Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2016-4427

    In zulip before 1.3.12, deactivated users could access messages if SSO was enabled.... Read more

    Affected Products : zulip
    • EPSS Score: %0.26
    • Published: Jul. 28, 2022
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2016-4426

    In zulip before 1.3.12, bot API keys were accessible to other users in the same realm.... Read more

    Affected Products : zulip
    • EPSS Score: %0.15
    • Published: Jul. 28, 2022
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-4406

    A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.... Read more

    • EPSS Score: %0.54
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-4405

    A remote code execution vulnerability was identified in HP Business Service Management (BSM) using Apache Commons Collection Java Deserialization versions v9.20-v9.26... Read more

    Affected Products : business_service_management
    • EPSS Score: %20.31
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-4404

    A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via a memory allocation issue.... Read more

    Affected Products : keyview
    • EPSS Score: %12.00
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-4403

    A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via memory corruption.... Read more

    Affected Products : keyview
    • EPSS Score: %12.00
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-4402

    A security vulnerability was identified in the Filter SDK component of HP KeyView earlier than v11.2. The vulnerability could be exploited remotely to allow code execution via buffer overflow.... Read more

    Affected Products : keyview
    • EPSS Score: %12.80
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2016-4401

    Aruba ClearPass Policy Manager before 6.5.7 and 6.6.x before 6.6.2 allows attackers to obtain database credentials.... Read more

    Affected Products : clearpass
    • EPSS Score: %0.47
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-4400

    A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).... Read more

    Affected Products : network_node_manager_i
    • EPSS Score: %0.31
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-4399

    A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).... Read more

    Affected Products : network_node_manager_i
    • EPSS Score: %0.27
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-4398

    A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.... Read more

    Affected Products : network_node_manager_i
    • EPSS Score: %20.31
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2016-4397

    A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.... Read more

    Affected Products : network_node_manager_i
    • EPSS Score: %0.23
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2016-4392

    A remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.... Read more

    Affected Products : business_service_management
    • EPSS Score: %0.27
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-4391

    A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.... Read more

    Affected Products : arcsight_winc_connector
    • EPSS Score: %41.61
    • Published: Aug. 06, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2016-4289

    A stack based buffer overflow vulnerability exists in the method receiving data from SysTreeView32 control of the GMER 2.1.19357 application. A specially created long path can lead to a buffer overflow on the stack resulting in code execution. An attacker... Read more

    Affected Products : gmer
    • EPSS Score: %0.13
    • Published: Oct. 29, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-3957

    The secure_load function in gluon/utils.py in web2py before 2.14.2 uses pickle.loads to deserialize session information stored in cookies, which might allow remote attackers to execute arbitrary code by leveraging knowledge of encryption_key.... Read more

    Affected Products : web2py
    • EPSS Score: %12.74
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2016-3954

    web2py before 2.14.2 allows remote attackers to obtain the session_cookie_key value via a direct request to examples/simple_examples/status. NOTE: this issue can be leveraged by remote attackers to execute arbitrary code using CVE-2016-3957.... Read more

    Affected Products : web2py
    • EPSS Score: %0.39
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-3953

    The sample web application in web2py before 2.14.2 might allow remote attackers to execute arbitrary code via vectors involving use of a hardcoded encryption key when calling the session.connect function.... Read more

    Affected Products : web2py
    • EPSS Score: %1.51
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2016-3952

    web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify. NOTE: this issue can be leveraged by remote attackers to gain administrati... Read more

    Affected Products : web2py
    • EPSS Score: %0.40
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2016-3735

    Piwigo is image gallery software written in PHP. When a criteria is not met on a host, piwigo defaults to usingmt_rand in order to generate password reset tokens. mt_rand output can be predicted after recovering the seed used to generate it. This low an u... Read more

    Affected Products : piwigo
    • EPSS Score: %1.44
    • Published: Jan. 28, 2022
    • Modified: Nov. 21, 2024
Showing 20 of 291722 Results