Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.0

    MEDIUM
    CVE-2016-4707

    CFNetwork in Apple iOS before 10 and OS X before 10.12 mishandles Local Storage deletion, which allows local users to discover the visited web sites of arbitrary users via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os
    • EPSS Score: %0.06
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 5.5

    MEDIUM
    CVE-2016-4706

    cd9660 in Apple OS X before 10.12 allows local users to cause a denial of service via unspecified vectors.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.14
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-4703

    Bluetooth in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.36
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-4702

    Audio in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors.... Read more

    Affected Products : mac_os_x iphone_os tvos watchos
    • EPSS Score: %14.12
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 6.2

    MEDIUM
    CVE-2016-4701

    Application Firewall in Apple OS X before 10.12 allows local users to cause a denial of service via vectors involving a crafted SO_EXECPATH environment variable.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.14
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-4700

    AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4699.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.36
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-4699

    AppleUUC in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app, a different vulnerability than CVE-2016-4700.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.23
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-4698

    AppleMobileFileIntegrity in Apple iOS before 10 and OS X before 10.12 mishandles process entitlement and Team ID values in the task port inheritance policy, which allows attackers to execute arbitrary code in a privileged context via a crafted app.... Read more

    Affected Products : mac_os_x iphone_os
    • EPSS Score: %0.24
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-4697

    Apple HSSPI Support in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.22
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-4696

    AppleEFIRuntime in Apple OS X before 10.12 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (NULL pointer dereference) via a crafted app.... Read more

    Affected Products : mac_os_x mac_os_x
    • EPSS Score: %0.22
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.1

    CRITICAL
    CVE-2016-4694

    The Apache HTTP Server in Apple OS X before 10.12 and OS X Server before 5.2 follows RFC 3875 section 4.1.18 and therefore does not protect applications from the presence of untrusted CGI client data in the HTTP_PROXY environment variable, which might all... Read more

    Affected Products : mac_os_x os_x_server
    • EPSS Score: %0.96
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-4658

    xpointer.c in libxml2 before 2.9.5 (as used in Apple iOS before 10, OS X before 10.12, tvOS before 10, and watchOS before 3, and other products) does not forbid namespace nodes in XPointer ranges, which allows remote attackers to execute arbitrary code or... Read more

    • EPSS Score: %19.34
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-4618

    Cross-site scripting (XSS) vulnerability in Safari Reader in Apple iOS before 10 and Safari before 10 allows remote attackers to inject arbitrary web script or HTML via a crafted web site, aka "Universal XSS (UXSS)."... Read more

    Affected Products : iphone_os safari
    • EPSS Score: %0.50
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-4611

    WebKit in Apple iOS before 10, Safari before 10, and tvOS before 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, a different vulnerability than CVE-2016-4730, CVE-2016-4733, CVE... Read more

    Affected Products : iphone_os tvos safari
    • EPSS Score: %0.92
    • Published: Sep. 25, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-6532

    DEXIS Imaging Suite 10 has a hardcoded password for the sa account, which allows remote attackers to obtain administrative access by entering this password in a DEXIS_DATA SQL Server session.... Read more

    Affected Products : imaging_suite
    • EPSS Score: %0.73
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-6531

    Open Dental 16.1 and earlier has a hardcoded MySQL root password, which allows remote attackers to obtain administrative access by leveraging access to intranet TCP port 3306. NOTE: the vendor disputes this issue, stating that the "vulnerability note ...... Read more

    Affected Products : opendental
    • EPSS Score: %3.27
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5793

    Unquoted Windows search path vulnerability in Moxa Active OPC Server before 2.4.19 allows local users to gain privileges via a Trojan horse executable file in the %SYSTEMDRIVE% directory.... Read more

    Affected Products : active_opc_server
    • EPSS Score: %0.05
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-4845

    Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the au... Read more

    • EPSS Score: %5.58
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-0918

    EMC RSA Identity Management and Governance before 6.8.1 P25 and 6.9.x before 6.9.1 P15 and RSA Via Lifecycle and Governance before 7.0.0 P04 allow remote authenticated users to obtain User Detail Popup information via a modified URL.... Read more

    • EPSS Score: %0.17
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-6413

    The installation procedure on Cisco Application Policy Infrastructure Controller (APIC) devices 1.3(2f) mishandles binary files, which allows local users to obtain root access via unspecified vectors, aka Bug ID CSCva50496.... Read more

    • EPSS Score: %0.08
    • Published: Sep. 24, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291712 Results