Latest CVE Feed
-
9.8
CRITICALCVE-2016-6655
An issue was discovered in Cloud Foundry Foundation Cloud Foundry release versions prior to v245 and cf-mysql-release versions prior to v31. A command injection vulnerability was discovered in a common script used by many Cloud Foundry components. A malic... Read more
- EPSS Score: %4.68
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7665
In Apache NiFi before 0.7.4 and 1.x before 1.3.0, there are certain user input components in the UI which had been guarding for some forms of XSS issues but were insufficient.... Read more
Affected Products : nifi- EPSS Score: %1.06
- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-3618
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the... Read more
Affected Products : automatic_service_request- EPSS Score: %0.09
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2207
Untrusted search path vulnerability in the installer of SaAT Personal ver.1.0.10.272 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : personal- EPSS Score: %1.54
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2187
Cross-site scripting vulnerability in WP Live Chat Support prior to version 7.0.07 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : live_chat- EPSS Score: %0.29
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2165
GroupSession versions 4.6.4 and earlier allows remote authenticated attackers to bypass access restrictions to obtain sensitive information such as emails via unspecified vectors.... Read more
Affected Products : groupsession- EPSS Score: %0.27
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7833
Cybozu Dezie 8.0.0 to 8.1.1 allows remote attackers to bypass access restrictions to delete an arbitrary DBM (Cybozu Dezie proprietary format) file via unspecified vectors.... Read more
Affected Products : dezie- EPSS Score: %0.93
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7826
Directory traversal vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to read arbitrary files via specially crafted POST requests.... Read more
- EPSS Score: %4.27
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-7823
Cross-site scripting vulnerability in Buffalo WNC01WH devices with firmware version 1.0.0.8 and earlier allows authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.18
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7817
Cross-site scripting vulnerability in Simple keitai chat 2.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : simple_keitai_chat- EPSS Score: %0.23
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-7813
Cross-site scripting vulnerability in DERAEMON-CMS version 0.8.9 and earlier allows remote attackers to inject arbitrary web script or HTML via the parameters hostname, database and username.... Read more
Affected Products : deraemon-cms- EPSS Score: %0.32
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-7805
The mobiGate App for Android version 2.2.1.2 and earlier and mobiGate App for iOS version 2.2.4.1 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via... Read more
Affected Products : mobigate- EPSS Score: %0.26
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7802
Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %3.53
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4909
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.23
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4907
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.32
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-6098
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.... Read more
- EPSS Score: %0.14
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3634
The SlideshowPluginSlideshowStylesheet::loadStylesheetByAJAX function in the Slideshow plugin 2.2.8 through 2.2.21 for Wordpress allows remote attackers to read arbitrary Wordpress option values.... Read more
Affected Products : slideshow- EPSS Score: %2.07
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-5648
Acer Portal app before 3.9.4.2000 for Android does not properly validate SSL certificates, which allows remote attackers to perform a Man-in-the-middle attack via a crafted SSL certificate.... Read more
Affected Products : acer_portal- EPSS Score: %1.34
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-3108
The pulp-gen-nodes-certificate script in Pulp before 2.8.3 allows local users to leak the keys or write to arbitrary files via a symlink attack.... Read more
Affected Products : pulp- EPSS Score: %0.04
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2015-2253
The XML interface in Huawei OceanStor UDS devices with software before V100R002C01SPC102 allows remote authenticated users to obtain sensitive information via a crafted XML document.... Read more
- EPSS Score: %0.08
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025