Latest CVE Feed
-
6.1
MEDIUMCVE-2015-3998
Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php.... Read more
- EPSS Score: %0.17
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-1894
NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.... Read more
Affected Products : oncommand_workflow_automation- EPSS Score: %0.41
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-8494
Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.... Read more
Affected Products : connect- EPSS Score: %1.14
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-10206
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user ac... Read more
Affected Products : zoneminder- EPSS Score: %0.13
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8940
IBM Tivoli Storage Manager (IBM Spectrum Protect) 6.1, 6.2, 6.3, and 7.1 does not perform sufficient authority checking on SQL queries. As a result, an attacker is able to submit SQL queries that access database tables that are not intended for access or ... Read more
Affected Products : tivoli_storage_manager- EPSS Score: %0.32
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9728
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.26
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2013-7462
A directory traversal vulnerability in the web application in McAfee (now Intel Security) SaaS Control Console (SCC) Platform 6.14 before patch 1070, and 6.15 before patch 1076 allows unauthenticated users to view contents of arbitrary system files that d... Read more
Affected Products : saas_control_console_platform- EPSS Score: %2.32
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-6756
An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requir... Read more
- EPSS Score: %0.23
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-8213
EMC Documentum WebTop Version 6.8, prior to P18 and Version 6.8.1, prior to P06; and EMC Documentum TaskSpace version 6.7SP3, prior to P02; and EMC Documentum Capital Projects Version 1.9, prior to P30 and Version 1.10, prior to P17; and EMC Documentum Ad... Read more
Affected Products : documentum_administrator documentum_webtop documentum_taskspace documentum_capital_projects- EPSS Score: %0.25
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-0356
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.... Read more
Affected Products : sametime- EPSS Score: %0.26
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1449
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL ... Read more
Affected Products : emptoris_sourcing- EPSS Score: %0.08
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14406
A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.... Read more
Affected Products : mp3gain- EPSS Score: %0.24
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14396
In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.... Read more
Affected Products : osticket- EPSS Score: %1.72
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1431
IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : infosphere_streams- EPSS Score: %0.24
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-14263
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can l... Read more
- EPSS Score: %24.42
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14242
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.... Read more
- EPSS Score: %0.34
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14238
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.... Read more
- EPSS Score: %0.34
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14081
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.... Read more
Affected Products : mobile_security- EPSS Score: %13.34
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14070
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.... Read more
Affected Products : nexusphp- EPSS Score: %0.24
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14036
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.... Read more
Affected Products : crushftp- EPSS Score: %0.20
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025