Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.3

    HIGH
    CVE-2016-0068

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.... Read more

    Affected Products : internet_explorer
    • EPSS Score: %35.00
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 9.1

    CRITICAL
    CVE-2015-8151

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.... Read more

    Affected Products : encryption_management_server
    • EPSS Score: %1.63
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-8150

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows local users to obtain root access by modifying a batch file.... Read more

    Affected Products : encryption_management_server
    • EPSS Score: %0.18
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8149

    The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to cause a denial of service (heap memory corruption and service outage) via crafted requests.... Read more

    Affected Products : encryption_management_server
    • EPSS Score: %1.16
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8148

    The LDAP service in Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote attackers to obtain sensitive information about administrator accounts via a modified request.... Read more

    Affected Products : encryption_management_server
    • EPSS Score: %0.44
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2015-5970

    The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity reference.... Read more

    Affected Products : zenworks_configuration_management
    • EPSS Score: %0.52
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-0795

    LibreOffice before 5.0.5 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LwpTocSuperLayout record in a LotusWordPro (lwp) document.... Read more

    Affected Products : ubuntu_linux libreoffice
    • EPSS Score: %0.55
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-0794

    The lwp filter in LibreOffice before 5.0.4 allows remote attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted LotusWordPro (lwp) document.... Read more

    Affected Products : ubuntu_linux libreoffice
    • EPSS Score: %0.48
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 8.1

    HIGH
    CVE-2015-7547

    Multiple stack-based buffer overflows in the (1) send_dg and (2) send_vc functions in the libresolv library in the GNU C Library (aka glibc or libc6) before 2.23 allow remote attackers to cause a denial of service (crash) or possibly execute arbitrary cod... Read more

    • EPSS Score: %91.80
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2015-8287

    Swann SRNVW-470LCD devices with firmware through 0114 and SWNVW-470CAM devices with firmware through 1022 allow remote attackers to watch live video by visiting an unspecified URL.... Read more

    • EPSS Score: %0.28
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-8286

    Zhuhai RaySharp firmware has a hardcoded root password, which makes it easier for remote attackers to obtain access via a session on TCP port 23 or 9000.... Read more

    Affected Products : raysharp_firmware
    • EPSS Score: %21.12
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-2398

    Comcast XFINITY Home Security System does not properly maintain base-station communication, which allows physically proximate attackers to defeat sensor functionality by interfering with ZigBee 2.4 GHz transmissions.... Read more

    Affected Products : xfinity_home_security_system
    • EPSS Score: %0.10
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-1334

    Cisco Small Business 500 Wireless Access Point devices with firmware 1.0.4.4 allow remote attackers to set the system time via a crafted POST request, aka Bug ID CSCuy01457.... Read more

    • EPSS Score: %0.24
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2016-1333

    Cisco IOS 15.5(3)M and 15.6(1)T0a on Cisco 1000 Connected Grid routers allows remote authenticated users to cause a denial of service (device reload) via an SNMP request for unspecified BRIDGE MIB OIDs, aka Bug ID CSCux89878.... Read more

    Affected Products : ios
    • EPSS Score: %0.45
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2397

    The cliserver implementation in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote attackers to deserialize and execute arbitrary Java code via crafted XML data.... Read more

    • EPSS Score: %5.04
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 9.9

    CRITICAL
    CVE-2016-2396

    The GMS ViewPoint (GMSVP) web application in Dell SonicWALL GMS, Analyzer, and UMA EM5000 7.2, 8.0, and 8.1 before Hotfix 168056 allows remote authenticated users to execute arbitrary commands via vectors related to configuration input.... Read more

    • EPSS Score: %0.59
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-2072

    The Administrative Web Interface in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, 10.5.e before Build 59.1305.e, and 10.1 allows remote attackers to conduct clickja... Read more

    • EPSS Score: %0.24
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-2071

    Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 11.x before 11.0 Build 64.34, 10.5 before 10.5 Build 59.13, and 10.5.e before Build 59.1305.e allows remote attackers to gain privileges via unspecified NS Web GUI commands.... Read more

    • EPSS Score: %2.74
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-2046

    Cross-site scripting (XSS) vulnerability in the UserPortal page in SOPHOS UTM before 9.353 allows remote attackers to inject arbitrary web script or HTML via the lang parameter.... Read more

    • EPSS Score: %0.97
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-0773

    PostgreSQL before 9.1.20, 9.2.x before 9.2.15, 9.3.x before 9.3.11, 9.4.x before 9.4.6, and 9.5.x before 9.5.1 allows remote attackers to cause a denial of service (infinite loop or buffer overflow and crash) via a large Unicode character range in a regul... Read more

    Affected Products : ubuntu_linux debian_linux postgresql
    • EPSS Score: %4.51
    • Published: Feb. 17, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291898 Results