Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    CRITICAL
    CVE-2016-20010

    EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.... Read more

    Affected Products : image_optimizer
    • EPSS Score: %6.83
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20009

    A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more

    • EPSS Score: %0.42
    • Published: Mar. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20008

    The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.32
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20007

    The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.28
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20006

    The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.33
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20005

    The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20004

    The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20003

    The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.32
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20002

    The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20001

    The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-1600

    The ServiceNow driver in NetIQ Identity Manager versions prior to 4.6 are susceptible to an information disclosure vulnerability.... Read more

    Affected Products : identity_manager identity_manager
    • EPSS Score: %0.32
    • Published: May. 09, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-1587

    The Snapweb interface before version 0.21.2 was exposing controls to install or remove snap packages without controlling the identity of the user, nor the origin of the connection. An attacker could have used the controls to remotely add a valid, but mali... Read more

    Affected Products : snapweb
    • EPSS Score: %0.28
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-1586

    A malicious webview could install long-lived unload handlers that re-use an incognito BrowserContext that is queued for destruction in versions of Oxide before 1.18.3.... Read more

    Affected Products : oxide
    • EPSS Score: %0.18
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2016-1584

    In all versions of Unity8 a running but not active application on a large-screen device could talk with Maliit and consume keyboard input.... Read more

    Affected Products : unity8
    • EPSS Score: %0.24
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1579

    UDM provides support for running commands after a download is completed, this is currently made use of for click package installation. This functionality was not restricted to unconfined applications. Before UDM version 1.2+16.04.20160408-0ubuntu1 any con... Read more

    Affected Products : ubuntu_download_manager
    • EPSS Score: %0.20
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2016-1573

    Versions of Unity8 before 8.11+16.04.20160122-0ubuntu1 file plugins/Dash/CardCreator.js will execute any code found in place of a fallback image supplied by a scope.... Read more

    Affected Products : unity8 unity8
    • EPSS Score: %0.09
    • Published: Apr. 22, 2019
    • Modified: Nov. 21, 2024
  • 3.3

    LOW
    CVE-2016-1544

    nghttp2 before 1.7.1 allows remote attackers to cause a denial of service (memory exhaustion).... Read more

    Affected Products : fedora nghttp2
    • EPSS Score: %2.12
    • Published: Feb. 06, 2020
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-1487

    Lexmark Markvision Enterprise before 2.3.0 misuses the Apache Commons Collections Library, leading to remote code execution because of Java deserialization.... Read more

    Affected Products : markvision_enterprise
    • EPSS Score: %0.86
    • Published: Mar. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1239

    duck before 0.10 did not properly handle loading of untrusted code from the current directory.... Read more

    Affected Products : duck
    • EPSS Score: %0.61
    • Published: Feb. 19, 2022
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2016-1203

    Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may... Read more

    Affected Products : windows netizen netizen_installer
    • EPSS Score: %1.64
    • Published: Oct. 31, 2023
    • Modified: Nov. 21, 2024
Showing 20 of 291672 Results