Latest CVE Feed
-
5.4
MEDIUMCVE-2016-7509
Cross-site scripting (XSS) vulnerability in GLPI 0.90.4 allows remote authenticated attackers to inject arbitrary web script or HTML by attaching a crafted HTML file to a ticket.... Read more
Affected Products : glpi- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9764
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.17 allows remote attackers to inject arbitrary web script or HTML via the Client-IP or X-Forwarded-For HTTP header to /include/stat/stat.php in a para action.... Read more
Affected Products : metinfo- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6798
In the XSS Protection API module before 1.0.12 in Apache Sling, the method XSS.getValidXML() uses an insecure SAX parser to validate the input string, which allows for XXE attacks in all scripts which use this method to validate user input, potentially al... Read more
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1309
IBM InfoSphere Master Data Management Server 11.0 - 11.6 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 125463.... Read more
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11470
IDERA Uptime Monitor 7.8 has SQL injection in /gadgets/definitions/uptime.CapacityWhatifGadget/getxenmetrics.php via the element parameter.... Read more
Affected Products : uptime_infrastructure_monitor- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6531
On Televes COAXDATA GATEWAY 1Gbps devices doc-wifi-hgw_v1.02.0014 4.20, the backup/restore feature lacks access control, related to ReadFile.cgi and LoadCfgFile.... Read more
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9932
Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb has a default password of admin for the admin account.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-3886
libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.... Read more
Affected Products : libinfinity- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1373
Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.... Read more
Affected Products : tririga_application_platform- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7523
Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileg... Read more
Affected Products : cygwin- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-2276
Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.... Read more
- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11326
An issue was discovered in Tilde CMS 1.0.1. It is possible to bypass the implemented restrictions on arbitrary file upload via a filename.+php manipulation.... Read more
Affected Products : tilde_cms- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8975
IBM Rhapsody DM 5.0 and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted ses... Read more
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8919
NetApp OnCommand API Services before 1.2P3 logs the LDAP BIND password when a user attempts to log in using the REST API, which allows remote authenticated users to obtain sensitive password information via unspecified vectors.... Read more
Affected Products : oncommand_api_services- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6672
A vulnerability in certain filtering mechanisms of access control lists (ACLs) for Cisco ASR 5000 Series Aggregation Services Routers through 21.x could allow an unauthenticated, remote attacker to bypass ACL rules that have been configured for an affecte... Read more
Affected Products : asr_5000_series_software- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11674
Reporter.exe in Acunetix 8 allows remote attackers to cause a denial of service (application crash) via a malformed PRE file, related to a "Read Access Violation starting at reporter!madTraceProcess."... Read more
Affected Products : web_vulnerability_scanner- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11678
SQL injection vulnerability in Hashtopus 1.5g allows remote authenticated users to execute arbitrary SQL commands via the format parameter in admin.php.... Read more
Affected Products : hashtopus- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11685
Multiple Reflective cross-site scripting (XSS) vulnerabilities in search and display of event data in Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allow remote attackers to inject arbitrary web script or HTML, as demonstrated by the fName parameter.... Read more
Affected Products : manageengine_eventlog_analyzer- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11686
Zoho ManageEngine Event Log Analyzer 11.4 and 11.5 allows remote attackers to obtain an authenticated user's password via XSS vulnerabilities or sniffing non-SSL traffic on the network, because the password is represented in a cookie with a reversible enc... Read more
Affected Products : manageengine_eventlog_analyzer- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-11694
MEDHOST Document Management System contains hard-coded credentials that are used for Apache Solr access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with Apache Solr may be able to obtain or modify sens... Read more
Affected Products : medhost_document_management_system- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025