Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.0

    HIGH
    CVE-2016-7070

    A privilege escalation flaw was found in the Ansible Tower. When Tower before 3.0.3 deploys a PostgreSQL database, it incorrectly configures the trust level of postgres user. An attacker could use this vulnerability to gain admin level access to the datab... Read more

    Affected Products : ansible_tower
    • Published: Sep. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-7069

    An issue has been found in dnsdist before 1.2.0 in the way EDNS0 OPT records are handled when parsing responses from a backend. When dnsdist is configured to add EDNS Client Subnet to a query, the response may contain an EDNS0 OPT record that has to be re... Read more

    Affected Products : dnsdist
    • Published: Sep. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2016-7068

    An issue has been found in PowerDNS before 3.4.11 and 4.0.2, and PowerDNS recursor before 3.7.4 and 4.0.4, allowing a remote, unauthenticated attacker to cause an abnormal CPU usage load on the PowerDNS server by sending crafted DNS queries, which might r... Read more

    Affected Products : debian_linux authoritative recursor
    • Published: Sep. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-7067

    Monit before version 5.20.0 is vulnerable to a cross site request forgery attack. Successful exploitation will enable an attacker to disable/enable all monitoring for a particular host or disable/enable monitoring for a specific service.... Read more

    Affected Products : monit
    • Published: Sep. 10, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2016-7066

    It was found that the improper default permissions on /tmp/auth directory in JBoss Enterprise Application Platform before 7.1.0 can allow any local user to connect to CLI and allow the user to execute any arbitrary operations.... Read more

    • Published: Sep. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2016-7064

    A flaw was found in pritunl-client before version 1.0.1116.6. A lack of signature verification leads to sensitive information leakage... Read more

    Affected Products : pritunl-client
    • Published: Jul. 21, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-7063

    A flaw was found in pritunl-client before version 1.0.1116.6. Arbitrary write to user specified path may lead to privilege escalation.... Read more

    Affected Products : pritunl-client
    • Published: Jul. 21, 2020
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2016-7061

    An information disclosure vulnerability was found in JBoss Enterprise Application Platform before 7.0.4. It was discovered that when configuring RBAC and marking information as sensitive, users with a Monitor role are able to view the sensitive informatio... Read more

    • Published: Sep. 10, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2016-7056

    A timing attack flaw was found in OpenSSL 1.0.1u and before that could allow a malicious user with local access to recover ECDSA P-256 private keys.... Read more

    • Published: Sep. 10, 2018
    • Modified: Nov. 21, 2024
  • 9.3

    HIGH
    CVE-2016-7048

    The interactive installer in PostgreSQL before 9.3.15, 9.4.x before 9.4.10, and 9.5.x before 9.5.5 might allow remote attackers to execute arbitrary code by leveraging use of HTTP to download software.... Read more

    Affected Products : postgresql
    • Published: Aug. 20, 2018
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2016-7047

    A flaw was found in the CloudForms API before 5.6.3.0, 5.7.3.1 and 5.8.1.2. A user with permissions to use the MiqReportResults capability within the API could potentially view data from other tenants or groups to which they should not have access.... Read more

    • Published: Sep. 11, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-7043

    It has been reported that KIE server and Busitess Central before version 7.21.0.Final contain username and password as plaintext Java properties. Any app deployed on the same server would have access to these properties, thus granting access to ther servi... Read more

    Affected Products : kie-server
    • Published: May. 15, 2019
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2016-7041

    Drools Workbench contains a path traversal vulnerability. The vulnerability allows a remote, authenticated attacker to bypass the directory restrictions and retrieve arbitrary files from the affected host.... Read more

    Affected Products : jboss_brms jboss_drools
    • Published: Sep. 10, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-7035

    An authorization flaw was found in Pacemaker before 1.1.16, where it did not properly guard its IPC interface. An attacker with an unprivileged account on a Pacemaker node could use this flaw to, for example, force the Local Resource Manager daemon to exe... Read more

    • Published: Sep. 10, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    CRITICAL
    CVE-2016-6918

    Lexmark Markvision Enterprise (MVE) before 2.4.1 allows remote attackers to execute arbitrary commands by uploading files. (... Read more

    Affected Products : markvision_enterprise
    • Published: Mar. 09, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-6814

    When an application with unsupported Codehaus versions of Groovy from 1.7.0 to 2.4.3, Apache Groovy 2.4.4 to 2.4.7 on classpath uses standard Java serialization mechanisms, e.g. to communicate between servers or to store local data, it was possible for an... Read more

    Affected Products : enterprise_linux_server groovy
    • Published: Jan. 18, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-6813

    Apache CloudStack 4.1 to 4.8.1.0 and 4.9.0.0 contain an API call designed to allow a user to register for the developer API. If a malicious user is able to determine the ID of another (non-"root") CloudStack user, the malicious user may be able to reset t... Read more

    Affected Products : cloudstack
    • Published: Feb. 06, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-6810

    In Apache ActiveMQ 5.x before 5.14.2, an instance of a cross-site scripting vulnerability was identified to be present in the web based administration console. The root cause of this issue is improper user data output validation.... Read more

    Affected Products : activemq
    • Published: Jan. 10, 2018
    • Modified: Nov. 21, 2024
  • 9.6

    CRITICAL
    CVE-2016-6658

    Applications in cf-release before 245 can be configured and pushed with a user-provided custom buildpack using a URL pointing to the buildpack. Although it is not recommended, a user can specify a credential in the URL (basic auth or OAuth) to access the ... Read more

    • Published: Mar. 29, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-6599

    BMC Track-It! 11.4 before Hotfix 3 exposes an unauthenticated .NET remoting configuration service (ConfigurationService) on port 9010. This service contains a method that can be used to retrieve a configuration file that contains the application database ... Read more

    Affected Products : track-it\!
    • Published: Jan. 30, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 292826 Results