Latest CVE Feed
-
7.5
HIGHCVE-2017-1523
IBM InfoSphere Master Data Management - Collaborative Edition 11.5 could allow an unauthorized user to download reports without authentication. IBM X-Force ID: 129892.... Read more
Affected Products : infosphere_master_data_management- EPSS Score: %0.26
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1212
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.24
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1210
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.26
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3049
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. IBM X-Force... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.18
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15863
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.... Read more
Affected Products : wp_no_external_links- EPSS Score: %0.19
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15222
Buffer Overflow vulnerability in Ayukov NFTPD 2.0 and earlier allows remote attackers to execute arbitrary code.... Read more
Affected Products : nftp- EPSS Score: %81.59
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2013-3734
The Embedded Jopr component in JBoss Application Server includes the cleartext datasource password in unspecified HTML responses, which might allow (1) man-in-the-middle attackers to obtain sensitive information by leveraging failure to use SSL or (2) att... Read more
Affected Products : jboss_application_server- EPSS Score: %0.78
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2015-6839
The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physically proximate attackers to cast multiple votes for a candidate via a crafted RFID ballot tag.... Read more
Affected Products : vot.ar- EPSS Score: %0.07
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-5533
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE:... Read more
Affected Products : count_per_day- EPSS Score: %9.52
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-5379
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email attachment.... Read more
Affected Products : axigen_mail_server- EPSS Score: %0.10
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-2878
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/j... Read more
Affected Products : hawkeye_g- EPSS Score: %0.33
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2013-7377
The codem-transcode module before 0.5.0 for Node.js, when ffprobe is enabled, allows remote attackers to execute arbitrary commands via a POST request to /probe.... Read more
Affected Products : codem-transcode- EPSS Score: %1.27
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2012-4570
SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : letodms- EPSS Score: %0.57
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2012-4569
Multiple cross-site scripting (XSS) vulnerabilities in out/out.UsrMgr.php in LetoDMS (formerly MyDMS) before 3.3.9 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : letodms- EPSS Score: %0.34
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2012-4568
Multiple cross-site request forgery (CSRF) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to hijack the authentication of unspecified victims via unknown vectors.... Read more
Affected Products : letodms- EPSS Score: %0.15
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2012-4567
Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) inc/inc.ClassUI.php or (2) out/out.DocumentNotify.php.... Read more
Affected Products : letodms- EPSS Score: %0.26
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2011-4334
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.... Read more
Affected Products : labwiki- EPSS Score: %3.85
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2011-4333
Multiple cross-site scripting (XSS) vulnerabilities in LabWiki 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) from parameter to index.php or the (2) page_no parameter to recentchanges.php.... Read more
Affected Products : labwiki- EPSS Score: %0.33
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2011-2684
foo2zjs before 20110722dfsg-3ubuntu1 as packaged in Ubuntu, 20110722dfsg-1 as packaged in Debian unstable, and 20090908dfsg-5.1+squeeze0 as packaged in Debian squeeze create temporary files insecurely, which allows local users to write over arbitrary file... Read more
Affected Products : foo2zjs- EPSS Score: %0.07
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15810
The PopCash.Net Code Integration Tool plugin before 1.1 for WordPress has XSS via the tab parameter to wp-admin/admin.php.... Read more
Affected Products : popcash.net_code_integration_tool- EPSS Score: %0.24
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025