Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2015-8620

    Heap-based buffer overflow in the Avast virtualization driver (aswSnx.sys) in Avast Internet Security, Pro Antivirus, Premier, and Free Antivirus before 11.1.2253 allows local users to gain privileges via a Unicode file path in an IOCTL request.... Read more

    • EPSS Score: %0.09
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2015-8304

    Integer overflow in Huawei P7 phones with software before P7-L07 V100R001C01B606 allows remote attackers to gain privileges via a crafted application with the system or camera permission.... Read more

    Affected Products : p7_firmware p7
    • EPSS Score: %0.14
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2014-9766

    Integer overflow in the create_bits function in pixman-bits-image.c in Pixman before 0.32.6 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via large height and stride values.... Read more

    Affected Products : ubuntu_linux pixman
    • EPSS Score: %10.74
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-6276

    schema.py in Roundup before 1.5.1 does not properly limit attributes included in default user permissions, which might allow remote authenticated users to obtain sensitive user information by viewing user details.... Read more

    Affected Products : debian_linux roundup
    • EPSS Score: %0.13
    • Published: Apr. 13, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-2118

    The MS-SAMR and MS-LSAD protocol implementations in Samba 3.x and 4.x before 4.2.11, 4.3.x before 4.3.8, and 4.4.x before 4.4.2 mishandle DCERPC connections, which allows man-in-the-middle attackers to perform protocol-downgrade attacks and impersonate us... Read more

    Affected Products : ubuntu_linux debian_linux samba
    • EPSS Score: %78.65
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.4

    HIGH
    CVE-2016-2001

    HPE Universal CMDB Foundation 10.0, 10.01, 10.10, 10.11, and 10.20 allows remote attackers to obtain sensitive information or conduct URL redirection attacks via unspecified vectors.... Read more

    Affected Products : universal_cmbd_foundation
    • EPSS Score: %0.50
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-1377

    Cross-site scripting (XSS) vulnerability in Cisco Unity Connection through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug ID CSCus21776.... Read more

    Affected Products : unity_connection
    • EPSS Score: %0.25
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-1376

    Cisco IOS XR 4.2.3, 4.3.0, 4.3.4, and 5.3.1 on ASR 9000 devices allows remote attackers to cause a denial of service (CRC and symbol errors, and interface flap) via crafted bit patterns in packets, aka Bug ID CSCuv78548.... Read more

    Affected Products : ios_xr
    • EPSS Score: %0.48
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-1035

    Adobe RoboHelp Server 9 before 9.0.1 mishandles SQL queries, which allows attackers to obtain sensitive information via unspecified vectors.... Read more

    Affected Products : robohelp_server robohelp
    • EPSS Score: %3.39
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 9.4

    HIGH
    CVE-2016-1034

    The Sync Process in the JavaScript API for Creative Cloud Libraries in Adobe Creative Cloud Desktop Application before 3.6.0.244 allows remote attackers to read or write to arbitrary files via unspecified vectors.... Read more

    Affected Products : creative_cloud
    • EPSS Score: %1.44
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2016-0887

    EMC RSA BSAFE Micro Edition Suite (MES) 4.0.x and 4.1.x before 4.1.5, RSA BSAFE Crypto-C Micro Edition (CCME) 4.0.x and 4.1.x before 4.1.3, RSA BSAFE Crypto-J before 6.2.1, RSA BSAFE SSL-J before 6.2.1, and RSA BSAFE SSL-C before 2.8.9 allow remote attack... Read more

    • EPSS Score: %0.94
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-0167

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applic... Read more

    • Actively Exploited
    • EPSS Score: %2.02
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-0166

    Microsoft Internet Explorer 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more

    Affected Products : internet_explorer
    • EPSS Score: %12.64
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-0165

    The kernel-mode driver in Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows 10 Gold and 1511 allows local users to gain privileges via a crafted applic... Read more

    • Actively Exploited
    • EPSS Score: %11.62
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-0164

    Microsoft Internet Explorer 10 and 11 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more

    Affected Products : internet_explorer
    • EPSS Score: %16.25
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-0162

    Microsoft Internet Explorer 9 through 11 allows remote attackers to determine the existence of files via crafted JavaScript code, aka "Internet Explorer Information Disclosure Vulnerability."... Read more

    • Actively Exploited
    • EPSS Score: %20.72
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-0161

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0158.... Read more

    Affected Products : edge
    • EPSS Score: %23.98
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2016-0160

    Microsoft Internet Explorer 11 mishandles DLL loading, which allows local users to gain privileges via a crafted application, aka "DLL Loading Remote Code Execution Vulnerability."... Read more

    Affected Products : internet_explorer
    • EPSS Score: %2.21
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-0159

    Microsoft Internet Explorer 9 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability."... Read more

    Affected Products : internet_explorer
    • EPSS Score: %12.64
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-0158

    Microsoft Edge allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Microsoft Edge Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0161.... Read more

    Affected Products : edge
    • EPSS Score: %18.90
    • Published: Apr. 12, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 292316 Results