Latest CVE Feed
-
8.6
HIGHCVE-2016-8361
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.... Read more
Affected Products : jenesys_bas_bridge- EPSS Score: %0.38
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7782
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the src parameter.... Read more
Affected Products : exponent_cms- EPSS Score: %0.59
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-9726
IBM QRadar Incident Forensics 7.2 could allow a remote authenticated attacker to execute arbitrary commands on the system. By sending a specially-crafted request, an attacker could exploit this vulnerability to execute arbitrary commands on the system. IB... Read more
- EPSS Score: %1.45
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4296
When opening a Hangul Hcell Document (.cell) and processing a record that uses the CSSValFormat object, Hancom Office 2014 will search for an underscore ("_") character at the end of the string and write a null terminator after it. If the character is at ... Read more
Affected Products : hancom_office_2014- EPSS Score: %0.46
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8406
An information disclosure vulnerability in kernel components including the ION subsystem, Binder, USB driver and networking subsystem could enable a local malicious application to access data outside of its permission levels. This issue is rated as Modera... Read more
- EPSS Score: %0.15
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2010-5327
Liferay Portal through 6.2.10 allows remote authenticated users to execute arbitrary shell commands via a crafted Velocity template.... Read more
Affected Products : liferay_portal- EPSS Score: %1.51
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8432
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- EPSS Score: %0.24
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-8298
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Product / Instrument Search). Supported versions that are affected are 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.39
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10070
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Maintenance Folders). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker ... Read more
Affected Products : peoplesoft_enterprise_prtl_interaction_hub- EPSS Score: %0.46
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8385
An exploitable uninitialized variable vulnerability which leads to a stack-based buffer overflow exists in Iceni Argus. When it attempts to convert a malformed PDF to XML a stack variable will be left uninitialized which will later be used to fetch a leng... Read more
Affected Products : argus- EPSS Score: %0.95
- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-3657
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated lower-level administrators to gain "Super Admin" privileges via unspecified vectors.... Read more
Affected Products : clearpass- EPSS Score: %0.76
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-10014
Vulnerability in the Oracle Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite8/RESTAPI). The supported version that is affected is 1.1. Easily exploitable vulnerability allows low privileged attacker with network a... Read more
Affected Products : hospitality_hotel_mobile- EPSS Score: %0.24
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3454
TelescopeJS before 0.15 leaks user bcrypt password hashes in websocket messages, which might allow remote attackers to obtain password hashes via a cross-site scripting attack.... Read more
Affected Products : vulcan- EPSS Score: %1.76
- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000374
A flaw exists in NetBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using certain setuid binaries. This affects NetBSD 7.1 and possibly earlier versions.... Read more
Affected Products : netbsd- EPSS Score: %2.72
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000375
NetBSD maps the run-time link-editor ld.so directly below the stack region, even if ASLR is enabled, this allows attackers to more easily manipulate memory leading to arbitrary code execution. This affects NetBSD 7.1 and possibly earlier versions.... Read more
Affected Products : netbsd- EPSS Score: %38.41
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-3314
SQL injection vulnerability in WordPress Tune Library plugin before 1.5.5.... Read more
Affected Products : tune_library- EPSS Score: %8.76
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-3296
Multiple cross-site scripting (XSS) vulnerabilities in NodeBB before 0.7 allow remote attackers to inject arbitrary web script or HTML via vectors related to (1) javascript: or (2) data: URLs.... Read more
Affected Products : nodebb- EPSS Score: %0.34
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-6501
Open redirect vulnerability in the Console in Puppet Enterprise before 2015.2.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via the string parameter.... Read more
Affected Products : puppet_enterprise- EPSS Score: %0.19
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-6585
hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag.... Read more
Affected Products : hangul_word_processor- EPSS Score: %1.81
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-9337
An issue was discovered in Tesla Motors Model S automobile, all firmware versions before version 7.1 (2.36.31) with web browser functionality enabled. The vehicle's Gateway ECU is susceptible to commands that may allow an attacker to install malicious sof... Read more
Affected Products : gateway_ecu- EPSS Score: %0.95
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025