Latest CVE Feed
-
5.4
MEDIUMCVE-2015-7672
Cross-site scripting (XSS) vulnerability in Centreon 2.6.1 (fixed in Centreon 18.10.0 and Centreon web 2.8.27).... Read more
Affected Products : centreon- EPSS Score: %0.03
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-5060
Cross-site scripting (XSS) vulnerability in anchor-cms before 0.9-dev.... Read more
Affected Products : anchor_cms- EPSS Score: %0.24
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-4627
SQL injection vulnerability in Pragyan CMS 3.0.... Read more
Affected Products : pragyan_cms- EPSS Score: %0.25
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-4085
Directory traversal vulnerability in node/hooks/express/tests.js in Etherpad frontend tests before 1.6.1.... Read more
Affected Products : etherpad- EPSS Score: %0.39
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1098
IBM Emptoris Supplier Lifecycle Management 10.1.0.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclos... Read more
Affected Products : emptoris_supplier_lifecycle_management- EPSS Score: %0.20
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-8316
Array index error in LightDM (aka Light Display Manager) 1.14.3, 1.16.x before 1.16.6 when the XDMCP server is enabled allows remote attackers to cause a denial of service (process crash) via an XDMCP request packet with no address.... Read more
Affected Products : lightdm- EPSS Score: %0.59
- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-5947
SuiteCRM before 7.2.3 allows remote attackers to execute arbitrary code.... Read more
Affected Products : suitecrm- EPSS Score: %2.86
- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-3163
The admin pages for power types and key types in Beaker before 20.1 do not have any access controls, which allows remote authenticated users to modify power types and key types via navigating to $BEAKER/powertypes and $BEAKER/keytypes respectively.... Read more
Affected Products : beaker- EPSS Score: %0.46
- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1535
IBM Cognos Analytics 11.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sessi... Read more
Affected Products : cognos_analytics- EPSS Score: %0.27
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7855
In the webmail component in IceWarp Server 11.3.1.5, there was an XSS vulnerability discovered in the "language" parameter.... Read more
- EPSS Score: %0.54
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14076
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the id parameter to linksmanage.php in an editlink action.... Read more
Affected Products : nexusphp- EPSS Score: %0.25
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9978
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, a flaw was found with the error message sent as a response for users that don't exist on the system. An attacker could leverage this information to fine-tune and enumerate valid accounts on the ... Read more
Affected Products : quantastor- EPSS Score: %16.42
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12708
An Improper Restriction Of Operations Within The Bounds Of A Memory Buffer issue was discovered in Advantech WebAccess versions prior to V8.2_20170817. Researchers have identified multiple vulnerabilities that allow invalid locations to be referenced for ... Read more
Affected Products : webaccess- EPSS Score: %0.74
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-13778
Fiyo CMS 2.0.7 has XSS in dapur\apps\app_config\sys_config.php via the site_name parameter.... Read more
Affected Products : fiyo_cms- EPSS Score: %0.22
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13774
Hikvision iVMS-4200 devices before v2.6.2.7 allow local users to generate password-recovery codes via unspecified vectors.... Read more
Affected Products : ivms-4200- EPSS Score: %0.12
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-2977
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a malicious user to lower other users hands in the meeting. IBM X-Force ID: 113937.... Read more
Affected Products : sametime- EPSS Score: %0.24
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-2965
IBM Sametime Meeting Server 8.5.2 and 9.0 is vulnerable to cross-site request forgery, caused by improper validation of user-supplied input. By persuading a user to visit a malicious link, a remote attacker could force the user to log out of Sametime. IBM... Read more
Affected Products : sametime- EPSS Score: %0.15
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12775
qa-include/qa-install.php in Question2Answer before 1.7.5 allows remote attackers to create multiple user accounts.... Read more
Affected Products : question2answer- EPSS Score: %0.24
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2015-3653
Aruba Networks ClearPass Policy Manager before 6.4.7 and 6.5.x before 6.5.2 allows remote authenticated administrators to write to arbitrary files within the underlying operating system and consequently cause a denial of service or gain privileges by leve... Read more
Affected Products : clearpass- EPSS Score: %0.65
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2258
Directory traversal vulnerability in Cybozu Garoon 4.2.4 to 4.2.5 allows an attacker to read arbitrary files via Garoon SOAP API "WorkflowHandleApplications".... Read more
Affected Products : garoon- EPSS Score: %1.28
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025