Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2015-7417

    Cross-site scripting (XSS) vulnerability in IBM WebSphere Application Server 7.0 before 7.0.0.41, 8.0 before 8.0.0.12, and 8.5 before 8.5.5.9 allows remote authenticated users to inject arbitrary web script or HTML via crafted data from an OAuth provider.... Read more

    Affected Products : websphere_application_server
    • EPSS Score: %0.17
    • Published: Jan. 23, 2016
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-6317

    Cisco Identity Services Engine (ISE) before 2.0 allows remote authenticated users to bypass intended web-resource access restrictions via a direct request, aka Bug ID CSCuu45926.... Read more

    Affected Products : identity_services_engine_software
    • EPSS Score: %0.14
    • Published: Jan. 23, 2016
    • Modified: Apr. 12, 2025
  • 8.4

    HIGH
    CVE-2016-1572

    mount.ecryptfs_private.c in eCryptfs-utils does not validate mount destination filesystem types, which allows local users to gain privileges by mounting over a nonstandard filesystem, as demonstrated by /proc/$pid.... Read more

    • EPSS Score: %0.05
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2016-1571

    The paging_invlpg function in include/asm-x86/paging.h in Xen 3.3.x through 4.6.x, when using shadow mode paging or nested virtualization is enabled, allows local HVM guest users to cause a denial of service (host crash) via a non-canonical guest address ... Read more

    Affected Products : xen xenserver
    • EPSS Score: %0.30
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 8.5

    HIGH
    CVE-2016-1570

    The PV superpage functionality in arch/x86/mm.c in Xen 3.4.0, 3.4.1, and 4.1.x through 4.6.x allows local PV guests to obtain sensitive information, cause a denial of service, gain privileges, or have unspecified other impact via a crafted page identifier... Read more

    Affected Products : xen
    • EPSS Score: %0.20
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2015-7744

    wolfSSL (formerly CyaSSL) before 3.6.8 does not properly handle faults associated with the Chinese Remainder Theorem (CRT) process when allowing ephemeral key exchange without low memory optimizations on a server, which makes it easier for remote attacker... Read more

    Affected Products : leap mariadb opensuse wolfssl
    • EPSS Score: %3.42
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-6925

    wolfSSL (formerly CyaSSL) before 3.6.8 allows remote attackers to cause a denial of service (resource consumption or traffic amplification) via a crafted DTLS cookie in a ClientHello message.... Read more

    Affected Products : wolfssl
    • EPSS Score: %0.90
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6015

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more

    • EPSS Score: %19.92
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6014

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more

    • EPSS Score: %19.92
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6013

    Unspecified vulnerability in the Oracle Outside In Technology component in Oracle Fusion Middleware 8.5.0, 8.5.1, and 8.5.2 allows local users to affect availability via unknown vectors related to Outside In Filters, a different vulnerability than CVE-201... Read more

    • EPSS Score: %19.92
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2016-1984

    The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2016-01-20 has a hardcoded password for the 1MB@tMaN account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerabil... Read more

    Affected Products : amx_firmware
    • EPSS Score: %4.08
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 6.1

    MEDIUM
    CVE-2016-1135

    Cross-site scripting (XSS) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earlier, WH... Read more

    • EPSS Score: %0.24
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 8.8

    HIGH
    CVE-2016-1134

    Cross-site request forgery (CSRF) vulnerability on BUFFALO BHR-4GRV2 devices with firmware 1.04 and earlier, WEX-300 devices with firmware 1.90 and earlier, WHR-1166DHP devices with firmware 1.90 and earlier, WHR-300HP2 devices with firmware 1.90 and earl... Read more

    • EPSS Score: %0.10
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-8362

    The setUpSubtleUserAccount function in /bin/bw on Harman AMX devices before 2015-10-12 has a hardcoded password for the BlackWidow account, which makes it easier for remote attackers to obtain access via a (1) SSH or (2) HTTP session, a different vulnerab... Read more

    Affected Products : amx_firmware
    • EPSS Score: %7.47
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7909

    Stack-based buffer overflow in Hospira Communication Engine (CE) before 1.2 in LifeCare PCA Infusion System 5.07, Plum A+ Infusion System 13.40, and Plum A+3 Infusion System 13.40 allows remote attackers to cause a denial of service or possibly have unspe... Read more

    • EPSS Score: %0.39
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6435

    An unspecified CGI script in Cisco FX-OS before 1.1.2 on Firepower 9000 devices and Cisco Unified Computing System (UCS) Manager before 2.2(4b), 2.2(5) before 2.2(5a), and 3.0 before 3.0(2e) allows remote attackers to execute arbitrary shell commands via ... Read more

    • EPSS Score: %16.00
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-6412

    Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070.... Read more

    • EPSS Score: %1.94
    • Published: Jan. 22, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-8472

    Buffer overflow in the png_set_PLTE function in libpng before 1.0.65, 1.1.x and 1.2.x before 1.2.55, 1.3.x, 1.4.x before 1.4.18, 1.5.x before 1.5.25, and 1.6.x before 1.6.20 allows remote attackers to cause a denial of service (application crash) or possi... Read more

    Affected Products : libpng mac_os_x
    • EPSS Score: %3.20
    • Published: Jan. 21, 2016
    • Modified: Apr. 12, 2025
  • 1.4

    LOW
    CVE-2016-0618

    Unspecified vulnerability in Oracle Sun Solaris 11 allows local users to affect confidentiality via unknown vectors related to Zones.... Read more

    Affected Products : solaris
    • EPSS Score: %0.08
    • Published: Jan. 21, 2016
    • Modified: Apr. 12, 2025
  • 4.0

    MEDIUM
    CVE-2016-0616

    Unspecified vulnerability in Oracle MySQL 5.5.46 and earlier and MariaDB before 5.5.47, 10.0.x before 10.0.23, and 10.1.x before 10.1.10 allows remote authenticated users to affect availability via unknown vectors related to Optimizer.... Read more

    • EPSS Score: %0.57
    • Published: Jan. 21, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 291728 Results