Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.8

    HIGH
    CVE-2016-2393

    Lenovo Fingerprint Manager before 8.01.57 and Touch Fingerprint before 1.00.08 use weak ACLs for unspecified (1) services and (2) files, which allows local users to gain privileges by invalidating local checks.... Read more

    • EPSS Score: %0.04
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-2171

    The User Manager service in Apache Jetspeed before 2.3.1 does not properly restrict access using Jetspeed Security, which allows remote attackers to (1) add, (2) edit, or (3) delete users via the REST API.... Read more

    Affected Products : jetspeed
    • EPSS Score: %10.30
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-2164

    The (1) FileService.importFileByInternalUserId and (2) FileService.importFile SOAP API methods in Apache OpenMeetings before 3.1.1 improperly use the Java URL class without checking the specified protocol handler, which allows remote attackers to read arb... Read more

    Affected Products : openmeetings
    • EPSS Score: %1.23
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-2163

    Cross-site scripting (XSS) vulnerability in Apache OpenMeetings before 3.1.1 allows remote attackers to inject arbitrary web script or HTML via the event description when creating an event.... Read more

    Affected Products : openmeetings
    • EPSS Score: %2.73
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-0784

    Directory traversal vulnerability in the Import/Export System Backups functionality in Apache OpenMeetings before 3.1.1 allows remote authenticated administrators to write to arbitrary files via a .. (dot dot) in a ZIP archive entry.... Read more

    Affected Products : openmeetings
    • EPSS Score: %6.06
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-0783

    The sendHashByUser function in Apache OpenMeetings before 3.1.1 generates predictable password reset tokens, which makes it easier for remote attackers to reset arbitrary user passwords by leveraging knowledge of a user name and the current system time.... Read more

    Affected Products : openmeetings
    • EPSS Score: %1.46
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-0712

    Cross-site scripting (XSS) vulnerability in Apache Jetspeed before 2.3.1 allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO to portal.... Read more

    Affected Products : jetspeed
    • EPSS Score: %2.55
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-0711

    Multiple cross-site scripting (XSS) vulnerabilities in Apache Jetspeed before 2.3.1 allow remote attackers to inject arbitrary web script or HTML via the title parameter when adding a (1) link, (2) page, or (3) folder resource.... Read more

    Affected Products : jetspeed
    • EPSS Score: %2.55
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-0710

    Multiple SQL injection vulnerabilities in the User Manager service in Apache Jetspeed before 2.3.1 allow remote attackers to execute arbitrary SQL commands via the (1) role or (2) user parameter to services/usermanager/users/.... Read more

    Affected Products : jetspeed
    • EPSS Score: %81.16
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 9.0

    HIGH
    CVE-2016-0709

    Directory traversal vulnerability in the Import/Export function in the Portal Site Manager in Apache Jetspeed before 2.3.1 allows remote authenticated administrators to write to arbitrary files, and consequently execute arbitrary code, via a .. (dot dot) ... Read more

    Affected Products : jetspeed
    • EPSS Score: %70.16
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8240

    The Traffic Management Microkernel (TMM) in F5 BIG-IP LTM, AAM, AFM, Analytics, APM, ASM, GTM, Link Controller, and BIG-IP PEM before 11.4.1 HF10, 11.5.x before 11.5.4, and 11.6.x before 11.6.0 HF6 and BIG-IP PSM before 11.4.1 HF10 does not properly handl... Read more

    • EPSS Score: %1.20
    • Published: Apr. 11, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1033

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %3.19
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1032

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %3.19
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1031

    Use-after-free vulnerability in Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code via unspecified vectors, a different vulnerability... Read more

    • EPSS Score: %4.55
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 8.1

    HIGH
    CVE-2016-1030

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to bypass intended access restrictions via unspecified vectors.... Read more

    • EPSS Score: %1.10
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1029

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %3.19
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1028

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %3.19
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1027

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %2.37
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1026

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %2.37
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1025

    Adobe Flash Player before 18.0.0.343 and 19.x through 21.x before 21.0.0.213 on Windows and OS X and before 11.2.202.616 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a differ... Read more

    • EPSS Score: %2.37
    • Published: Apr. 09, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 292318 Results