Latest CVE Feed
-
5.3
MEDIUMCVE-2016-9467
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake ... Read more
- EPSS Score: %1.15
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-9464
Nextcloud Server before 9.0.54 and 10.0.0 suffers from an improper authorization check on removing shares. The Sharing Backend as implemented in Nextcloud does differentiate between shares to users and groups. In case of a received group share, users shou... Read more
Affected Products : nextcloud_server- EPSS Score: %0.37
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-9461
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are not properly verifying edit check permissions on WebDAV copy actions. The WebDAV endpoint was not properly checking the permission on a WebDAV COPY action. This allowed an authenticated att... Read more
- EPSS Score: %0.59
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9460
Nextcloud Server before 9.0.52 & ownCloud Server before 9.0.4 are vulnerable to a content-spoofing attack in the files app. The location bar in the files app was not verifying the passed parameters. An attacker could craft an invalid link to a fake direct... Read more
- EPSS Score: %0.41
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9457
Revive Adserver before 3.2.3 suffers from Reflected XSS. `www/admin/stats.php` is vulnerable to reflected XSS attacks via multiple parameters that are not properly sanitised or escaped when displayed, such as setPerPage, pageId, bannerid, period_start, pe... Read more
Affected Products : revive_adserver- EPSS Score: %0.30
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9455
Revive Adserver before 3.2.3 suffers from Cross-Site Request Forgery (CSRF). A number of scripts in Revive Adserver's user interface are vulnerable to CSRF attacks: `www/admin/banner-acl.php`, `www/admin/banner-activate.php`, `www/admin/banner-advanced.ph... Read more
Affected Products : revive_adserver- EPSS Score: %0.14
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9129
Revive Adserver before 3.2.3 suffers from Information Exposure Through Discrepancy. It is possible to check whether or not an email address was associated to one or more user accounts on a target Revive Adserver instance by examining the message printed b... Read more
Affected Products : revive_adserver- EPSS Score: %0.24
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9124
Revive Adserver before 3.2.3 suffers from Improper Restriction of Excessive Authentication Attempts. The login page of Revive Adserver is vulnerable to password-guessing attacks. An account lockdown feature was considered, but rejected to avoid introducin... Read more
Affected Products : revive_adserver- EPSS Score: %0.33
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9123
go-jose before 1.0.5 suffers from a CBC-HMAC integer overflow on 32-bit architectures. An integer overflow could lead to authentication bypass for CBC-HMAC encrypted ciphertexts on 32-bit architectures.... Read more
Affected Products : go-jose- EPSS Score: %0.23
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1142
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to set the secure flag for the session cookie in SSL mode. By intercepting its transmission within an HTTP session, an attac... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.18
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8960
IBM Cognos Business Intelligence 10.2 could allow a user with lower privilege Capabilities to adopt the Capabilities of a higher-privilege user by intercepting the higher-privilege user's cookie value from its HTTP request and then reusing it in subsequen... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.53
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6056
IBM Call Center for Commerce 9.3 and 9.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : call_center_for_commerce- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5239
Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitoring service, the Eview EV-07S GPS Tracker discloses personally identifying information, such as GPS data and IMEI numbers, to any man-in... Read more
- EPSS Score: %0.06
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7274
The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.... Read more
Affected Products : radare2- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7271
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen... Read more
- EPSS Score: %0.28
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6069
Subrion CMS 4.0.5 has CSRF in admin/blog/add/. The attacker can add any tag, and can optionally insert XSS via the tags parameter.... Read more
Affected Products : subrion_cms- EPSS Score: %0.21
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6068
Subrion CMS 4.0.5 has CSRF in admin/blocks/add/. The attacker can create any block, and can optionally insert XSS via the content parameter.... Read more
- EPSS Score: %0.21
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6971
AlienVault USM and OSSIM before 5.3.7 and NfSen before 1.3.8 allow remote authenticated users to execute arbitrary commands in a privileged context, or launch a reverse shell, via vectors involving the PHP session ID and the NfSen PHP code, aka AlienVault... Read more
- EPSS Score: %36.32
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6067
Symphony 2.6.9 has XSS in publish/notes/edit/##/saved/ via the bottom form field.... Read more
- EPSS Score: %0.23
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6013
Subrion CMS 4.0.5.10 has SQL injection in admin/database/ via the query parameter.... Read more
Affected Products : subrion_cms- EPSS Score: %0.57
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025