Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2016-10007

    SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.... Read more

    Affected Products : dotcms
    • Published: Feb. 19, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000282

    Haraka version 2.8.8 and earlier comes with a plugin for processing attachments for zip files. Versions 2.8.8 and earlier can be vulnerable to command injection.... Read more

    Affected Products : haraka
    • Published: Feb. 05, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000271

    Joomla extension DT Register version before 3.1.12 (Joomla 3.x) / 2.8.18 (Joomla 2.5) contains an SQL injection in "/index.php?controller=calendar&format=raw&cat[0]=SQLi&task=events". This attack appears to be exploitable if the attacker can reach the web... Read more

    Affected Products : dt_register
    • Published: Feb. 04, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-1000237

    sanitize-html before 1.4.3 has XSS.... Read more

    Affected Products : sanitize-html
    • Published: Jan. 23, 2020
    • Modified: Nov. 21, 2024
  • 4.4

    MEDIUM
    CVE-2016-1000236

    Node-cookie-signature before 1.0.6 is affected by a timing attack due to the type of comparison used.... Read more

    Affected Products : debian_linux cookie-signature
    • Published: Nov. 19, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2016-1000232

    NodeJS Tough-Cookie version 2.2.2 contains a Regular Expression Parsing vulnerability in HTTP request Cookie Header parsing that can result in Denial of Service. This attack appear to be exploitable via Custom HTTP header passed by client. This vulnerabil... Read more

    • Published: Sep. 05, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-1000229

    swagger-ui has XSS in key names... Read more

    Affected Products : openshift jboss_fuse swagger-ui
    • Published: Dec. 20, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-1000110

    The CGIHandler class in Python before 2.7.12 does not protect against the HTTP_PROXY variable name clash in a CGI script, which could allow a remote attacker to redirect HTTP requests.... Read more

    Affected Products : fedora debian_linux python
    • Published: Nov. 27, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2016-1000109

    HHVM does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect ... Read more

    Affected Products : hhvm
    • Published: Feb. 19, 2020
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-1000108

    yaws before 2.0.4 does not attempt to address RFC 3875 section 4.1.18 namespace conflicts and therefore does not protect CGI applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers... Read more

    Affected Products : debian_linux yaws
    • Published: Dec. 10, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-1000107

    inets in Erlang possibly 22.1 and earlier follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted client data in the HTTP_PROXY environment variable, which might allow remote attackers to redirect an appl... Read more

    Affected Products : erlang\/otp
    • Published: Dec. 10, 2019
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2016-1000104

    A security Bypass vulnerability exists in the FcgidPassHeader Proxy in mod_fcgid through 2016-07-07.... Read more

    Affected Products : leap opensuse mod_fcgid
    • Published: Dec. 03, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2016-1000037

    Pagure: XSS possible in file attachment endpoint... Read more

    Affected Products : enterprise_linux fedora pagure
    • Published: Nov. 06, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000030

    Pidgin version <2.11.0 contains a vulnerability in X.509 Certificates imports specifically due to improper check of return values from gnutls_x509_crt_init() and gnutls_x509_crt_import() that can result in code execution. This attack appear to be exploita... Read more

    Affected Products : linux_enterprise_server pidgin
    • Published: Sep. 05, 2018
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2016-1000029

    Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would potentially impact other admins (Tenable IDs 5218 and 5269).... Read more

    Affected Products : nessus
    • Published: Dec. 27, 2019
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2016-1000028

    Tenable Nessus before 6.8 has a stored XSS issue that requires admin-level authentication to the Nessus UI, and would only potentially impact other admins. (Tenable ID 5198).... Read more

    Affected Products : nessus
    • Published: Dec. 27, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000027

    Pivotal Spring Framework through 5.3.16 suffers from a potential remote code execution (RCE) issue if used for Java deserialization of untrusted data. Depending on how the library is implemented within a product, this issue may or not occur, and authentic... Read more

    Affected Products : spring_framework
    • Published: Jan. 02, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000006

    hhvm before 3.12.11 has a use-after-free in the serialize_memoize_param() and ResourceBundle::__construct() functions.... Read more

    Affected Products : hhvm
    • Published: Nov. 19, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000005

    mcrypt_get_block_size did not enforce that the provided "module" parameter was a string, leading to type confusion if other types of data were passed in. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), ... Read more

    Affected Products : hhvm
    • Published: Feb. 19, 2020
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2016-1000004

    Insufficient type checks were employed prior to casting input data in SimpleXMLElement_exportNode and simplexml_import_dom. This issue affects HHVM versions prior to 3.9.5, all versions between 3.10.0 and 3.12.3 (inclusive), and all versions between 3.13.... Read more

    Affected Products : hhvm
    • Published: Feb. 19, 2020
    • Modified: Nov. 21, 2024
Showing 20 of 292811 Results