Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2016-2123

    A flaw was found in samba versions 4.0.0 to 4.5.2. The Samba routine ndr_pull_dnsp_name contains an integer wrap problem, leading to an attacker-controlled memory overwrite. ndr_pull_dnsp_name parses data from the Samba Active Directory ldb database. Any ... Read more

    Affected Products : samba
    • EPSS Score: %1.47
    • Published: Nov. 01, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2016-2121

    A permissions flaw was found in redis, which sets weak permissions on certain files and directories that could potentially contain sensitive information. A local, unprivileged user could possibly use this flaw to access unauthorized system information.... Read more

    Affected Products : openstack
    • EPSS Score: %0.07
    • Published: Oct. 31, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-2120

    An issue has been found in PowerDNS Authoritative Server versions up to and including 3.4.10, 4.0.1 allowing an authorized user to crash the server by inserting a specially crafted record in a zone under their control then sending a DNS query for that rec... Read more

    Affected Products : debian_linux authoritative recursor
    • EPSS Score: %0.13
    • Published: Nov. 01, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-2032

    A vulnerability exists in the Aruba AirWave Management Platform 8.x prior to 8.2 in the management interface of an underlying system component called RabbitMQ, which could let a malicious user obtain sensitive information. This interface listens on TCP po... Read more

    Affected Products : arubaos airwave aruba_instant
    • EPSS Score: %2.17
    • Published: Jan. 31, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-2031

    Multiple vulnerabilities exists in Aruba Instate before 4.1.3.0 and 4.2.3.1 due to insufficient validation of user-supplied input and insufficient checking of parameters, which could allow a malicious user to bypass security restrictions, obtain sensitive... Read more

    • EPSS Score: %0.97
    • Published: Jan. 31, 2020
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20018

    Knex Knex.js through 2.3.0 has a limited SQL injection vulnerability that can be exploited to ignore the WHERE clause of a SQL query.... Read more

    Affected Products : knex
    • EPSS Score: %0.25
    • Published: Dec. 19, 2022
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20014

    In pam_tacplus.c in pam_tacplus before 1.4.1, pam_sm_acct_mgmt does not zero out the arep data structure.... Read more

    Affected Products : pam_tacplus
    • EPSS Score: %0.30
    • Published: Apr. 21, 2022
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20013

    sha256crypt and sha512crypt through 0.6 allow attackers to cause a denial of service (CPU consumption) because the algorithm's runtime is proportional to the square of the length of the password.... Read more

    Affected Products : sha256crypt sha512crypt
    • EPSS Score: %0.20
    • Published: Feb. 19, 2022
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2016-20012

    OpenSSH through 8.7 allows remote attackers, who have a suspicion that a certain combination of username and public key is known to an SSH server, to test whether this suspicion is correct. This occurs because a challenge is sent only when that combinatio... Read more

    • EPSS Score: %25.27
    • Published: Sep. 15, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20011

    libgrss through 0.7.0 fails to perform TLS certificate verification when downloading feeds, allowing remote attackers to manipulate the contents of feeds without detection. This occurs because of the default behavior of SoupSessionSync.... Read more

    Affected Products : libgrss
    • EPSS Score: %0.36
    • Published: May. 25, 2021
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2016-20010

    EWWW Image Optimizer before 2.8.5 allows remote command execution because it relies on a protection mechanism involving boolval, which is unavailable before PHP 5.5.... Read more

    Affected Products : image_optimizer
    • EPSS Score: %6.83
    • Published: May. 05, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20009

    A DNS client stack-based buffer overflow in ipdnsc_decode_name() affects Wind River VxWorks 6.5 through 7. NOTE: This vulnerability only affects products that are no longer supported by the maintainer... Read more

    • EPSS Score: %0.42
    • Published: Mar. 11, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20008

    The REST/JSON project 7.x-1.x for Drupal allows session enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.32
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20007

    The REST/JSON project 7.x-1.x for Drupal allows session name guessing, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.28
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20006

    The REST/JSON project 7.x-1.x for Drupal allows blockage of user logins, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.33
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20005

    The REST/JSON project 7.x-1.x for Drupal allows user registration bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20004

    The REST/JSON project 7.x-1.x for Drupal allows field access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-20003

    The REST/JSON project 7.x-1.x for Drupal allows user enumeration, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.32
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20002

    The REST/JSON project 7.x-1.x for Drupal allows comment access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-20001

    The REST/JSON project 7.x-1.x for Drupal allows node access bypass, aka SA-CONTRIB-2016-033. NOTE: This project is not covered by Drupal's security advisory policy.... Read more

    Affected Products : rest\/json
    • EPSS Score: %0.36
    • Published: Jan. 01, 2021
    • Modified: Nov. 21, 2024
Showing 20 of 291722 Results