Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.1

    HIGH
    CVE-2016-0869

    Heap-based buffer overflow in MICROSYS PROMOTIC before 8.3.11 allows remote authenticated users to cause a denial of service via a malformed HTML document.... Read more

    Affected Products : promotic
    • EPSS Score: %0.23
    • Published: Jan. 26, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2015-8379

    CakePHP 2.x and 3.x before 3.1.5 might allow remote attackers to bypass the CSRF protection mechanism via the _method parameter.... Read more

    Affected Products : cakephp
    • EPSS Score: %0.27
    • Published: Jan. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.7

    HIGH
    CVE-2015-7974

    NTP 4.x before 4.2.8p6 and 4.3.x before 4.3.90 do not verify peer associations of symmetric keys when authenticating packets, which might allow remote attackers to conduct impersonation attacks via an arbitrary trusted key, aka a "skeleton key."... Read more

    • EPSS Score: %3.67
    • Published: Jan. 26, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-1298

    Multiple cross-site scripting (XSS) vulnerabilities in Cisco Unified Contact Center Express 10.0(1), 10.5(1), 10.6(1), and 11.0(1) allow remote attackers to inject arbitrary web script or HTML via vectors related to permalinks, aka Bug ID CSCux92033.... Read more

    Affected Products : unified_contact_center_express
    • EPSS Score: %0.23
    • Published: Jan. 26, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2015-6337

    Cross-site scripting (XSS) vulnerability in Cisco Application Policy Infrastructure Controller Enterprise Module (APIC-EM) 1.0.10 allows remote attackers to inject arbitrary web script or HTML via a crafted hostname in an SNMP response, aka Bug ID CSCuw47... Read more

    • EPSS Score: %0.25
    • Published: Jan. 26, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-2052

    Multiple unspecified vulnerabilities in HarfBuzz before 1.0.6, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via crafted data, as demonstrated by a buffer over-read resulting from ... Read more

    Affected Products : chrome harfbuzz
    • EPSS Score: %0.47
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.8

    CRITICAL
    CVE-2016-2051

    Multiple unspecified vulnerabilities in Google V8 before 4.8.271.17, as used in Google Chrome before 48.0.2564.82, allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    • EPSS Score: %0.30
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-1620

    Multiple unspecified vulnerabilities in Google Chrome before 48.0.2564.82 allow attackers to cause a denial of service or possibly have other impact via unknown vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %1.43
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1619

    Multiple integer overflows in the (1) sycc422_to_rgb and (2) sycc444_to_rgb functions in fxcodec/codec/fx_codec_jpx_opj.cpp in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service (out-of-bounds read) o... Read more

    Affected Products : chrome
    • EPSS Score: %0.80
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-1618

    Blink, as used in Google Chrome before 48.0.2564.82, does not ensure that a proper cryptographicallyRandomValues random number generator is used, which makes it easier for remote attackers to defeat cryptographic protection mechanisms via unspecified vect... Read more

    Affected Products : chrome
    • EPSS Score: %0.91
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1617

    The CSPSource::schemeMatches function in WebKit/Source/core/frame/csp/CSPSource.cpp in the Content Security Policy (CSP) implementation in Blink, as used in Google Chrome before 48.0.2564.82, does not apply http policies to https URLs and does not apply w... Read more

    Affected Products : chrome
    • EPSS Score: %0.64
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1616

    The CustomButton::AcceleratorPressed function in ui/views/controls/button/custom_button.cc in Google Chrome before 48.0.2564.82 allows remote attackers to spoof URLs via vectors involving an unfocused custom button.... Read more

    Affected Products : chrome
    • EPSS Score: %1.18
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2016-1615

    The Omnibox implementation in Google Chrome before 48.0.2564.82 allows remote attackers to spoof a document's origin via unspecified vectors.... Read more

    Affected Products : chrome
    • EPSS Score: %0.76
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2016-1614

    The UnacceleratedImageBufferSurface class in WebKit/Source/platform/graphics/UnacceleratedImageBufferSurface.cpp in Blink, as used in Google Chrome before 48.0.2564.82, mishandles the initialization mode, which allows remote attackers to obtain sensitive ... Read more

    Affected Products : chrome
    • EPSS Score: %0.79
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1613

    Multiple use-after-free vulnerabilities in the formfiller implementation in PDFium, as used in Google Chrome before 48.0.2564.82, allow remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted PDF document, rel... Read more

    Affected Products : chrome
    • EPSS Score: %0.87
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 7.6

    HIGH
    CVE-2016-1612

    The LoadIC::UpdateCaches function in ic/ic.cc in Google V8, as used in Google Chrome before 48.0.2564.82, does not ensure receiver compatibility before performing a cast of an unspecified variable, which allows remote attackers to cause a denial of servic... Read more

    Affected Products : chrome
    • EPSS Score: %1.03
    • Published: Jan. 25, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2015-7417

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.... Read more

    Affected Products : websphere_application_server
    • EPSS Score: %0.17
    • Published: Jan. 23, 2016
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-6317

    Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.... Read more

    Affected Products : identity_services_engine_software
    • EPSS Score: %0.14
    • Published: Jan. 23, 2016
    • Modified: Apr. 12, 2025
  • 8.4

    HIGH
    CVE-2016-1572

    mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.... Read more

    • EPSS Score: %0.05
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2016-1571

    The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address ... Read more

    Affected Products : xen xenserver
    • EPSS Score: %0.30
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291564 Results