Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.2

    HIGH
    CVE-2015-7866

    Unquoted Windows search path vulnerability in the Smart Maximize Helper (nvSmartMaxApp.exe) in the Control Panel in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows allows local users to gain privile... Read more

    Affected Products : windows gpu_driver
    • EPSS Score: %0.07
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.7

    HIGH
    CVE-2015-7865

    nvSCPAPISvr.exe in the Stereoscopic 3D Driver Service in the NVIDIA GPU graphics driver R340 before 341.92, R352 before 354.35, and R358 before 358.87 on Windows does not properly restrict access to the stereosvrpipe named pipe, which allows local users t... Read more

    Affected Products : windows gpu_driver
    • EPSS Score: %2.11
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7808

    The vB_Api_Hook::decodeArguments method in vBulletin 5 Connect 5.1.2 through 5.1.9 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object in the arguments parameter to ajax/api/hook/d... Read more

    Affected Products : vbulletin
    • EPSS Score: %84.78
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-7496

    GNOME Display Manager (gdm) before 3.18.2 allows physically proximate attackers to bypass the lock screen by holding the Escape key.... Read more

    Affected Products : fedora gnome_display_manager
    • EPSS Score: %0.08
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 2.6

    LOW
    CVE-2015-5281

    The grub2 package before 2.02-0.29 in Red Hat Enterprise Linux (RHEL) 7, when used on UEFI systems, allows local users to bypass intended Secure Boot restrictions and execute non-verified code via a crafted (1) multiboot or (2) multiboot2 module in the co... Read more

    Affected Products : enterprise_linux
    • EPSS Score: %0.06
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-5053

    The host memory mapping path feature in the NVIDIA GPU graphics driver R346 before 346.87 and R352 before 352.41 for Linux and R352 before 352.46 for GRID vGPU and vSGA does not properly restrict access to third-party device IO memory, which allows attack... Read more

    Affected Products : gpu_driver
    • EPSS Score: %0.52
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 4.6

    MEDIUM
    CVE-2015-0856

    daemon/Greeter.cpp in sddm before 0.13.0 does not properly disable the KDE crash handler, which allows local users to gain privileges by crashing a greeter when using certain themes, as demonstrated by the plasma-workspace breeze theme.... Read more

    Affected Products : fedora sddm
    • EPSS Score: %0.17
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-6380

    An unspecified script in the web interface in Cisco Firepower Extensible Operating System 1.1(1.160) on Firepower 9000 devices allows remote authenticated users to execute arbitrary OS commands via crafted parameters, aka Bug ID CSCux10622.... Read more

    • EPSS Score: %0.45
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-6377

    Cisco Virtual Topology System (VTS) 2.0(0) and 2.0(1) allows remote attackers to cause a denial of service (CPU and memory consumption, and TCP port outage) via a flood of crafted TCP packets, aka Bug ID CSCux13379.... Read more

    Affected Products : virtual_topology_system
    • EPSS Score: %3.55
    • Published: Nov. 24, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-8320

    Apache Cordova-Android before 3.7.0 improperly generates random values for BridgeSecret data, which makes it easier for attackers to conduct bridge hijacking attacks by predicting a value.... Read more

    Affected Products : cordova
    • EPSS Score: %2.56
    • Published: Nov. 23, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-5256

    Apache Cordova-Android before 4.1.0, when an application relies on a remote server, improperly implements a JavaScript whitelist protection mechanism, which allows attackers to bypass intended access restrictions via a crafted URI.... Read more

    Affected Products : cordova
    • EPSS Score: %0.70
    • Published: Nov. 23, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-5451

    Cross-site request forgery (CSRF) vulnerability in HP Operations Orchestration Central 10.x before 10.22.001 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more

    Affected Products : operations_orchestration
    • EPSS Score: %0.11
    • Published: Nov. 23, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-7036

    The fts3_tokenizer function in SQLite, as used in Apple iOS before 8.4 and OS X before 10.10.4, allows remote attackers to execute arbitrary code or cause a denial of service (application crash) via a SQL command that triggers an API call with a crafted p... Read more

    Affected Products : mac_os_x iphone_os
    • EPSS Score: %3.07
    • Published: Nov. 22, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-5859

    The CFNetwork HTTPProtocol component in Apple iOS before 9 and OS X before 10.11 does not properly recognize the HSTS preload list during a Safari private-browsing session, which makes it easier for remote attackers to obtain sensitive information by snif... Read more

    Affected Products : mac_os_x iphone_os
    • EPSS Score: %0.25
    • Published: Nov. 22, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-5787

    The kernel in Apple iOS before 8.4.1 does not properly restrict debugging features, which allows attackers to bypass background-execution limitations via a crafted app.... Read more

    Affected Products : iphone_os
    • EPSS Score: %0.55
    • Published: Nov. 22, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2015-7913

    ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows local users to execute arbitrary Java code with SYSTEM privileges by using the Apache Axis AdminService deployment method to publish a class.... Read more

    Affected Products : aggregate
    • EPSS Score: %0.05
    • Published: Nov. 21, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2015-7912

    The Ice Faces servlet in ag_server_service.exe in the AggreGate Server Service in Tibbo AggreGate before 5.30.06 allows remote attackers to upload and execute arbitrary Java code via a crafted XML document.... Read more

    Affected Products : aggregate
    • EPSS Score: %0.54
    • Published: Nov. 21, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-7777

    Cross-site scripting (XSS) vulnerability in index.php in JosephErnest Void before 2015-10-02 allows remote attackers to inject arbitrary web script or HTML via a crafted URI.... Read more

    Affected Products : void
    • EPSS Score: %0.32
    • Published: Nov. 21, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-7291

    Cross-site request forgery (CSRF) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to hijack the authentication of arb... Read more

    • EPSS Score: %0.10
    • Published: Nov. 21, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-7290

    Cross-site scripting (XSS) vulnerability in adv_pwd_cgi in the web management interface on Arris DG860A, TG862A, and TG862G devices with firmware TS0703128_100611 through TS0705125D_031115 allows remote attackers to inject arbitrary web script or HTML via... Read more

    • EPSS Score: %0.64
    • Published: Nov. 21, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 291608 Results