Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    MEDIUM
    CVE-2014-9951

    In TrustZone in all Android releases from CAF using the Linux kernel, an Information Exposure Through Timing Discrepancy vulnerability could potentially exist.... Read more

    Affected Products : android
    • EPSS Score: %0.06
    • Published: Jun. 06, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2014-9929

    In WCDMA in all Android releases from CAF using the Linux kernel, a Use of Out-of-range Pointer Offset vulnerability could potentially exist.... Read more

    Affected Products : android
    • EPSS Score: %0.04
    • Published: Jun. 06, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-8838

    XSS via syncid exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The affected script is cgi-bin/HASync/hasync.cgi.... Read more

    • EPSS Score: %2.05
    • Published: Jun. 05, 2017
    • Modified: Apr. 20, 2025
  • 5.5

    MEDIUM
    CVE-2017-3740

    In Lenovo Active Protection System before 1.82.0.14, an attacker with local privileges could send commands to the system's embedded controller, which could cause a denial of service attack on the system or the ability to alter hardware functionality.... Read more

    Affected Products : active_protection_system
    • EPSS Score: %0.04
    • Published: Jun. 04, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2016-8231

    In Lenovo Service Bridge before version 4, a bug found in the signature verification logic of the code signing certificate could be exploited by an attacker to insert a forged code signing certificate.... Read more

    Affected Products : lenovo_service_bridge
    • EPSS Score: %0.10
    • Published: Jun. 04, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2016-8228

    In Lenovo Service Bridge before version 4, a user with local privileges on a system could execute code with administrative privileges.... Read more

    Affected Products : lenovo_service_bridge
    • EPSS Score: %0.04
    • Published: Jun. 04, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-9380

    OpenEMR 5.0.0 and prior allows low-privilege users to upload files of dangerous types which can result in arbitrary code execution within the context of the vulnerable application.... Read more

    Affected Products : openemr
    • EPSS Score: %0.55
    • Published: Jun. 02, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-9378

    BigTree CMS through 4.2.18 does not prevent a user from deleting their own account. This could have security relevance because deletion was supposed to be an admin-only action, and the admin may have other tasks (such as data backups) to complete before a... Read more

    Affected Products : bigtree_cms
    • EPSS Score: %0.12
    • Published: Jun. 02, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-9361

    WebsiteBaker v2.10.0 has a stored XSS vulnerability in /account/details.php.... Read more

    Affected Products : websitebaker
    • EPSS Score: %0.24
    • Published: Jun. 02, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-9307

    SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.... Read more

    Affected Products : allen_disk allendisk
    • EPSS Score: %0.19
    • Published: May. 31, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-9297

    Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.... Read more

    Affected Products : device_manager
    • EPSS Score: %0.19
    • Published: May. 29, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-9033

    Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted request to SProt... Read more

    Affected Products : serverprotect
    • EPSS Score: %0.13
    • Published: May. 26, 2017
    • Modified: Apr. 20, 2025
  • 7.4

    HIGH
    CVE-2017-9035

    Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.... Read more

    Affected Products : serverprotect
    • EPSS Score: %0.68
    • Published: May. 26, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-7439

    NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.... Read more

    • EPSS Score: %0.30
    • Published: May. 26, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-5868

    CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters i... Read more

    Affected Products : openvpn_access_server
    • EPSS Score: %5.51
    • Published: May. 26, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2016-4977

    When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via... Read more

    • EPSS Score: %94.09
    • Published: May. 25, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2016-0780

    It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attack... Read more

    • EPSS Score: %0.39
    • Published: May. 25, 2017
    • Modified: Apr. 20, 2025
  • 8.3

    HIGH
    CVE-2017-2799

    An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can sen... Read more

    Affected Products : marklogic
    • EPSS Score: %0.61
    • Published: May. 24, 2017
    • Modified: Apr. 20, 2025
  • 4.9

    MEDIUM
    CVE-2017-5966

    Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.... Read more

    Affected Products : crm
    • EPSS Score: %0.27
    • Published: May. 23, 2017
    • Modified: Apr. 20, 2025
  • 8.3

    HIGH
    CVE-2017-8914

    sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.... Read more

    Affected Products : hana_xs
    • EPSS Score: %0.49
    • Published: May. 23, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 292727 Results