Latest CVE Feed
-
6.5
MEDIUMCVE-2016-3027
IBM Security Access Manager for Web is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume... Read more
- EPSS Score: %0.56
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8931
IBM Kenexa LMS on Cloud could allow a remote attacker to upload arbitrary files, which could allow the attacker to execute arbitrary code on the vulnerable server.... Read more
- EPSS Score: %2.27
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-8999
IBM InfoSphere Information Server contains a Path-relative stylesheet import vulnerability that allows attackers to render a page in quirks mode thereby facilitating an attacker to inject malicious CSS.... Read more
Affected Products : infosphere_information_server infosphere_information_server_on_cloud infosphere_datastage- EPSS Score: %0.27
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-0310
IBM Connections 5.5 and earlier is vulnerable to possible host header injection attack that could cause navigation to the attacker's domain.... Read more
Affected Products : connections- EPSS Score: %0.26
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2016-9994
IBM Kenexa LCMS Premier on Cloud 9.0, and 10.0.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM Referen... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.16
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4950
Cloudera Manager 5.5 and earlier allows remote attackers to enumerate user sessions via a request to /api/v11/users/sessions.... Read more
Affected Products : manager- EPSS Score: %0.61
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0460
An elevation of privilege vulnerability in the Qualcomm networking driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privilege... Read more
- EPSS Score: %0.24
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-8479
An elevation of privilege vulnerability in the Qualcomm GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device co... Read more
- EPSS Score: %0.25
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8443
Possible unauthorized memory access in the hypervisor. Incorrect configuration provides access to subsystem page tables. Product: Android. Versions: Kernel 3.18. Android ID: A-32576499. References: QC-CR#964185.... Read more
- EPSS Score: %0.04
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-5554
An issue was discovered in ABOOT in OnePlus 3 and 3T OxygenOS before 4.0.2. The attacker can reboot the device into the fastboot mode, which could be done without any authentication. A physical attacker can press the "Volume Up" button during device boot,... Read more
- EPSS Score: %2.13
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2016-9039
An exploitable denial of service exists in the Joyent SmartOS 20161110T013148Z Hyprlofs file system. The vulnerability is present in the Ioctl system call with the command HYPRLOFS_ADD_ENTRIES. An attacker can cause a buffer to be allocated and never free... Read more
Affected Products : smartos- EPSS Score: %0.07
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-3614
Fortinet FortiManager 5.0.x before 5.0.11, 5.2.x before 5.2.2 allows remote attackers to obtain arbitrary files via vectors involving another unspecified vulnerability.... Read more
- EPSS Score: %0.32
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002009
Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.... Read more
Affected Products : membership_simplified- EPSS Score: %6.01
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9878
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at FPX!FPX_GetScanDevicePropertyGroup+0x00000... Read more
- EPSS Score: %0.39
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1000226
Stop User Enumeration 1.3.8 allows user enumeration via the REST API... Read more
Affected Products : stop_user_enumeration- EPSS Score: %0.42
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000221
In Opencast 2.2.3 and older if user names overlap, the Opencast search service used for publication to the media modules and players will handle the access control incorrectly so that users only need to match part of the user name used for the access rest... Read more
Affected Products : opencast- EPSS Score: %0.22
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000194
October CMS build 412 is vulnerable to Apache configuration modification via file upload functionality resulting in site compromise and possibly other applications on the server.... Read more
Affected Products : october- EPSS Score: %0.41
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-1000176
In SWFTools, a memcpy buffer overflow was found in swfc.... Read more
Affected Products : swftools- EPSS Score: %0.16
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1632
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
Affected Products : sterling_file_gateway- EPSS Score: %0.25
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2013-0870
The 'vp3_decode_frame' function in FFmpeg 1.1.4 moves threads check out of header packet type check.... Read more
Affected Products : ffmpeg- EPSS Score: %0.46
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025