Latest CVE Feed
-
6.5
MEDIUMCVE-2017-1142
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attac... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.18
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8960
IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequen... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.53
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6056
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : call_center_for_commerce- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5239
Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitoring service, the Eview EV-07S GPS Tracker discloses personally identifying information, such as GPS data and IMEI numbers, to any man-in... Read more
- EPSS Score: %0.06
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7274
The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.... Read more
Affected Products : radare2- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7271
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen... Read more
- EPSS Score: %0.28
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6069
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.... Read more
Affected Products : subrion_cms- EPSS Score: %0.21
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6068
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.... Read more
- EPSS Score: %0.21
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6971
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault... Read more
- EPSS Score: %36.32
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6067
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.... Read more
- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6013
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.... Read more
Affected Products : subrion_cms- EPSS Score: %0.57
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6003
dotCMS 3.7.0 has XSS reachable from ext/languages_manager/edit_language in portal/layout via the bottom two form fields.... Read more
Affected Products : dotcms- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6002
Subrion CMS 4.0.5.10 has CSRF in admin/blog/add/. The attacker can add any blog entry, and can optionally insert XSS into that entry via the body parameter.... Read more
Affected Products : subrion_cms- EPSS Score: %0.13
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2643
In Moodle 3.2.x, global search displays user names for unauthenticated users.... Read more
Affected Products : moodle- EPSS Score: %0.76
- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7266
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.... Read more
Affected Products : security_monkey- EPSS Score: %0.24
- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-10273
Multiple stack buffer overflow vulnerabilities in Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to execute arb... Read more
- EPSS Score: %2.30
- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7262
The AMD Ryzen processor with AGESA microcode through 2017-01-27 allows local users to cause a denial of service (system hang) via an application that makes a long series of FMA3 instructions, as demonstrated by the Flops test suite.... Read more
Affected Products : ryzen- EPSS Score: %0.06
- Published: Mar. 25, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-6206
Huawei AR3200 routers with software before V200R007C00SPC600 allow remote attackers to cause a denial of service or execute arbitrary code via a crafted packet.... Read more
- EPSS Score: %1.41
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7255
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.21
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7240
An issue was discovered on Miele Professional PST10 devices. The corresponding embedded webserver "PST10 WebServer" typically listens to port 80 and is prone to a directory traversal attack; therefore, an unauthenticated attacker may be able to exploit th... Read more
- EPSS Score: %32.66
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025