Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.5

    MEDIUM
    CVE-2015-0682

    Cisco Unified Communications Domain Manager 8.1(4) allows remote authenticated users to execute arbitrary code by visiting a "deprecated page," aka Bug ID CSCup90168.... Read more

    • EPSS Score: %1.22
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-0666

    Directory traversal vulnerability in the fmserver servlet in Cisco Prime Data Center Network Manager (DCNM) before 7.1(1) allows remote attackers to read arbitrary files via a crafted pathname, aka Bug ID CSCus00241.... Read more

    Affected Products : prime_data_center_network_manager
    • Actively Exploited
    • EPSS Score: %68.97
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 4.4

    MEDIUM
    CVE-2014-8390

    Multiple buffer overflows in Schneider Electric VAMPSET before 2.2.168 allow local users to gain privileges via malformed disturbance-recording data in a (1) CFG or (2) DAT file.... Read more

    Affected Products : vampset
    • EPSS Score: %0.17
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 9.0

    HIGH
    CVE-2014-5405

    Hospira MedNet before 6.1 uses a hardcoded cleartext password to control SQL database authorization, which allows remote authenticated users to bypass intended access restrictions by leveraging knowledge of this password.... Read more

    Affected Products : mednet
    • EPSS Score: %0.22
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-5403

    Hospira MedNet before 6.1 uses hardcoded cryptographic keys for protection of data transmission from infusion pumps, which allows remote attackers to obtain sensitive information by sniffing the network.... Read more

    Affected Products : mednet
    • EPSS Score: %0.39
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 2.1

    LOW
    CVE-2014-5400

    The installation component in Hospira MedNet before 6.1 places cleartext credentials in configuration files, which allows local users to obtain sensitive information by reading a file.... Read more

    Affected Products : mednet
    • EPSS Score: %0.06
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2015-0687

    The SNMP implementation in Cisco IOS 15.1(2)SG4 on Catalyst 4500 devices, when single-switch Virtual Switching System (VSS) is configured, allows remote authenticated users to cause a denial of service (device crash) by performing SNMP polling, aka Bug ID... Read more

    • EPSS Score: %0.34
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2015-0686

    The SNMP implementation in Cisco NX-OS 6.1(2)I2(3) on Nexus 9000 devices, when a Reset High Availability (HA) policy is configured, allows remote authenticated users to cause a denial of service (device reload) via unspecified vectors, aka Bug ID CSCuq922... Read more

    • EPSS Score: %0.77
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 7.8

    HIGH
    CVE-2015-0685

    Cisco IOS XE before 3.7.5S on ASR 1000 devices does not properly handle route adjacencies, which allows remote attackers to cause a denial of service (device hang) via crafted IP packets, aka Bug ID CSCub31873.... Read more

    Affected Products : ios_xe ios_xe
    • EPSS Score: %0.43
    • Published: Apr. 03, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2015-1234

    Race condition in gpu/command_buffer/service/gles2_cmd_decoder.cc in Google Chrome before 41.0.2272.118 allows remote attackers to cause a denial of service (buffer overflow) or possibly have unspecified other impact by manipulating OpenGL ES commands.... Read more

    Affected Products : linux_kernel chrome macos windows
    • EPSS Score: %2.01
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-1233

    Google Chrome before 41.0.2272.118 does not properly handle the interaction of IPC, the Gamepad API, and Google V8, which allows remote attackers to execute arbitrary code via unspecified vectors.... Read more

    Affected Products : linux_kernel chrome macos windows
    • EPSS Score: %28.72
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-2821

    TYPO3 Neos 1.1.x before 1.1.3 and 1.2.x before 1.2.3 allows remote editors to access, create, and modify content nodes in the workspace of other editors via unspecified vectors.... Read more

    Affected Products : neos
    • EPSS Score: %0.32
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2820

    Buffer overflow in XcListener in SAP Afaria 7.0.6001.5 allows remote attackers to cause a denial of service (process termination) via a crafted request, aka SAP Security Note 2132584.... Read more

    Affected Products : afaria
    • EPSS Score: %3.87
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2819

    SAP Sybase SQL Anywhere 11 and 16 allows remote attackers to cause a denial of service (crash) via a crafted request, aka SAP Security Note 2108161.... Read more

    Affected Products : sql_anywhere
    • EPSS Score: %3.28
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2818

    XML external entity (XXE) vulnerability in SAP Mobile Platform 3 allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125513.... Read more

    Affected Products : mobile_platform
    • EPSS Score: %0.37
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2817

    The SAP Management Console in SAP NetWeaver 7.40 allows remote attackers to obtain sensitive information via the ReadProfile parameters, aka SAP Security Note 2091768.... Read more

    Affected Products : netweaver
    • EPSS Score: %0.44
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-2816

    The XcListener in SAP Afaria 7.0.6001.5 does not properly restrict access, which allows remote attackers to have unspecified impact via a crafted request, aka SAP Security Note 2134905.... Read more

    Affected Products : afaria
    • EPSS Score: %0.76
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 6.5

    MEDIUM
    CVE-2015-2815

    Buffer overflow in the C_SAPGPARAM function in the NetWeaver Dispatcher in SAP KERNEL 7.00 (7000.52.12.34966) and 7.40 (7400.12.21.30308) allows remote authenticated users to cause a denial of service or possibly execute arbitrary code via unspecified vec... Read more

    Affected Products : netweaver
    • EPSS Score: %3.46
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 6.4

    MEDIUM
    CVE-2015-2814

    SAP EMR Unwired (com.sap.mobile.healthcare.emr.v2) and Clinical Task Tracker (com.sap.mobile.healthcare.ctt) does not properly restrict access, which allows remote attackers to change the backendurl, clientid, ssourl, and infopageurl settings via unspecif... Read more

    Affected Products : clinical_task_tracker emr_unwired
    • EPSS Score: %0.46
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2813

    XML external entity (XXE) vulnerability in SAP Mobile Platform allows remote attackers to send requests to intranet servers via crafted XML, aka SAP Security Note 2125358.... Read more

    Affected Products : mobile_platform
    • EPSS Score: %0.54
    • Published: Apr. 01, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 290955 Results