Latest CVE Feed
-
5.9
MEDIUMCVE-2015-2943
Honda Moto LINC 1.6.1 does not verify SSL certificates.... Read more
Affected Products : moto_linc- EPSS Score: %0.30
- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2822
An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400. A specifically crafted PDF can cause a function call on a corrupted DCTStream to occur, resulting in user controlle... Read more
Affected Products : perceptive_document_filters- EPSS Score: %0.64
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-2975
IBM Sametime 8.5.2 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : sametime- EPSS Score: %0.27
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-2972
IBM Sametime Meeting Server 8.5.2 and 9.0 could store credentials of the Sametime Meetings user in the local cache of their browser which could be accessed by a local user. IBM X-Force ID: 113855.... Read more
Affected Products : sametime- EPSS Score: %0.06
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-2971
IBM Sametime Media Services 8.5.2 and 9.0 can disclose sensitive information in stack trace error logs that could aid an attacker in future attacks. IBM X-Force ID: 113898.... Read more
Affected Products : sametime- EPSS Score: %0.25
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0765
Multiple cross-site scripting (XSS) vulnerabilities in eshop-orders.php in the eShop plugin 6.3.14 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page or (2) action parameter.... Read more
Affected Products : eshop_plugin- EPSS Score: %0.30
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0398
An information disclosure vulnerability in Audioserver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data without permission. Produc... Read more
Affected Products : android- EPSS Score: %0.07
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3151
Directory traversal vulnerability in the wallpaper parsing functionality in Barco ClickShare CSC-1 devices with firmware before 01.09.03, CSM-1 devices with firmware before 01.06.02, and CSE-200 devices with firmware before 01.03.02 allows remote attacker... Read more
- EPSS Score: %0.99
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8398
Unauthenticated messages processed by the UE. Certain NAS messages are processed when no EPS security context exists in the UE. Product: Android. Versions: Kernel 3.18. Android ID: A-31548486. References: QC-CR#877705.... Read more
- EPSS Score: %0.63
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8480
An elevation of privilege vulnerability in the Qualcomm Secure Execution Environment Communicator driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first re... Read more
- EPSS Score: %0.14
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8420
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.14
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2016-6092
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 stores user credentials in plain in clear text which can be read by a local user.... Read more
- EPSS Score: %0.05
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2016-8942
IBM Tivoli Storage Productivity Center could allow an authenticated user with intimate knowledge of the system to edit a limited set of properties on the server.... Read more
- EPSS Score: %0.12
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6030
IBM Jazz Foundation is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.23
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2016-0394
IBM Integration Bus and WebSphere Message broker sets incorrect permissions for an object that could allow a local attacker to manipulate certain files.... Read more
- EPSS Score: %0.05
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6604
NULL pointer dereference in Samsung Exynos fimg2d driver for Android L(5.0/5.1) and M(6.0) allows attackers to have unspecified impact via unknown vectors. The Samsung ID is SVE-2016-6382.... Read more
- EPSS Score: %0.55
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6077
ping.cgi on NETGEAR DGN2200 devices with firmware through 10.0.0.50 allows remote authenticated users to execute arbitrary OS commands via shell metacharacters in the ping_IPAddr field of an HTTP POST request.... Read more
- Actively Exploited
- EPSS Score: %87.65
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5585
OpenText Documentum Content Server (formerly EMC Documentum Content Server) 7.3, when PostgreSQL Database is used and return_top_results_row_based config option is false, does not properly restrict DQL hints, which allows remote authenticated users to con... Read more
Affected Products : documentum_content_server- EPSS Score: %1.04
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-9684
The SonicWall Secure Remote Access server (version 8.1.0.2-14sv) is vulnerable to a Remote Command Injection vulnerability in its web administrative interface. This vulnerability occurs in the 'viewcert' CGI (/cgi-bin/viewcert) component responsible for p... Read more
Affected Products : sonicwall_secure_remote_access_server- EPSS Score: %13.52
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3837
An HTTP Packet Processing vulnerability in the Web Bridge interface of the Cisco Meeting Server (CMS), formerly Acano Conferencing Server, could allow an authenticated, remote attacker to retrieve memory contents, which could lead to the disclosure of con... Read more
Affected Products : meeting_server- EPSS Score: %0.79
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025