Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2016-2298

    Meteocontrol WEB'log Basic 100, Light, Pro, and Pro Unlimited allows remote attackers to obtain sensitive cleartext information via unspecified vectors.... Read more

    • Published: May. 14, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2275

    The web interface on Advantech/B+B SmartWorx VESP211-EU devices with firmware 1.7.2 and VESP211-232 devices with firmware 1.5.1 and 1.7.2 relies on the client to implement access control, which allows remote attackers to perform administrative actions via... Read more

    • Published: Feb. 21, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2230

    OpenELEC and RasPlex devices have a hardcoded password for the root account, which makes it easier for remote attackers to obtain access via an SSH session.... Read more

    Affected Products : openelec
    • Published: Feb. 08, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2207

    The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SE... Read more

    • Published: Jun. 30, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2196

    Heap-based buffer overflow in the P-521 reduction function in Botan 1.11.x before 1.11.27 allows remote attackers to cause a denial of service (memory overwrite and crash) or execute arbitrary code via unspecified vectors.... Read more

    Affected Products : botan
    • Published: May. 13, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2245

    HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors.... Read more

    Affected Products : support_assistant
    • Published: Mar. 19, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2071

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.... Read more

    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1984

    The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerabil... Read more

    Affected Products : amx_firmware
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    CRITICAL
    CVE-2016-20010

    EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.... Read more

    Affected Products : image_optimizer
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-1995

    HPE System Management Homepage before 7.5.4 allows remote attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : system_management_homepage
    • Published: Mar. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    CRITICAL
    CVE-2016-1985

    HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.... Read more

    Affected Products : windows operations_manager
    • Published: Jan. 30, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1999

    The server in HP Release Control 9.13, 9.20, and 9.21 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.... Read more

    Affected Products : release_control
    • Published: May. 30, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1906

    Openshift allows remote attackers to gain privileges by updating a build configuration that was created with an allowed type to a type that is not allowed.... Read more

    Affected Products : kubernetes origin
    • Published: Feb. 03, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1909

    Fortinet FortiAnalyzer before 5.0.12 and 5.2.x before 5.2.5; FortiSwitch 3.3.x before 3.3.3; FortiCache 3.0.x before 3.0.8; and FortiOS 4.1.x before 4.1.11, 4.2.x before 4.2.16, 4.3.x before 4.3.17 and 5.0.x before 5.0.8 have a hardcoded passphrase for th... Read more

    Affected Products : fortios
    • Published: Jan. 15, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1989

    HPE Network Automation 9.22 through 9.22.02 and 10.x before 10.00.02 allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors, a different vulnerability than CVE-2016-1988.... Read more

    Affected Products : network_automation
    • Published: Mar. 15, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2022-31800

    An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.... Read more

    • Published: Jun. 21, 2022
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-1662

    extensions/renderer/gc_callback.cc in Google Chrome before 50.0.2661.94 does not prevent fallback execution once the Garbage Collection callback has started, which allows remote attackers to cause a denial of service (use-after-free) or possibly have unsp... Read more

    • Published: May. 14, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1642

    Multiple unspecified vulnerabilities in Google Chrome before 49.0.2623.75 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    Affected Products : chrome
    • Published: Mar. 06, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1629

    Google Chrome before 48.0.2564.116 allows remote attackers to bypass the Blink Same Origin Policy and a sandbox protection mechanism via unspecified vectors.... Read more

    • Published: Feb. 21, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1560

    ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or ... Read more

    • Published: Apr. 21, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 292795 Results