Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.0

    HIGH
    CVE-2012-6613

    D-Link DSR-250N devices with firmware 1.05B73_WW allow Persistent Root Access because of the admin password for the admin account.... Read more

    Affected Products : dsr-250n_firmware dsr-250n
    • EPSS Score: %0.98
    • Published: Jan. 25, 2020
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2012-6611

    An issue was discovered in Polycom Web Management Interface G3/HDX 8000 HD with Durango 2.6.0 4740 software and embedded Polycom Linux Development Platform 2.14.g3. It has a blank administrative password by default, and can be successfully used without se... Read more

    • EPSS Score: %1.01
    • Published: Feb. 10, 2020
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2012-6610

    Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote authenticated users to execute arbitrary commands as demonstrated by a ; (semicolon) to the ping command feature.... Read more

    Affected Products : hdx_video_end_points uc_apl hdx_8000
    • EPSS Score: %2.23
    • Published: Jan. 28, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-6609

    Directory traversal vulnerability in a_getlog.cgi in Polycom HDX Video End Points before 3.0.4 and UC APL before 2.7.1.J allows remote attackers to read arbitrary files via a .. (dot dot) in the name parameter.... Read more

    Affected Products : hdx_video_end_points uc_apl hdx_8000
    • EPSS Score: %0.41
    • Published: Jan. 28, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6494

    Rapid7 Nexpose before 5.5.4 contains a session hijacking vulnerability which allows remote attackers to capture a user's session and gain unauthorized access.... Read more

    Affected Products : nexpose
    • EPSS Score: %0.53
    • Published: Jan. 25, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-6451

    Lorex LNC116 and LNC104 IP Cameras have a Remote Authentication Bypass Vulnerability... Read more

    • EPSS Score: %1.80
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2012-6449

    The clientconf.html and detailbw.html pages in x3 in cPanel & WHM 11.34.0 (build 8) have a XSS vulnerability.... Read more

    Affected Products : cpanel whm
    • EPSS Score: %0.18
    • Published: Feb. 10, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6448

    Cross-site Scripting (XSS) in cPanel WebHost Manager (WHM) 11.34.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : webhost_manager
    • EPSS Score: %0.26
    • Published: Jan. 27, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6347

    Multiple cross-site scripting (XSS) vulnerabilities in Java number format exception handling in FortiGate FortiDB before 4.4.2 allow remote attackers to inject arbitrary web script or HTML via the conversationContext parameter to (1) admin/auditTrail.jsf,... Read more

    Affected Products : fortidb
    • EPSS Score: %0.23
    • Published: Feb. 09, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6346

    Multiple cross-site scripting (XSS) vulnerabilities in FortiWeb before 4.4.4 allow remote attackers to inject arbitrary web script or HTML via the (1) redir or (2) mkey parameter to waf/pcre_expression/validate.... Read more

    Affected Products : fortiweb
    • EPSS Score: %0.26
    • Published: Feb. 09, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-6345

    Novell ZENworks Configuration Management before 11.2.4 allows obtaining sensitive trace information.... Read more

    Affected Products : zenworks_configuration_management
    • EPSS Score: %0.51
    • Published: Jan. 25, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2012-6344

    Novell ZENworks Configuration Management before 11.2.4 allows XSS.... Read more

    Affected Products : zenworks_configuration_management
    • EPSS Score: %0.23
    • Published: Jan. 25, 2020
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2012-6341

    An Information Disclosure vulnerability exists in the my config file in NEtGEAR WGR614 v7 and v9, which could let a malicious user recover all previously used passwords on the device, for both the control panel and WEP/WPA/WPA2, in plaintext. This is a di... Read more

    • EPSS Score: %0.47
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 4.6

    MEDIUM
    CVE-2012-6340

    An Authentication vulnerability exists in NETGEAR WGR614 v7 and v9 due to a hardcoded credential used for serial programming, a related issue to CVE-2006-1002.... Read more

    • EPSS Score: %0.24
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2012-6309

    A vulnerability exists in Arctic Torrent 1.4 via unspecified vectors in .torrent file handling, which could let a malicious user cause a Denial of Service.... Read more

    Affected Products : arctic_torrent
    • EPSS Score: %0.33
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2012-6307

    A vulnerability exists in JPEGsnoop 1.5.2 due to an unspecified issue in JPEG file handling, which could let a malicious user execute arbitrary code... Read more

    Affected Products : jpegsnoop
    • EPSS Score: %4.35
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2012-6306

    A vulnerability exists in HCView (aka Hardcoreview) 1.4 due to a write access violation with a GIF file.... Read more

    Affected Products : hcview
    • EPSS Score: %0.43
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2012-6302

    Soapbox through 0.3.1: Sandbox bypass - runs a second instance of Soapbox within a sandboxed Soapbox.... Read more

    Affected Products : soapbox
    • EPSS Score: %0.04
    • Published: Jan. 24, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2012-6297

    Command Injection vulnerability exists via a CSRF in DD-WRT 24-sp2 from specially crafted configuration values containing shell meta-characters, which could let a remote malicious user cause a Denial of Service.... Read more

    Affected Products : dd-wrt
    • EPSS Score: %0.65
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2012-6277

    Multiple unspecified vulnerabilities in Autonomy KeyView IDOL before 10.16, as used in Symantec Mail Security for Microsoft Exchange before 6.5.8, Symantec Mail Security for Domino before 8.1.1, Symantec Messaging Gateway before 10.0.1, Symantec Data Loss... Read more

    • EPSS Score: %3.25
    • Published: Feb. 21, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 291647 Results