS Score: %5.27
    • Published: May. 07, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2008-2888

    Multiple PHP remote file inclusion vulnerabilities in MiGCMS 2.0.5, when register_globals is enabled, allow remote attackers to execute arbitrary PHP code via a URL in the GLOBALS[application][app_root] parameter to (1) collection.class.php and (2) conten... Read more

    Affected Products : migcms
    • EPSS Score: %2.25
    • Published: Jun. 27, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2002-0491

    admin.php in AlGuest 1.0 guestbook checks for the existence of the admin cookie to authenticate the AlGuest administrator, which allows remote attackers to bypass the authentication and gain privileges by setting the admin cookie to an arbitrary value.... Read more

    Affected Products : alguest
    • EPSS Score: %0.55
    • Published: Aug. 12, 2002
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2001-1573

    Buffer overflow in smtpscan.dll for Trend Micro InterScan VirusWall 3.51 for Windows NT has allows remote attackers to execute arbitrary code via a certain configuration parameter.... Read more

    Affected Products : interscan_viruswall
    • EPSS Score: %1.95
    • Published: Dec. 31, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2008-4509

    Unrestricted file upload vulnerability in processFiles.php in FOSS Gallery Admin and FOSS Gallery Public 1.0 beta allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to... Read more

    Affected Products : foss_gallery
    • EPSS Score: %14.68
    • Published: Oct. 09, 2008
    • Modified: Apr. 09, 2025
  • 10.0

    CRITICAL
    CVE-2019-18580

    Dell EMC Storage Monitoring and Reporting version 4.3.1 contains a Java RMI Deserialization of Untrusted Data vulnerability. A remote unauthenticated attacker may potentially exploit this vulnerability by sending a crafted RMI request to execute arbitrary... Read more

    • EPSS Score: %11.84
    • Published: Nov. 26, 2019
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2007-1917

    Buffer overflow in the SYSTEM_CREATE_INSTANCE function in the SAP RFC Library 6.40 and 7.00 before 20061211 allows remote attackers to execute arbitrary code via unspecified vectors. NOTE: This information is based upon a vague initial disclosure. Detail... Read more

    • EPSS Score: %9.37
    • Published: Apr. 10, 2007
    • Modified: Apr. 09, 2025
  • 10.0

    HIGH
    CVE-2012-1239

    The TopAccess web-based management interface on TOSHIBA TEC e-Studio multi-function peripheral (MFP) devices with firmware 30x through 302, 35x through 354, and 4xx through 421 allows remote attackers to bypass authentication and obtain administrative pri... Read more

    • EPSS Score: %15.08
    • Published: Apr. 06, 2012
    • Modified: Apr. 11, 2025
  • 10.0

    HIGH
    CVE-1999-0119

    Windows NT 4.0 beta allows users to read and delete shares.... Read more

    Affected Products : windows_nt
    • EPSS Score: %11.70
    • Published: Jan. 19, 1999
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-0124

    Vulnerabilities in UMN gopher and gopher+ versions 1.12 and 2.0x allow an intruder to read any files that can be accessed by the gopher daemon.... Read more

    Affected Products : gopherd
    • EPSS Score: %0.48
    • Published: Aug. 09, 1993
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2017-6526

    An issue was discovered in dnaTools dnaLIMS 4-2015s13. dnaLIMS is vulnerable to unauthenticated command execution through an improperly protected administrative web shell (cgi-bin/dna/sysAdmin.cgi POST requests).... Read more

    Affected Products : dnalims
    • EPSS Score: %83.73
    • Published: Mar. 09, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    CRITICAL
    CVE-2024-31115

    Unrestricted Upload of File with Dangerous Type vulnerability in QuanticaLabs Chauffeur Taxi Booking System for WordPress.This issue affects Chauffeur Taxi Booking System for WordPress: from n/a through 7.2. ... Read more

    Affected Products :
    • Published: Mar. 31, 2024
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2000-0515

    The snmpd.conf configuration file for the SNMP daemon (snmpd) in HP-UX 11.0 is world writable, which allows local users to modify SNMP configuration or gain privileges.... Read more

    Affected Products : hp-ux
    • EPSS Score: %1.47
    • Published: Jun. 07, 2000
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-1999-1588

    Buffer overflow in nlps_server in Sun Solaris x86 2.4, 2.5, and 2.5.1 allows remote attackers to execute arbitrary code as root via a long string beginning with "NLPS:002:002:" to the listen (aka System V listener) port, TCP port 2766.... Read more

    Affected Products : solaris
    • EPSS Score: %6.85
    • Published: Dec. 31, 1999
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2016-0815

    The MPEG4Source::fragmentedRead function in MPEG4Extractor.cpp in libstagefright in mediaserver in Android 4.x before 4.4.4, 5.x before 5.1.1 LMY49H, and 6.x before 2016-03-01 allows remote attackers to execute arbitrary code or cause a denial of service ... Read more

    Affected Products : android
    • EPSS Score: %1.90
    • Published: Mar. 12, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2004-0962

    Apple Remote Desktop Client 1.2.4 executes a GUI application as root when it is started by an Apple Remote Desktop Administrator application, which allows remote authenticated users to execute arbitrary code when loginwindow is active via Fast User Switch... Read more

    Affected Products : apple_remote_desktop
    • EPSS Score: %1.78
    • Published: Feb. 09, 2005
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2020-8636

    An issue was discovered in OpServices OpMon 9.3.2 that allows Remote Code Execution .... Read more

    Affected Products : opmon
    • EPSS Score: %4.75
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2001-0629

    HP Event Correlation Service (ecsd) as included with OpenView Network Node Manager 6.1 allows a remote attacker to gain addition privileges via a buffer overflow attack in the '-restore_config' command line parameter.... Read more

    Affected Products : openview_network_node_manager
    • EPSS Score: %0.98
    • Published: Aug. 14, 2001
    • Modified: Apr. 03, 2025
  • 10.0

    HIGH
    CVE-2018-17066

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in... Read more

    Affected Products : dir-816_a2_firmware dir-816_a2
    • EPSS Score: %29.49
    • Published: Sep. 15, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292518 Results