Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2015-6337

    Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CSCuw47... Read more

    • EPSS Score: %0.25
    • Published: Jan. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-2052

    Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from ... Read more

    Affected Products : chrome harfbuzz
    • EPSS Score: %0.47
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-2051

    Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    • EPSS Score: %0.30
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1620

    Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %1.43
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1619

    Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service (out-of-bounds read) o... Read more

    Affected Products : chrome
    • EPSS Score: %0.80
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-1618

    Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vect... Read more

    Affected Products : chrome
    • EPSS Score: %0.91
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1617

    The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply w... Read more

    Affected Products : chrome
    • EPSS Score: %0.64
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1616

    The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.... Read more

    Affected Products : chrome
    • EPSS Score: %1.18
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-1615

    The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %0.76
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1614

    The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive ... Read more

    Affected Products : chrome
    • EPSS Score: %0.79
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1613

    Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, rel... Read more

    Affected Products : chrome
    • EPSS Score: %0.87
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1612

    The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of servic... Read more

    Affected Products : chrome
    • EPSS Score: %1.03
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2015-7417

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.... Read more

    Affected Products : websphere_application_server
    • EPSS Score: %0.17
    • Published: Jan. 23, 2016
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-6317

    Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.... Read more

    Affected Products : identity_services_engine_software
    • EPSS Score: %0.14
    • Published: Jan. 23, 2016
    • Modified: Apr. 12, 2025
  • 8.4

    HIGH
    CVE-2016-1572

    mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.... Read more

    • EPSS Score: %0.05
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2016-1571

    The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address ... Read more

    Affected Products : xen xenserver
    • EPSS Score: %0.30
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 8.5

    HIGH
    CVE-2016-1570

    The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier... Read more

    Affected Products : xen
    • EPSS Score: %0.20
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2015-7744

    wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attacker... Read more

    Affected Products : leap mariadb opensuse wolfssl
    • EPSS Score: %3.42
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-6925

    wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.... Read more

    Affected Products : wolfssl
    • EPSS Score: %0.90
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6015

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more

    • EPSS Score: %19.92
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291520 Results