Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.0

    HIGH
    CVE-2016-6184

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges ... Read more

    Affected Products : honor_4c_firmware honor_4c
    • EPSS Score: %0.05
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 7.0

    HIGH
    CVE-2016-6183

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges ... Read more

    Affected Products : honor_4c_firmware honor_4c
    • EPSS Score: %0.05
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-6182

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges ... Read more

    Affected Products : honor_4c_firmware honor_4c
    • EPSS Score: %0.10
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 7.0

    HIGH
    CVE-2016-6181

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges ... Read more

    Affected Products : honor_4c_firmware honor_4c
    • EPSS Score: %0.05
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 7.0

    HIGH
    CVE-2016-6180

    The Camera driver in Huawei Honor 4C smartphones with software CHM-UL00C00 before CHM-UL00C00B564, CHM-TL00C01 before CHM-TL00C01B564, and CHM-TL00C00 before CHM-TL00HC00B564 allows attackers to cause a denial of service (system crash) or gain privileges ... Read more

    Affected Products : honor_4c_firmware honor_4c
    • EPSS Score: %0.05
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5422

    The web console in Red Hat JBoss Operations Network (JON) before 3.3.7 does not properly authorize requests to add users with the super user role, which allows remote authenticated users to gain admin privileges via a crafted POST request.... Read more

    Affected Products : jboss_operations_network
    • EPSS Score: %0.68
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-5022

    F5 BIG-IP LTM, Analytics, APM, ASM, and Link Controller 11.2.x before 11.2.1 HF16, 11.3.x, 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.6.1 HF1, and 12.x before 12.0.0 HF3; BIG-IP AAM, AFM, and PEM 11.4.x, 11.5.x before 11.5.4 HF2, 11.6.x before 11.... Read more

    • EPSS Score: %1.30
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 4.4

    MEDIUM
    CVE-2016-1242

    file_open in Tryton before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allows remote authenticated users with certain permissions to read arbitrary files via the name parameter or unspecified other vectors.... Read more

    Affected Products : trytond tryton
    • EPSS Score: %0.21
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-1241

    Tryton 3.x before 3.2.17, 3.4.x before 3.4.14, 3.6.x before 3.6.12, 3.8.x before 3.8.8, and 4.x before 4.0.4 allow remote authenticated users to discover user password hashes via unspecified vectors.... Read more

    Affected Products : trytond tryton
    • EPSS Score: %0.24
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-7034

    The dashbuilder in Red Hat JBoss BPM Suite 6.3.2 does not properly handle CSRF tokens generated during an active session and includes them in query strings, which makes easier for remote attackers to (1) bypass CSRF protection mechanisms or (2) conduct cr... Read more

    Affected Products : jboss_bpm_suite
    • EPSS Score: %0.04
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-7033

    Multiple cross-site scripting (XSS) vulnerabilities in the admin pages in dashbuilder in Red Hat JBoss BPM Suite 6.3.2 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : jboss_bpm_suite
    • EPSS Score: %0.35
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6855

    Eye of GNOME (aka eog) 3.16.5, 3.17.x, 3.18.x before 3.18.3, 3.19.x, and 3.20.x before 3.20.4, when used with glib before 2.44.1, allow remote attackers to cause a denial of service (out-of-bounds write and crash) via vectors involving passing invalid UTF... Read more

    • EPSS Score: %2.55
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2016-6351

    The esp_do_dma function in hw/scsi/esp.c in QEMU (aka Quick Emulator), when built with ESP/NCR53C9x controller emulation support, allows local guest OS administrators to cause a denial of service (out-of-bounds write and QEMU process crash) or execute arb... Read more

    Affected Products : ubuntu_linux debian_linux qemu
    • EPSS Score: %0.24
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-6346

    RESTEasy enables GZIPInterceptor, which allows remote attackers to cause a denial of service via unspecified vectors.... Read more

    Affected Products : resteasy
    • EPSS Score: %2.02
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-6345

    RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.... Read more

    Affected Products : resteasy
    • EPSS Score: %0.15
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-6344

    Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.... Read more

    Affected Products : jboss_bpm_suite
    • EPSS Score: %0.46
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-7153

    The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party c... Read more

    • EPSS Score: %3.92
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-7152

    The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party co... Read more

    • EPSS Score: %3.92
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.0

    HIGH
    CVE-2016-7114

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more

    • EPSS Score: %0.42
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-7113

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more

    • EPSS Score: %0.43
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291564 Results