Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.0

    MEDIUM
    CVE-2015-5242

    OpenStack Swift-on-File (aka Swiftonfile) does not properly restrict use of the pickle Python module when loading metadata, which allows remote authenticated users to execute arbitrary code via a crafted extended attribute (xattrs).... Read more

    Affected Products : gluster_storage
    • EPSS Score: %1.20
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2014-3665

    Jenkins before 1.587 and LTS before 1.580.1 do not properly ensure trust separation between a master and slaves, which might allow remote attackers to execute arbitrary code on the master by leveraging access to the slave.... Read more

    Affected Products : jenkins
    • EPSS Score: %0.34
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-7288

    CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 allow remote attackers to modify the configuration via a command in an SMS message, as demonstrated by a "4 2" command.... Read more

    Affected Products : gprs_cs2300-r_firmware gprs
    • EPSS Score: %1.10
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7287

    CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 use the same 001984 default PIN across different customers' installations, which allows remote attackers to execute commands by leveraging knowledge of this PIN and including it in an SMS m... Read more

    Affected Products : gprs_cs2300-r_firmware gprs
    • EPSS Score: %5.71
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 6.4

    MEDIUM
    CVE-2015-7286

    CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 rely on a polyalphabetic substitution cipher with hardcoded keys, which makes it easier for remote attackers to defeat a cryptographic protection mechanism by capturing IP or V.22bis PSTN p... Read more

    Affected Products : gprs_cs2300-r_firmware gprs
    • EPSS Score: %1.49
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 5.8

    MEDIUM
    CVE-2015-7285

    CSL DualCom GPRS CS2300-R devices with firmware 1.25 through 3.53 do not require authentication from Alarm Receiving Center (ARC) servers, which allows man-in-the-middle attackers to bypass intended access restrictions via a spoofed HSxx response.... Read more

    Affected Products : gprs_cs2300-r_firmware gprs
    • EPSS Score: %0.36
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-6379

    The XML parser in the management interface in Cisco Adaptive Security Appliance (ASA) Software 8.4 allows remote authenticated users to cause a denial of service (device crash) via a crafted XML document, aka Bug ID CSCut14223.... Read more

    • EPSS Score: %0.78
    • Published: Nov. 25, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-8330

    The PCo agent in SAP Plant Connectivity (PCo) allows remote attackers to cause a denial of service (memory corruption and agent crash) via crafted xMII requests, aka SAP Security Note 2238619.... Read more

    Affected Products : plant_connectivity
    • EPSS Score: %3.35
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-8329

    SAP Manufacturing Integration and Intelligence (aka MII, formerly xMII) uses weak encryption (Base64 and DES), which allows attackers to conduct downgrade attacks and decrypt passwords via unspecified vectors, aka SAP Security Note 2240274.... Read more

    • EPSS Score: %0.15
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 6.6

    MEDIUM
    CVE-2015-8328

    Unspecified vulnerability in the NVAPI support layer in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to obtain sensitive information, cause a denial of service (crash), or poss... Read more

    Affected Products : windows gpu_driver
    • EPSS Score: %0.05
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 4.0

    MEDIUM
    CVE-2015-8229

    Huawei eSpace U2980 unified gateway with software before V100R001C10 and U2990 with software before V200R001C10 allow remote authenticated users to cause a denial of service via crafted signaling packets from a registered device.... Read more

    • EPSS Score: %0.19
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 4.0

    MEDIUM
    CVE-2015-8228

    Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors.... Read more

    • EPSS Score: %0.54
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 8.5

    HIGH
    CVE-2015-8227

    The built-in web server in Huawei VP9660 multi-point control unit with software before V200R001C30SPC700 allows remote administrators to obtain sensitive information or cause a denial of service via a crafted message.... Read more

    Affected Products : vp_9660_firmware vp9660
    • EPSS Score: %0.16
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-7985

    Valve Steam 2.10.91.91 uses weak permissions (Users: read and write) for the Install folder, which allows local users to gain privileges via a Trojan horse steam.exe file.... Read more

    Affected Products : steam_client steam
    • EPSS Score: %0.14
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-7981

    The png_convert_to_rfc1123 function in png.c in libpng 1.0.x before 1.0.64, 1.2.x before 1.2.54, and 1.4.x before 1.4.17 allows remote attackers to obtain sensitive process memory information via crafted tIME chunk data in an image file, which triggers an... Read more

    • EPSS Score: %0.79
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 6.6

    MEDIUM
    CVE-2015-7869

    Multiple integer overflows in the kernel mode driver for the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows and R304 before 304.131, R340 before 340.96, R352 before 352.63, and R358 before 358.16 on Li... Read more

    • EPSS Score: %0.06
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-7866

    Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to gain privile... Read more

    Affected Products : windows gpu_driver
    • EPSS Score: %0.07
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.7

    HIGH
    CVE-2015-7865

    nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users t... Read more

    Affected Products : windows gpu_driver
    • EPSS Score: %2.11
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7808

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/d... Read more

    Affected Products : vbulletin
    • EPSS Score: %84.78
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-7496

    GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.... Read more

    Affected Products : fedora gnome_display_manager
    • EPSS Score: %0.08
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 291384 Results