Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2009-3721

    Multiple directory traversal and buffer overflow vulnerabilities were discovered in yTNEF, and in Evolution's TNEF parser that is derived from yTNEF. A crafted email could cause these applications to write data in arbitrary locations on the filesystem, cr... Read more

    Affected Products : evolution ytnef
    • EPSS Score: %0.78
    • Published: May. 26, 2021
    • Modified: Nov. 21, 2024
  • 3.3

    LOW
    CVE-2009-3614

    liboping 1.3.2 allows users reading arbitrary files upon the local system.... Read more

    Affected Products : debian_linux liboping
    • EPSS Score: %0.12
    • Published: Nov. 09, 2019
    • Modified: Nov. 21, 2024
  • 3.1

    LOW
    CVE-2009-3552

    In RHEV-M VDC 2.2.0, it was found that the SSL certificate was not verified when using the client-side Red Hat Enterprise Virtualization Manager interface (a Windows Presentation Foundation (WPF) XAML browser application) to connect to the Red Hat Enterpr... Read more

    Affected Products : enterprise_virtualization_manager
    • EPSS Score: %0.19
    • Published: Nov. 09, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-2802

    MantisBT 1.2.x before 1.2.2 insecurely handles attachments and MIME types. Arbitrary inline attachment rendering could lead to cross-domain scripting or other browser attacks.... Read more

    Affected Products : mantisbt
    • EPSS Score: %0.45
    • Published: Nov. 09, 2019
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2009-20001

    An issue was discovered in MantisBT before 2.24.5. It associates a unique cookie string with each user. This string is not reset upon logout (i.e., the user session is still considered valid and active), allowing an attacker who somehow gained access to a... Read more

    Affected Products : mantisbt
    • EPSS Score: %0.14
    • Published: Mar. 07, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2009-1120

    EMC RepliStor Server Service before ESA-09-003 has a DoASOCommand Remote Code Execution Vulnerability. The flaw exists within the DoRcvRpcCall RPC function -exposed via the rep_srv.exe process- where the vulnerability is caused by an error when the rep_sr... Read more

    Affected Products : emc_replistor
    • EPSS Score: %6.10
    • Published: Jan. 15, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-10004

    A vulnerability was found in Turante Sandbox Theme up to 1.5.2. It has been classified as problematic. This affects the function sandbox_body_class of the file functions.php. The manipulation of the argument page leads to cross site scripting. It is possi... Read more

    Affected Products : sandbox_theme
    • EPSS Score: %0.06
    • Published: Apr. 10, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-10003

    A vulnerability was found in capnsquarepants wordcraft up to 0.6. It has been classified as problematic. Affected is an unknown function of the file tag.php. The manipulation of the argument tag leads to cross site scripting. It is possible to launch the ... Read more

    Affected Products : wordcraft
    • EPSS Score: %0.06
    • Published: Jan. 29, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-10002

    A vulnerability, which was classified as problematic, has been found in dpup fittr-flickr. This issue affects some unknown processing of the file fittr-flickr/features/easy-exif.js of the component EXIF Preview Handler. The manipulation leads to cross sit... Read more

    Affected Products : fittr_flickr
    • EPSS Score: %0.06
    • Published: Jan. 13, 2023
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2009-10001

    A vulnerability classified as problematic was found in jianlinwei cool-php-captcha up to 0.2. This vulnerability affects unknown code of the file example-form.php. The manipulation of the argument captcha with the input %3Cscript%3Ealert(1)%3C/script%3E l... Read more

    Affected Products : cool-php-captcha
    • EPSS Score: %0.08
    • Published: Jan. 13, 2023
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2009-0948

    Multiple buffer overflows in the (1) cdf_read_sat, (2) cdf_read_long_sector_chain, and (3) cdf_read_ssat function in file before 5.02.... Read more

    Affected Products : files
    • EPSS Score: %0.42
    • Published: Jun. 02, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2009-0947

    Multiple integer overflows in the (1) cdf_read_property_info and (2) cdf_read_sat functions in file before 5.02.... Read more

    Affected Products : files
    • EPSS Score: %0.39
    • Published: Jun. 02, 2021
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2009-0035

    alsa-utils 1.0.19 and later versions allows local users to overwrite arbitrary files via a symlink attack via the /usr/bin/alsa-info and /usr/bin/alsa-info.sh scripts.... Read more

    Affected Products : alsa
    • EPSS Score: %0.18
    • Published: Nov. 09, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2008-7321

    The tubepress plugin before 1.6.5 for WordPress has XSS.... Read more

    Affected Products : tubepress
    • EPSS Score: %0.19
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2008-7320

    GNOME Seahorse through 3.30 allows physically proximate attackers to read plaintext passwords by using the quickAllow dialog at an unattended workstation, if the keyring is unlocked. NOTE: this is disputed by a software maintainer because the behavior rep... Read more

    Affected Products : seahorse
    • EPSS Score: %0.08
    • Published: Nov. 18, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2008-7314

    mIRC before 6.35 allows attackers to cause a denial of service (crash) via a long nickname.... Read more

    Affected Products : mirc
    • EPSS Score: %0.41
    • Published: Jan. 23, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2008-7291

    gri before 2.12.18 generates temporary files in an insecure way.... Read more

    Affected Products : debian_linux gri
    • EPSS Score: %0.43
    • Published: Nov. 08, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2008-7273

    A symlink issue exists in Iceweasel-firegpg before 0.6 due to insecure tempfile handling.... Read more

    Affected Products : iceweasel-firegpg
    • EPSS Score: %0.20
    • Published: Nov. 18, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2008-7272

    FireGPG before 0.6 handle user’s passphrase and decrypted cleartext insecurely by writing pre-encrypted cleartext and the user's passphrase to disk which may result in the compromise of secure communication or a users’s private key.... Read more

    Affected Products : firegpg
    • EPSS Score: %0.22
    • Published: Nov. 08, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2008-5083

    In JON 2.1.x before 2.1.2 SP1, users can obtain unauthorized security information about private resources managed by JBoss ON.... Read more

    Affected Products : jboss_operations_network
    • EPSS Score: %0.33
    • Published: Nov. 08, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 291389 Results