Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2015-5946

    Incomplete blacklist vulnerability in SuiteCRM 7.2.2 allows remote authenticated users to execute arbitrary code by uploading a file with an executable extension.... Read more

    Affected Products : sugarcrm suitecrm
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2015-5244

    The NSSCipherSuite option with ciphersuites enabled in mod_nss before 1.0.12 allows remote attackers to bypass application restrictions.... Read more

    Affected Products : mod_nss
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2014-9831

    coders/wpg.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted wpg file.... Read more

    Affected Products : imagemagick
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2014-9830

    coders/sun.c in ImageMagick allows remote attackers to have unspecified impact via a corrupted sun file.... Read more

    Affected Products : imagemagick
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2014-9828

    coders/psd.c in ImageMagick allows remote attackers to have unspecified impact via a crafted psd file.... Read more

    Affected Products : imagemagick
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2014-9827

    coders/xpm.c in ImageMagick allows remote attackers to have unspecified impact via a crafted xpm file.... Read more

    Affected Products : imagemagick
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2014-3462

    The ".encfs6.xml" configuration file in encfs before 1.7.5 allows remote attackers to access sensitive data by setting "blockMACBytes" to 0 and adding 8 to "blockMACRandBytes".... Read more

    Affected Products : leap opensuse encfs
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2014-1235

    Stack-based buffer overflow in the "yyerror" function in Graphviz 2.34.0 allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a crafted file. NOTE: This vulnerability exists due to an incomplete fix for C... Read more

    Affected Products : graphviz
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-12654

    The ReadPICTImage function in coders/pict.c in ImageMagick 7.0.6-3 allows attackers to cause a denial of service (memory leak) via a crafted file.... Read more

    Affected Products : imagemagick
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 7.8

    HIGH
    CVE-2017-12653

    360 Total Security 9.0.0.1202 before 2017-07-07 allows Privilege Escalation via a Trojan horse Shcore.dll file in any directory in the PATH, as demonstrated by the C:\Python27 directory.... Read more

    Affected Products : 360_total_security
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-12651

    Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.... Read more

    Affected Products : loginizer
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-12650

    SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.... Read more

    Affected Products : loginizer
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 5.5

    MEDIUM
    CVE-2015-8621

    t-coffee before 11.00.8cbe486-2 allows local users to write to ~/.t_coffee globally.... Read more

    Affected Products : t-coffee
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.1

    HIGH
    CVE-2015-7887

    NetApp SnapCenter Server 1.0 allows remote authenticated users to list and delete backups.... Read more

    Affected Products : snapcenter_server
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2015-7875

    ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.... Read more

    Affected Products : ctools
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 3.5

    LOW
    CVE-2015-7561

    Kubernetes in OpenShift3 allows remote authenticated users to use the private images of other users should they know the name of said image.... Read more

    Affected Products : openshift kubernetes
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 5.5

    MEDIUM
    CVE-2015-3839

    The updateMessageStatus function in Android 5.1.1 and earlier allows local users to cause a denial of service (NULL pointer exception and process crash).... Read more

    Affected Products : android
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 9.1

    CRITICAL
    CVE-2015-1555

    Zend/Session/SessionManager in Zend Framework 2.2.x before 2.2.9, 2.3.x before 2.3.4 allows remote attackers to create valid sessions without using session validators.... Read more

    Affected Products : zend_framework
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2015-1378

    cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users.... Read more

    Affected Products : grml-debootstrap
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
  • 8.2

    HIGH
    CVE-2014-9262

    The Duplicator plugin in Wordpress before 0.5.10 allows remote authenticated users to create and download backup files.... Read more

    Affected Products : duplicator
    • Published: Aug. 07, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 294846 Results