Latest CVE Feed
-
7.5
HIGHCVE-2016-1556
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.... Read more
Affected Products : wnap320_firmware wnd930_firmware wn604_firmware wndap350_firmware wndap360_firmware wndap210v2_firmware wnap320 wndap350 wndap360 wndap210v2 +2 more products- EPSS Score: %0.96
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1194
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.... Read more
Affected Products : garoon- EPSS Score: %0.82
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1184
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.... Read more
Affected Products : tokyo_star_bank- EPSS Score: %0.23
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1148
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.... Read more
Affected Products : akerun- EPSS Score: %0.46
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7220
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exis... Read more
Affected Products : documentum_content_server- EPSS Score: %0.67
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-6615
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when ... Read more
Affected Products : ios_xe- EPSS Score: %0.45
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-4969
The Cloud Controller in Cloud Foundry cf-release versions prior to v255 allows authenticated developer users to exceed memory and disk quotas for tasks.... Read more
Affected Products : cf-release- EPSS Score: %0.38
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-1122
IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.... Read more
Affected Products : security_guardium- EPSS Score: %0.05
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9979
IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.26
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-9978
IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.20
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2806
An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 1... Read more
Affected Products : perceptive_document_filters- EPSS Score: %0.16
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4862
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.... Read more
Affected Products : cs-cart- EPSS Score: %2.43
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-4850
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.... Read more
Affected Products : line- EPSS Score: %2.94
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4842
Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.... Read more
Affected Products : mailwise- EPSS Score: %0.36
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-1216
Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.... Read more
Affected Products : garoon- EPSS Score: %0.34
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-1214
Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2.... Read more
Affected Products : garoon- EPSS Score: %0.35
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-1213
The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.... Read more
Affected Products : garoon- EPSS Score: %0.38
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5762
Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.... Read more
Affected Products : groupwise- EPSS Score: %14.84
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5409
Red Hat OpenShift Enterprise 2 does not include the HTTPOnly flag in a Set-Cookie header for the GEARID cookie, which makes it easier for remote attackers to obtain potentially sensitive information via script access to the cookies.... Read more
- EPSS Score: %0.23
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4847
Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.... Read more
Affected Products : web_ui- EPSS Score: %0.51
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025