Latest CVE Feed
-
5.4
MEDIUMCVE-2016-6123
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : kenexa_lms_on_cloud- EPSS Score: %0.23
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6100
IBM Disposal and Governance Management for IT and IBM Global Retention Policy and Schedule Management, components of IBM Atlas Policy Suite 6.0.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthoriz... Read more
- EPSS Score: %0.15
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-6080
The WebAdmin context for WebSphere Message Broker allows directory listings which could disclose sensitive information to the attacker.... Read more
Affected Products : websphere_message_broker- EPSS Score: %0.19
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5964
IBM Security Privileged Identity Manager Virtual Appliance version 2.0.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials.... Read more
Affected Products : security_privileged_identity_manager- EPSS Score: %0.39
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-5942
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session... Read more
- EPSS Score: %0.22
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5818
An issue was discovered in Schneider Electric PowerLogic PM8ECC device 2.651 and older. Undocumented hard-coded credentials allow access to the device.... Read more
- EPSS Score: %0.38
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-5782
An issue was discovered in Locus Energy LGate prior to 1.05H, LGate 50, LGate 100, LGate 101, LGate 120, and LGate 320. Locus Energy meters use a PHP script to manage the energy meter parameters for voltage monitoring and network configuration. The PHP co... Read more
- EPSS Score: %0.88
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5727
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.... Read more
Affected Products : simple_machines_forum- EPSS Score: %0.60
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5401
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page.... Read more
- EPSS Score: %0.13
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5197
The content view client in Google Chrome prior to 54.0.2840.85 for Android insufficiently validated intent URLs, which allowed a remote attacker who had compromised the renderer process to start arbitrary activity on the system via a crafted HTML page.... Read more
Affected Products : chrome- EPSS Score: %0.62
- Published: Jan. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5077
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.... Read more
Affected Products : eventsentry- EPSS Score: %0.24
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-5069
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 use guessable session tokens, which are in the URL.... Read more
- EPSS Score: %0.03
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4931
XML entity injection in Junos Space before 15.2R2 allows attackers to cause a denial of service.... Read more
- EPSS Score: %0.27
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-4929
Command injection vulnerability in Junos Space before 15.2R2 allows attackers to execute arbitrary code as a root user.... Read more
- EPSS Score: %2.05
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4900
Untrusted search path vulnerability in Evernote for Windows versions prior to 6.3 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : evernote- EPSS Score: %0.42
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4873
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to execute unintended operations via the Project function.... Read more
Affected Products : office- EPSS Score: %0.28
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4872
Cybozu Office 9.0.0 to 10.4.0 allows remote authenticated attackers to bypass access restrictions to view the names of unauthorized projects via a breadcrumb trail.... Read more
Affected Products : office- EPSS Score: %0.22
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-4871
Cybozu Office 9.0.0 through 10.4.0 allows remote attackers to cause a denial of service.... Read more
Affected Products : office- EPSS Score: %1.51
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-4869
Cybozu Office 9.0.0 to 10.4.0 allow remote attackers to obtain session information via a page where CGI environment variables are displayed.... Read more
Affected Products : office- EPSS Score: %1.16
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4292
When opening a Hangul HShow Document (.hpt) and processing a structure within the document, Hancom Office 2014 will use a static size to allocate a heap buffer yet explicitly trust a size from the file when modifying data inside of it. Due to this, an agg... Read more
Affected Products : hancom_office_2014- EPSS Score: %0.46
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025