Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2016-10387

    In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.... Read more

    Affected Products : android
    • EPSS Score: %0.25
    • Published: Aug. 18, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-1553

    IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more

    Affected Products : infosphere_biginsights
    • EPSS Score: %0.27
    • Published: Nov. 01, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2016-10184

    An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.... Read more

    Affected Products : dwr-932b_firmware dwr-932b
    • EPSS Score: %28.77
    • Published: Jan. 30, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2016-10180

    An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.... Read more

    Affected Products : dwr-932b_firmware dwr-932b
    • EPSS Score: %10.92
    • Published: Jan. 30, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2016-10137

    An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of com.adups.fota.sysoper allows any app on the device to read, write, and de... Read more

    Affected Products : adups_fota
    • EPSS Score: %0.05
    • Published: Jan. 13, 2017
    • Modified: Apr. 20, 2025
  • 5.5

    MEDIUM
    CVE-2016-10135

    An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5.0, and BLU R1 HD devices. The MTKLogger app with a package name of com.mediatek.mtklogger has application... Read more

    Affected Products : lg_mobile
    • EPSS Score: %0.30
    • Published: Jan. 13, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-15375

    Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, ... Read more

    Affected Products : wpjobboard
    • EPSS Score: %0.20
    • Published: Oct. 16, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2016-10123

    Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.... Read more

    Affected Products : firejail
    • EPSS Score: %0.04
    • Published: Apr. 13, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2017-15368

    The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers a... Read more

    Affected Products : radare2
    • EPSS Score: %0.24
    • Published: Oct. 16, 2017
    • Modified: Apr. 20, 2025
  • 10.0

    HIGH
    CVE-2017-15366

    Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to g... Read more

    Affected Products : ndoc
    • EPSS Score: %0.28
    • Published: Oct. 26, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2016-10091

    Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function.... Read more

    Affected Products : unrtf
    • EPSS Score: %2.61
    • Published: Apr. 21, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-15304

    /bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin passwo... Read more

    Affected Products : hdmi_dongle_firmware hdmi_dongle
    • EPSS Score: %0.34
    • Published: Oct. 15, 2017
    • Modified: Apr. 20, 2025
  • 4.3

    MEDIUM
    CVE-2017-15205

    In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user.... Read more

    Affected Products : kanboard
    • EPSS Score: %0.29
    • Published: Oct. 11, 2017
    • Modified: Apr. 20, 2025
  • 4.3

    MEDIUM
    CVE-2017-15195

    In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.... Read more

    Affected Products : kanboard
    • EPSS Score: %0.49
    • Published: Oct. 11, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-14985

    Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.php.... Read more

    Affected Products : eyesofnetwork
    • EPSS Score: %0.15
    • Published: Oct. 03, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2015-3639

    phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file.... Read more

    Affected Products : phpmybackuppro
    • EPSS Score: %1.37
    • Published: Jul. 21, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2015-3617

    Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.... Read more

    Affected Products : fortimanager_firmware
    • EPSS Score: %0.16
    • Published: Aug. 22, 2017
    • Modified: Apr. 20, 2025
  • 4.3

    MEDIUM
    CVE-2017-1481

    IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.... Read more

    Affected Products : sterling_b2b_integrator
    • EPSS Score: %0.18
    • Published: Dec. 07, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2015-3421

    The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure atta... Read more

    Affected Products : eshop
    • EPSS Score: %0.17
    • Published: Jul. 21, 2017
    • Modified: Apr. 20, 2025
  • 9.3

    HIGH
    CVE-2017-14705

    DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication paramete... Read more

    Affected Products : i-suite web_application_firewall
    • EPSS Score: %4.64
    • Published: Sep. 22, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 291564 Results