Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2016-6345

    RESTEasy allows remote authenticated users to obtain sensitive information by leveraging "insufficient use of random values" in async jobs.... Read more

    Affected Products : resteasy
    • EPSS Score: %0.15
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-6344

    Red Hat JBoss BPM Suite 6.3.x does not include the HTTPOnly flag in a Set-Cookie header for session cookies, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.... Read more

    Affected Products : jboss_bpm_suite
    • EPSS Score: %0.46
    • Published: Sep. 07, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-7153

    The HTTP/2 protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party c... Read more

    • EPSS Score: %3.92
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-7152

    The HTTPS protocol does not consider the role of the TCP congestion window in providing information about content length, which makes it easier for remote attackers to obtain cleartext data by leveraging a web-browser configuration in which third-party co... Read more

    • EPSS Score: %3.92
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 9.0

    HIGH
    CVE-2016-7114

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more

    • EPSS Score: %0.42
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-7113

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more

    • EPSS Score: %0.43
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-7112

    A vulnerability has been identified in Firmware variant PROFINET IO for EN100 Ethernet module : All versions < V1.04.01; Firmware variant Modbus TCP for EN100 Ethernet module : All versions < V1.11.00; Firmware variant DNP3 TCP for EN100 Ethernet module :... Read more

    • EPSS Score: %0.52
    • Published: Sep. 06, 2016
    • Modified: Apr. 12, 2025
  • 8.1

    HIGH
    CVE-2016-6377

    Media Origination System Suite Software 2.6 and earlier in Cisco Virtual Media Packager (VMP) allows remote attackers to bypass authentication and make arbitrary Platform and Applications Manager (PAM) API calls via unspecified vectors, aka Bug ID CSCuz52... Read more

    Affected Products : media_origination_system_suite
    • EPSS Score: %0.34
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-5430

    The RSA 1.5 algorithm implementation in the JOSE_JWE class in JWE.php in jose-php before 2.2.1 lacks the Random Filling protection mechanism, which makes it easier for remote attackers to obtain cleartext data via a Million Message Attack (MMA).... Read more

    Affected Products : jose-php
    • EPSS Score: %0.53
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-5429

    jose-php before 2.2.1 does not use constant-time operations for HMAC comparison, which makes it easier for remote attackers to obtain sensitive information via a timing attack, related to JWE.php and JWS.php.... Read more

    Affected Products : jose-php
    • EPSS Score: %0.32
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1464

    Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to execute arbitrary code via a crafted file, aka Bug ID CSCva09375.... Read more

    Affected Products : webex_meetings webex_wrf_player_t29
    • EPSS Score: %4.48
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 5.5

    MEDIUM
    CVE-2016-1415

    Cisco WebEx Meetings Player T29.10, when WRF file support is enabled, allows remote attackers to cause a denial of service (application crash) via a crafted file, aka Bug ID CSCuz80455.... Read more

    Affected Products : webex_meetings webex_wrf_player_t29
    • EPSS Score: %4.09
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2015-5721

    Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.... Read more

    • EPSS Score: %0.86
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2015-5720

    Multiple cross-site scripting (XSS) vulnerabilities in the template-creation feature in Malware Information Sharing Platform (MISP) before 2.3.90 allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) add.ctp, (2) edit.ctp... Read more

    • EPSS Score: %0.25
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-5719

    app/Controller/TemplatesController.php in Malware Information Sharing Platform (MISP) before 2.3.92 does not properly restrict filenames under the tmp/files/ directory, which has unspecified impact and attack vectors.... Read more

    • EPSS Score: %0.43
    • Published: Sep. 03, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-7123

    Cross-site request forgery (CSRF) vulnerability in the admin web interface in GNU Mailman before 2.1.15 allows remote attackers to hijack the authentication of administrators.... Read more

    Affected Products : mailman
    • EPSS Score: %0.22
    • Published: Sep. 02, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-6893

    Cross-site request forgery (CSRF) vulnerability in the user options page in GNU Mailman 2.1.x before 2.1.23 allows remote attackers to hijack the authentication of arbitrary users for requests that modify an option, as demonstrated by gaining access to th... Read more

    Affected Products : mailman
    • EPSS Score: %0.44
    • Published: Sep. 02, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-5879

    MQCLI on IBM MQ Appliance M2000 and M2001 devices allows local users to execute arbitrary shell commands via a crafted (1) Disaster Recovery or (2) High Availability command.... Read more

    • EPSS Score: %0.04
    • Published: Sep. 02, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-5699

    CRLF injection vulnerability in the HTTPConnection.putheader function in urllib2 and urllib in CPython (aka Python) before 2.7.10 and 3.x before 3.4.4 allows remote attackers to inject arbitrary HTTP headers via CRLF sequences in a URL.... Read more

    Affected Products : python
    • EPSS Score: %10.84
    • Published: Sep. 02, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-5636

    Integer overflow in the get_data function in zipimport.c in CPython (aka Python) before 2.7.12, 3.x before 3.4.5, and 3.5.x before 3.5.2 allows remote attackers to have unspecified impact via a negative data size value, which triggers a heap-based buffer ... Read more

    Affected Products : python
    • EPSS Score: %66.94
    • Published: Sep. 02, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291570 Results