Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.4

    MEDIUM
    CVE-2016-2045

    Cross-site scripting (XSS) vulnerability in the SQL editor in phpMyAdmin 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a SQL query that triggers JSON data in a response.... Read more

    Affected Products : fedora phpmyadmin
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-2044

    libraries/sql-parser/autoload.php in the SQL parser in phpMyAdmin 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more

    Affected Products : fedora phpmyadmin
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2016-2043

    Cross-site scripting (XSS) vulnerability in the goToFinish1NF function in js/normalization.js in phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote authenticated users to inject arbitrary web script or HTML via a table name to the norma... Read more

    Affected Products : fedora leap phpmyadmin opensuse
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-2042

    phpMyAdmin 4.4.x before 4.4.15.3 and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request to (1) libraries/phpseclib/Crypt/AES.php or (2) libraries/phpseclib/Crypt/Rijndael.php, which reveals the full path in an... Read more

    Affected Products : fedora leap phpmyadmin opensuse
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-2041

    libraries/common.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not use a constant-time algorithm for comparing CSRF tokens, which makes it easier for remote attackers to bypass intended access restriction... Read more

    Affected Products : fedora leap phpmyadmin opensuse
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 5.4

    MEDIUM
    CVE-2016-2040

    Multiple cross-site scripting (XSS) vulnerabilities in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allow remote authenticated users to inject arbitrary web script or HTML via a (1) table name, (2) SET value, (3) search... Read more

    Affected Products : fedora leap phpmyadmin opensuse
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-2039

    libraries/session.inc.php in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 does not properly generate CSRF token values, which allows remote attackers to bypass intended access restrictions by predicting a value.... Read more

    Affected Products : fedora leap phpmyadmin opensuse
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-2038

    phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 allows remote attackers to obtain sensitive information via a crafted request, which reveals the full path in an error message.... Read more

    Affected Products : fedora leap phpmyadmin opensuse
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-1927

    The suggestPassword function in js/functions.js in phpMyAdmin 4.0.x before 4.0.10.13, 4.4.x before 4.4.15.3, and 4.5.x before 4.5.4 relies on the Math.random JavaScript function, which makes it easier for remote attackers to guess passwords via a brute-fo... Read more

    Affected Products : phpmyadmin
    • Published: Feb. 20, 2016
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2016-1335

    The SSH implementation in Cisco StarOS before 19.3.M0.62771 and 20.x before 20.0.M0.62768 on ASR 5000 devices mishandles a multi-user public-key authentication configuration, which allows remote authenticated users to gain privileges by establishing a con... Read more

    Affected Products : asr_5000_series_software
    • Published: Feb. 19, 2016
    • Modified: Apr. 12, 2025
  • 5.7

    MEDIUM
    CVE-2016-1156

    LINE 4.3.0.724 and earlier on Windows and 4.3.1 and earlier on OS X allows remote authenticated users to cause a denial of service (application crash) via a crafted post that is mishandled when displaying a Timeline.... Read more

    Affected Products : mac_os_x windows line
    • Published: Feb. 19, 2016
    • Modified: Apr. 12, 2025
  • 9.1

    CRITICAL
    CVE-2016-1154

    SQL injection vulnerability in the Help plug-in 1.3.5 and earlier in Cuore EC-CUBE allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more

    Affected Products : ec-cube_help_plugin
    • Published: Feb. 19, 2016
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-7769

    baserCMS 3.0.2 through 3.0.8 allows remote authenticated users to execute arbitrary OS commands via unspecified vectors.... Read more

    Affected Products : basercms
    • Published: Feb. 19, 2016
    • Modified: Apr. 12, 2025
  • 5.5

    MEDIUM
    CVE-2016-2271

    VMX in Xen 4.6.x and earlier, when using an Intel or Cyrix CPU, allows local HVM guest users to cause a denial of service (guest crash) via vectors related to a non-canonical RIP.... Read more

    Affected Products : xen
    • Published: Feb. 19, 2016
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2016-2270

    Xen 4.6.x and earlier allows local guest administrators to cause a denial of service (host reboot) via vectors related to multiple mappings of MMIO pages with different cachability settings.... Read more

    Affected Products : fedora debian_linux xen vm_server
    • Published: Feb. 19, 2016
    • Modified: Apr. 12, 2025
  • 5.3

    MEDIUM
    CVE-2016-2509

    The password-sync feature on Belden Hirschmann Classic Platform switches L2B before 05.3.07 and L2E, L2P, L3E, and L3P before 09.0.06 sets an SNMP community to the same string as the administrator password, which allows remote attackers to obtain sensitiv... Read more

    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 5.9

    MEDIUM
    CVE-2016-1987

    HPE IPFilter A.11.31.18.21 on HP-UX, when a certain keep-state configuration is enabled, allows remote attackers to cause a denial of service via unspecified UDP packets.... Read more

    Affected Products : hp-ux_ipfilter
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-0069

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0068.... Read more

    Affected Products : internet_explorer
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 9.3

    HIGH
    CVE-2016-0068

    Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy via unspecified vectors, aka "Internet Explorer Elevation of Privilege Vulnerability," a different vulnerability than CVE-2016-0069.... Read more

    Affected Products : internet_explorer
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
  • 9.1

    CRITICAL
    CVE-2015-8151

    Symantec Encryption Management Server (SEMS) 3.3.2 before MP12 allows remote authenticated users to execute arbitrary OS commands by leveraging console administrator access.... Read more

    Affected Products : encryption_management_server
    • Published: Feb. 18, 2016
    • Modified: Apr. 12, 2025
Showing 20 of 292916 Results