Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.4

    MEDIUM
    CVE-2015-0239

    The em_sysenter function in arch/x86/kvm/emulate.c in the Linux kernel before 3.18.5, when the guest OS lacks SYSENTER MSR initialization, allows guest OS users to gain guest OS privileges or cause a denial of service (guest OS crash) by triggering use of... Read more

    • EPSS Score: %0.10
    • Published: Mar. 02, 2015
    • Modified: Apr. 12, 2025
  • 2.1

    LOW
    CVE-2014-9644

    The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expre... Read more

    • EPSS Score: %0.04
    • Published: Mar. 02, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-8160

    net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intende... Read more

    • EPSS Score: %2.45
    • Published: Mar. 02, 2015
    • Modified: Apr. 12, 2025
  • 2.1

    LOW
    CVE-2013-7421

    The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.... Read more

    • EPSS Score: %0.03
    • Published: Mar. 02, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2014-8921

    The IBM Notes Traveler Companion application 1.0 and 1.1 before 201411010515 for Window Phone, as distributed in IBM Notes Traveler 9.0.1, does not properly restrict the number of executions of the automatic configuration option, which makes it easier for... Read more

    Affected Products : notes_traveler_companion
    • EPSS Score: %0.75
    • Published: Mar. 02, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-0889

    KENT-WEB Joyful Note before 5.3 allows remote attackers to delete files or write to files, and consequently execute arbitrary code, via vectors involving an article.... Read more

    Affected Products : joyful_note
    • EPSS Score: %2.10
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 6.4

    MEDIUM
    CVE-2015-0888

    KENT-WEB Clip Board before 4.1 allows remote attackers to delete arbitrary files via unspecified vectors.... Read more

    Affected Products : clip_board
    • EPSS Score: %0.87
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 7.1

    HIGH
    CVE-2015-0887

    npppd in the PPP Access Concentrator (PPPAC) on SEIL SEIL/x86 Fuji routers 1.00 through 3.30, SEIL/X1 routers 3.50 through 4.70, SEIL/X2 routers 3.50 through 4.70, and SEIL/B1 routers 3.50 through 4.70 allows remote attackers to cause a denial of service ... Read more

    • EPSS Score: %0.51
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0886

    Integer overflow in the crypt_raw method in the key-stretching implementation in jBCrypt before 0.4 makes it easier for remote attackers to determine cleartext values of password hashes via a brute-force attack against hashes associated with the maximum e... Read more

    Affected Products : fedora jbcrypt
    • EPSS Score: %2.48
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0885

    checkpw 1.02 and earlier allows remote attackers to cause a denial of service (infinite loop) via a -- (dash dash) in a username.... Read more

    Affected Products : debian_linux checkpw
    • EPSS Score: %0.89
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 6.9

    MEDIUM
    CVE-2015-0884

    Unquoted Windows search path vulnerability in Toshiba Bluetooth Stack for Windows before 9.10.32(T) and Service Station before 2.2.14 allows local users to gain privileges via a Trojan horse application with a name composed of an initial substring of a pa... Read more

    • EPSS Score: %0.08
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-0655

    Cross-site scripting (XSS) vulnerability in Unified Web Interaction Manager in Cisco Unified Web and E-Mail Interaction Manager allows remote attackers to inject arbitrary web script or HTML via vectors related to a POST request, aka Bug ID CSCus74184.... Read more

    • EPSS Score: %0.30
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 10.0

    HIGH
    CVE-2014-9682

    The dns-sync module before 0.1.1 for node.js allows context-dependent attackers to execute arbitrary commands via shell metacharacters in the first argument to the resolve API function.... Read more

    Affected Products : node-dns-sync dns-sync
    • EPSS Score: %1.04
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 6.8

    MEDIUM
    CVE-2014-9676

    The seg_write_packet function in libavformat/segment.c in ffmpeg 2.1.4 and earlier does not free the correct memory location, which allows remote attackers to cause a denial of service ("invalid memory handler") and possibly execute arbitrary code via a c... Read more

    Affected Products : ffmpeg
    • EPSS Score: %1.61
    • Published: Feb. 28, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-2103

    Cross-site scripting (XSS) vulnerability in the admin-login panel (admin/index.cgi) in Cosmoshop allows remote attackers to inject arbitrary web script or HTML via the username field (u_name parameter).... Read more

    Affected Products : cosmoshop
    • EPSS Score: %0.32
    • Published: Feb. 27, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-2102

    SQL injection vulnerability in view_item.php in ClipBucket 2.7 RC3 (2.7.0.4.v2929-rc3) allows remote attackers to execute arbitrary SQL commands via the item parameter.... Read more

    Affected Products : clipbucket
    • EPSS Score: %2.41
    • Published: Feb. 27, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-2101

    Cross-site scripting (XSS) vulnerability in the Navigate bar in the Navigate module before 6.x-1.1 and 7.x-1.x before 7.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : navigate
    • EPSS Score: %0.49
    • Published: Feb. 27, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2076

    The Auditing service in SAP BusinessObjects Edge 4.0 allows remote attackers to obtain sensitive information by reading an audit event, aka SAP Note 2011395.... Read more

    Affected Products : businessobjects_edge
    • EPSS Score: %0.39
    • Published: Feb. 27, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-2075

    SAP BusinessObjects Edge 4.0 allows remote attackers to delete audit events from the auditee queue via a clearData CORBA operation, aka SAP Note 2011396.... Read more

    Affected Products : businessobjects_edge
    • EPSS Score: %1.19
    • Published: Feb. 27, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-2072

    Multiple cross-site scripting (XSS) vulnerabilities in SAP HANA 73 (1.00.73.00.389160) and HANA Developer Edition 80 (1.00.80.00.391861) allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) ide/core/plugins/editor/t... Read more

    Affected Products : hana
    • EPSS Score: %0.26
    • Published: Feb. 27, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 290958 Results