Latest CVE Feed
-
9.0
HIGHCVE-2016-7040
Red Hat CloudForms Management Engine 4.1 does not properly handle regular expressions passed to the expression engine via the JSON API and the web-based UI, which allows remote authenticated users to execute arbitrary shell commands by leveraging the abil... Read more
Affected Products : cloudforms_management_engine- EPSS Score: %0.64
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6323
The makecontext function in the GNU C Library (aka glibc or libc6) before 2.25 creates execution contexts incompatible with the unwinder on ARM EABI (32-bit) platforms, which might allow context-dependent attackers to cause a denial of service (hang), as ... Read more
- EPSS Score: %1.13
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-6273
The lmadmin component in Flexera FlexNet Publisher (aka Flex License Manager) before 2015 SP5 and 2016 before R1 SP1, as used by Citrix License Server for Windows before 11.14.0.1 and Citrix License Server VPX before 11.14.0.1, allows remote attackers to ... Read more
- EPSS Score: %1.67
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
7.4
HIGHCVE-2016-3699
The Linux kernel, as used in Red Hat Enterprise Linux 7.2 and Red Hat Enterprise MRG 2 and when booted with UEFI Secure Boot enabled, allows local users to bypass intended Secure Boot restrictions and execute untrusted code by appending ACPI tables to the... Read more
- EPSS Score: %0.04
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2015-7363
Cross-site scripting (XSS) vulnerability in the advanced settings page in Fortinet FortiManager 5.x before 5.0.12 and 5.2.x before 5.2.3, in hardware models with a hard disk, and FortiAnalyzer 5.x before 5.0.13 and 5.2.x before 5.2.3 allows remote adminis... Read more
- EPSS Score: %0.33
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-5162
The image parser in OpenStack Cinder 7.0.2 and 8.0.0 through 8.1.1; Glance before 11.0.1 and 12.0.0; and Nova before 12.0.4 and 13.0.0 does not properly limit qemu-img calls, which might allow attackers to cause a denial of service (memory and disk consum... Read more
- EPSS Score: %3.20
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-2080
The exception handling code in Eclipse Jetty before 9.2.9.v20150224 allows remote attackers to obtain sensitive information from process memory via illegal characters in an HTTP header, aka JetLeak.... Read more
- EPSS Score: %92.09
- Published: Oct. 07, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1000217
Zotpress plugin for WordPress SQLi in zp_get_account()... Read more
- EPSS Score: %11.40
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICAL- EPSS Score: %2.25
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1000124
Unauthenticated SQL Injection in Huge-IT Portfolio Gallery Plugin v1.0.6... Read more
Affected Products : portfolio_gallery- EPSS Score: %2.27
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1000123
Unauthenticated SQL Injection in Huge-IT Video Gallery v1.0.9 for Joomla... Read more
Affected Products : video_gallery- EPSS Score: %6.45
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUM- EPSS Score: %0.23
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICAL- EPSS Score: %2.77
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.4
HIGHCVE-2016-1000112
Unauthenticated remote .jpg file upload in contus-video-comments v1.0 wordpress plugin... Read more
Affected Products : contus-video-comments- EPSS Score: %35.66
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2016-1000009
TP-LINK lost control of two domains, www.tplinklogin.net and tplinkextender.net. Please note that these domains are physically printed on many of the devices.... Read more
Affected Products : tp-link- EPSS Score: %0.27
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1000000
Ipswitch WhatsUp Gold 16.4.1 WrFreeFormText.asp sUniqueID Parameter Blind SQL Injection... Read more
- EPSS Score: %0.03
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2015-1000013
Remote file upload vulnerability in wordpress plugin csv2wpec-coupon v1.1... Read more
Affected Products : csv2wpec-coupon- EPSS Score: %6.04
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1000012
Local File Inclusion Vulnerability in mypixs v0.3 wordpress plugin... Read more
Affected Products : mypixs- EPSS Score: %68.58
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2015-1000011
Blind SQL Injection in wordpress plugin dukapress v2.5.9... Read more
- EPSS Score: %6.01
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025
-
7.5
HIGHCVE-2015-1000010
Remote file download in simple-image-manipulator v1.0 wordpress plugin... Read more
Affected Products : simple-image-manipulator- EPSS Score: %31.97
- Published: Oct. 06, 2016
- Modified: Apr. 12, 2025