Latest CVE Feed
-
6.1
MEDIUMCVE-2016-9405
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-2046
Cross-site scripting (XSS) vulnerability in MantisBT 1.2.13 and later before 1.2.20.... Read more
Affected Products : mantisbt- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1612
OpenFlow plugin for OpenDaylight before Helium SR3 allows remote attackers to spoof the SDN topology and affect the flow of data, related to the reuse of LLDP packets, aka "LLDP Relay."... Read more
Affected Products : openflow- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-8794
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-8792
Huawei Mate 8 phones with software Versions before NXT-AL10C00B386, Versions before NXT-CL00C92B386, Versions before NXT-DL00C17B386, Versions before NXT-TL00C01B386; Mate S phones with software Versions before CRR-CL00C92B368, Versions before CRR-CL20C92... Read more
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14011
A Cross-Site Request Forgery issue was discovered in ProMinent MultiFLEX M10a Controller web interface. The application does not sufficiently verify requests, making it susceptible to cross-site request forgery. This may allow an attacker to execute unaut... Read more
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-2685
Siemens SINUMERIK Integrate Operate Clients between 2.0.3.00.016 (including) and 2.0.6 (excluding) and between 3.0.4.00.032 (including) and 3.0.6 (excluding) contain a vulnerability that could allow an attacker to read and manipulate data in TLS sessions ... Read more
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-0575
In all Qualcomm products with Android releases from CAF using the Linux kernel, insecure ciphersuites were included in the default configuration.... Read more
Affected Products : android- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-0904
The Restaurant Karaoke SHIDAX app 1.3.3 and earlier on Android does not verify SSL certificates, which allows remote attackers to obtain sensitive information via a man-in-the-middle attack.... Read more
Affected Products : restaurant_karaoke- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-15357
The setpermissions function in the auto-updater in Arq before 5.9.7 for Mac allows local users to gain root privileges via a symlink attack on the updater binary itself.... Read more
Affected Products : arq- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-7801
Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors.... Read more
Affected Products : garoon- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1530
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : business_process_manager- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15242
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to a "User Mode Write AV starting at PDF!xmlGetGlobalState+0x0000000000031abe."... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12777
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via some parameter to usersearch.php.... Read more
Affected Products : nexusphp- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-12732
A Stack-based Buffer Overflow issue was discovered in GE CIMPLICITY Versions 9.0 and prior. A function reads a packet to indicate the next packet length. The next packet length is not verified, allowing a buffer overwrite that could lead to an arbitrary r... Read more
Affected Products : intelligent_platforms_proficy_hmi\/scada_cimplicity- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-8393
DLL Hijacking vulnerability in CorelDRAW X7, Corel Photo-Paint X7, Corel PaintShop Pro X7, Corel Painter 2015, and Corel PDF Fusion.... Read more
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4857
Open redirect vulnerability in Splunk Enterprise 6.4.x prior to 6.4.2, Splunk Enterprise 6.3.x prior to 6.3.6, Splunk Enterprise 6.2.x prior to 6.2.11 and Splunk Light prior to 6.4.2 allows to redirect users to arbitrary web sites and conduct phishing att... Read more
Affected Products : splunk- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-9515
Dozer improperly uses a reflection-based approach to type conversion, which might allow remote attackers to execute arbitrary code via a crafted serialized object.... Read more
Affected Products : dozer- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8142
The Trusted Execution Environment (TEE) module driver of Mate 9 and Mate 9 Pro smart phones with software versions earlier than MHA-AL00BC00B221 and versions earlier than LON-AL00BC00B221 has a use after free (UAF) vulnerability. An attacker tricks a user... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2284
Cross-site scripting vulnerability in Popup Maker prior to version 1.6.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : popup_maker- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025