Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2016-3324

    Microsoft Internet Explorer 9 through 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more

    Affected Products : internet_explorer
    • EPSS Score: %17.01
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-3306

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack ... Read more

    • EPSS Score: %0.50
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-3305

    The kernel in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607 mishandles session objects, which allows local users to hijack ... Read more

    • EPSS Score: %0.54
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2016-3302

    Microsoft Windows 8.1, Windows Server 2012 R2, Windows RT 8.1, and Windows 10 Gold, 1511, and 1607, when the lock screen is enabled, do not properly restrict the loading of web content, which allows physically proximate attackers to execute arbitrary code... Read more

    • EPSS Score: %0.83
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-3297

    Microsoft Internet Explorer 9 through 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more

    Affected Products : edge internet_explorer
    • EPSS Score: %46.44
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-3295

    Microsoft Internet Explorer 10 and 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more

    Affected Products : edge internet_explorer
    • EPSS Score: %52.99
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-3294

    Microsoft Edge allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Edge Memory Corruption Vulnerability," a different vulnerability than CVE-2016-3330.... Read more

    Affected Products : edge
    • EPSS Score: %23.50
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 5.1

    MEDIUM
    CVE-2016-3292

    Microsoft Internet Explorer 10 and 11 mishandles integrity settings and zone settings, which allows remote attackers to bypass a sandbox protection mechanism via a crafted web site, aka "Internet Explorer Elevation of Privilege Vulnerability."... Read more

    Affected Products : internet_explorer
    • EPSS Score: %4.45
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 2.6

    LOW
    CVE-2016-3291

    Microsoft Internet Explorer 11 and Microsoft Edge mishandle cross-origin requests, which allows remote attackers to obtain sensitive information via a crafted web site, aka "Microsoft Browser Information Disclosure Vulnerability."... Read more

    Affected Products : edge internet_explorer
    • EPSS Score: %5.16
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-3247

    Microsoft Internet Explorer 11 and Microsoft Edge allow remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Microsoft Browser Memory Corruption Vulnerability."... Read more

    Affected Products : edge internet_explorer
    • EPSS Score: %66.98
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-0141

    The Visual Basic macros in Microsoft Office 2007 SP3, 2010 SP2, 2013 SP1, and 2016 export a certificate-store private key during a document-save operation, which allows attackers to obtain sensitive information via unspecified vectors, aka "Microsoft Info... Read more

    Affected Products : office
    • EPSS Score: %7.71
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-0138

    Microsoft Exchange Server 2007 SP3, 2010 SP3, 2013 SP1, 2013 Cumulative Update 12, 2013 Cumulative Update 13, 2016 Cumulative Update 1, and 2016 Cumulative Update 2 misparses e-mail messages, which allows remote authenticated users to obtain sensitive Out... Read more

    Affected Products : exchange_server
    • EPSS Score: %15.24
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-0137

    The Click-to-Run (C2R) implementation in Microsoft Office 2013 SP1 and 2016 allows local users to bypass the ASLR protection mechanism via a crafted application, aka "Microsoft APP-V ASLR Bypass."... Read more

    Affected Products : office
    • EPSS Score: %6.54
    • Published: Sep. 14, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-6399

    Cisco ACE30 Application Control Engine Module through A5 3.3 and ACE 4700 Application Control Engine appliances through A5 3.3 allow remote attackers to cause a denial of service (device reload) via crafted (1) SSL or (2) TLS packets, aka Bug ID CSCvb1631... Read more

    • EPSS Score: %0.74
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-6398

    The PPTP server in Cisco IOS 15.5(3)M does not properly initialize packet buffers, which allows remote attackers to obtain sensitive information from earlier network communication by reading packet data, aka Bug ID CSCvb16274.... Read more

    Affected Products : ios
    • EPSS Score: %0.27
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-6396

    Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1, when certain malware blocking options are enabled, allow remote attackers to bypass malware detection via crafted fields in HTTP headers, aka Bug ID CSCuz44482.... Read more

    Affected Products : firesight_system_software
    • EPSS Score: %0.43
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2016-6395

    Cross-site scripting (XSS) vulnerability in the web-based management interface in Cisco Firepower Management Center before 6.1 and FireSIGHT System Software before 6.1 allows remote authenticated users to inject arbitrary web script or HTML via a crafted ... Read more

    Affected Products : firesight_system_software
    • EPSS Score: %0.34
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
  • 9.1

    CRITICAL
    CVE-2016-6394

    Session fixation vulnerability in Cisco Firepower Management Center and Cisco FireSIGHT System Software through 6.1.0 allows remote attackers to hijack web sessions via a session identifier, aka Bug ID CSCuz80503.... Read more

    Affected Products : firesight_system_software
    • EPSS Score: %0.30
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6371

    Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote attackers to write to arbitrary files via a crafted URL, aka Bug ID CSCuz64717.... Read more

    • EPSS Score: %7.29
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-6370

    Directory traversal vulnerability in the web interface in Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) 10.6(3) and earlier allows remote authenticated users to read arbitrary files via a crafted pathname in an HTTP request, aka Bug ID CSCuz272... Read more

    • EPSS Score: %0.54
    • Published: Sep. 12, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291641 Results