Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.3

    MEDIUM
    CVE-2015-0072

    Cross-site scripting (XSS) vulnerability in Microsoft Internet Explorer 9 through 11 allows remote attackers to bypass the Same Origin Policy and inject arbitrary web script or HTML via vectors involving an IFRAME element that triggers a redirect, a secon... Read more

    Affected Products : internet_explorer
    • EPSS Score: %88.55
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-0871

    Cross-site scripting (XSS) vulnerability in Mrs. Shiromuku Perl CGI shiromuku(u1)GUESTBOOK 1.62 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more

    Affected Products : guestbook
    • EPSS Score: %0.25
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0602

    The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to obtain sensitive information by sniffing the network, aka Bug ID CSCuq12117.... Read more

    • EPSS Score: %0.35
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0600

    The mobility extension on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to cause a denial of service (logoff) via crafted packets, aka Bug ID CSCuq12139.... Read more

    • EPSS Score: %0.93
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 9.0

    HIGH
    CVE-2015-0589

    The administrative web interface in Cisco WebEx Meetings Server 1.0 through 1.5 allows remote authenticated users to execute arbitrary OS commands with root privileges via unspecified fields, aka Bug ID CSCuj40460.... Read more

    Affected Products : webex_meetings_server
    • EPSS Score: %0.74
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2014-9203

    Buffer overflow in the Field Device Tool (FDT) Frame application in the HART Device Type Manager (DTM) library, as used in MACTek Bullet DTM 1.00.0, GE Vector DTM 1.00.0, GE SVi1000 Positioner DTM 1.00.0, GE SVI II AP Positioner DTM 2.00.1, and GE 12400 L... Read more

    • EPSS Score: %0.76
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-0605

    The uuencode inspection engine in Cisco AsyncOS on Cisco Email Security Appliance (ESA) devices 8.5 and earlier allows remote attackers to bypass intended content restrictions via a crafted e-mail attachment with uuencode encoding, aka Bug ID CSCzv54343.... Read more

    • EPSS Score: %0.58
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 5.0

    MEDIUM
    CVE-2015-0604

    The web framework on Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allows remote attackers to upload files to arbitrary locations on a phone's filesystem via crafted HTTP requests, aka Bug ID CSCup90424.... Read more

    • EPSS Score: %0.18
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 4.6

    MEDIUM
    CVE-2015-0603

    Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier use weak permissions for unspecified files, which allows local users to cause a denial of service (persistent hang or reboot) by writing to a phone's filesystem, aka Bug ID CSCup90474.... Read more

    • EPSS Score: %0.06
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 4.6

    MEDIUM
    CVE-2015-0601

    Cisco Unified IP 9900 phones with firmware 9.4(.1) and earlier allow local users to cause a denial of service (device reload) via crafted commands, aka Bug ID CSCup92790.... Read more

    • EPSS Score: %0.26
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 6.3

    MEDIUM
    CVE-2013-5557

    The Proxy Bypass Content Rewriter feature in the WebVPN subsystem in Cisco Adaptive Security Appliance (ASA) Software 9.1(.2) and earlier allows remote authenticated users to cause a denial of service (device crash or error-recovery event) via an HTTP req... Read more

    • EPSS Score: %0.34
    • Published: Feb. 07, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-1514

    Multiple SQL injection vulnerabilities in FancyFon FAMOC before 3.17.4 allow (1) remote attackers to execute arbitrary SQL commands via the device ID REST parameter (PATH_INFO) to /ajax.php or (2) remote authenticated users to execute arbitrary SQL comman... Read more

    Affected Products : famoc
    • EPSS Score: %0.36
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-1513

    SQL injection vulnerability in SIPhone Enterprise PBX allows remote attackers to execute arbitrary SQL commands via the Username.... Read more

    Affected Products : siphone_enterprise_pbx
    • EPSS Score: %0.31
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-1512

    Multiple cross-site scripting (XSS) vulnerabilities in FancyFon FAMOC before 3.17.4 allow remote attackers to inject arbitrary web script or HTML via the (1) LoginForm[username] to ui/system/login or the (2) order or (3) myorgs to index.php.... Read more

    Affected Products : famoc
    • EPSS Score: %0.25
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-1467

    Multiple SQL injection vulnerabilities in Translations in Fork CMS before 3.8.6 allow remote authenticated users to execute arbitrary SQL commands via the (1) language[] or (2) type[] parameter to private/en/locale/index.... Read more

    Affected Products : fork_cms
    • EPSS Score: %1.34
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 4.3

    MEDIUM
    CVE-2015-1444

    Multiple cross-site scripting (XSS) vulnerabilities in the web administration frontend in the httpd package in fli4l before 3.10.1 and 4.0 before 2015-01-30 allow remote attackers to inject arbitrary web script or HTML via the (1) conntrack.cgi, (2) index... Read more

    Affected Products : fli4l
    • EPSS Score: %0.40
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.5

    HIGH
    CVE-2015-1442

    SQL injection vulnerability in views/zero_transact_user.php in the administrative backend in ZeroCMS 1.3.3, 1.3.2, and earlier allows remote authenticated users to execute arbitrary SQL commands via the user_id parameter in a Modify Account action. NOTE:... Read more

    Affected Products : zerocms
    • EPSS Score: %1.00
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 6.9

    MEDIUM
    CVE-2015-1305

    McAfee Data Loss Prevention Endpoint (DLPe) before 9.3.400 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted (1) 0x00224014 or (2) 0x0022c018 IOCTL call.... Read more

    • EPSS Score: %0.57
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2014-9643

    K7Sentry.sys in K7 Computing Ultimate Security, Anti-Virus Plus, and Total Security before 14.2.0.253 allows local users to write to arbitrary memory locations, and consequently gain privileges, via a crafted 0x95002570, 0x95002574, 0x95002580, 0x950025a8... Read more

    • EPSS Score: %0.73
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
  • 7.2

    HIGH
    CVE-2014-9642

    bdagent.sys in BullGuard Antivirus, Internet Security, Premium Protection, and Online Backup before 15.0.288 allows local users to write data to arbitrary memory locations, and consequently gain privileges, via a crafted 0x0022405c IOCTL call.... Read more

    • EPSS Score: %1.28
    • Published: Feb. 06, 2015
    • Modified: Apr. 12, 2025
Showing 20 of 290997 Results