Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2016-6827

    Huawei FusionCompute before V100R005C10CP7002 stores cleartext AES keys in a file, which allows remote authenticated users to obtain sensitive information via unspecified vectors.... Read more

    • EPSS Score: %0.11
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.1

    HIGH
    CVE-2016-6826

    Huawei AnyMail before 2.6.0301.0060 allows remote attackers to cause a denial of service (application crash) via a crafted compressed email attachment.... Read more

    Affected Products : anyoffice_secureapp
    • EPSS Score: %0.19
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.1

    HIGH
    CVE-2016-6172

    PowerDNS (aka pdns) Authoritative Server before 4.0.1 allows remote primary DNS servers to cause a denial of service (memory exhaustion and secondary DNS server crash) via a large (1) AXFR or (2) IXFR response.... Read more

    Affected Products : leap opensuse authoritative_server
    • EPSS Score: %0.01
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2016-6153

    os_unix.c in SQLite before 3.13.0 improperly implements the temporary directory search algorithm, which might allow local users to obtain sensitive information, cause a denial of service (application crash), or have unspecified other impact by leveraging ... Read more

    Affected Products : fedora leap sqlite
    • EPSS Score: %0.03
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6142

    SAP HANA DB 1.00.73.00.389160 (NewDB100_REL) allows remote attackers to inject arbitrary audit trail fields into the SYSLOG via vectors related to the SQL protocol, aka SAP Security Note 2197459.... Read more

    Affected Products : hana hana_db
    • EPSS Score: %1.22
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-4972

    OpenStack Murano before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), Murano-dashboard before 1.0.3 (liberty) and 2.x before 2.0.1 (mitaka), and python-muranoclient before 0.7.3 (liberty) and 0.8.x before 0.8.5 (mitaka) improperly use loaders inherited f... Read more

    • EPSS Score: %3.93
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2016-3639

    SAP HANA DB 1.00.091.00.1418659308 allows remote attackers to obtain sensitive topology information via an unspecified HTTP request, aka SAP Security Note 2176128.... Read more

    Affected Products : hana_db
    • EPSS Score: %0.36
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-7162

    The _g_file_remove_directory function in file-utils.c in File Roller 3.5.4 through 3.20.2 allows remote attackers to delete arbitrary files via a symlink attack on a folder in an archive.... Read more

    Affected Products : ubuntu_linux file_roller
    • EPSS Score: %1.15
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2016-7142

    The m_sasl module in InspIRCd before 2.0.23, when used with a service that supports SASL_EXTERNAL authentication, allows remote attackers to spoof certificate fingerprints and consequently log in as another user via a crafted SASL message.... Read more

    Affected Products : debian_linux inspircd
    • EPSS Score: %0.14
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6518

    Memory leak in Huawei S9300, S5300, S5700, S6700, S7700, S9700, and S12700 devices allows remote attackers to cause a denial of service (memory consumption and restart) via a large number of malformed packets.... Read more

    • EPSS Score: %0.32
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 5.1

    MEDIUM
    CVE-2016-5746

    libstorage, libstorage-ng, and yast-storage improperly store passphrases for encrypted storage devices in a temporary file on disk, which might allow local users to obtain sensitive information by reading the file, as demonstrated by /tmp/libstorage-XXXXX... Read more

    • EPSS Score: %0.06
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.1

    HIGH
    CVE-2016-8279

    The video driver in Huawei Mate S smartphones with software CRR-TL00 before CRR-TL00C01B362, CRR-UL20 before CRR-UL20C00B362, CRR-CL00 before CRR-CL00C92B362, and CRR-CL20 before CRR-CL20C92B362; P8 smartphones with software GRA-TL00 before GRA-TL00C01B36... Read more

    • EPSS Score: %0.05
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 8.1

    HIGH
    CVE-2016-7098

    Race condition in wget 1.17 and earlier, when used in recursive or mirroring mode to download a single file, might allow remote servers to bypass intended access list restrictions by keeping an HTTP connection open.... Read more

    Affected Products : wget
    • EPSS Score: %3.65
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-6840

    Cross-site scripting (XSS) vulnerability in the management interface in Huawei OceanStor ISM before V200R001C04SPC200 allows remote attackers to inject arbitrary web script or HTML via the loginName parameter to cgi-bin/doLogin_CgiEntry and possibly other... Read more

    Affected Products : oceanstor_ism
    • EPSS Score: %0.15
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-6276

    Citrix Linux Virtual Delivery Agent (aka VDA, formerly Linux Virtual Desktop) before 1.4.0 allows local users to gain root privileges via unspecified vectors.... Read more

    Affected Products : linux_virtual_delivery_agent
    • EPSS Score: %0.05
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5406

    The domain controller in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2 allows remote authenticated users to gain privileges by leveraging failure to propagate administrative RBAC configuration to all slaves.... Read more

    • EPSS Score: %1.50
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 4.8

    MEDIUM
    CVE-2016-5395

    Cross-site scripting (XSS) vulnerability in the create user functionality in the policy admin tool in Apache Ranger before 0.6.1 allows remote authenticated administrators to inject arbitrary web script or HTML via vectors related to policies.... Read more

    Affected Products : ranger
    • EPSS Score: %0.13
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-4993

    CRLF injection vulnerability in the Undertow web server in WildFly 10.0.0, as used in Red Hat JBoss Enterprise Application Platform (EAP) 7.x before 7.0.2, allows remote attackers to inject arbitrary HTTP headers and conduct HTTP response splitting attack... Read more

    • EPSS Score: %0.60
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-4303

    The parse_string function in cjson.c in the cJSON library mishandles UTF8/16 strings, which allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a non-hex character in a JSON string, which triggers a heap-based buffer... Read more

    • EPSS Score: %5.76
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-3110

    mod_cluster, as used in Red Hat JBoss Web Server 2.1, allows remote attackers to cause a denial of service (Apache http server crash) via an MCMP message containing a series of = (equals) characters after a legitimate element.... Read more

    • EPSS Score: %3.22
    • Published: Sep. 26, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291641 Results