Latest CVE Feed
-
9.8
CRITICALCVE-2016-7789
SQL injection vulnerability in framework/core/models/expConfig.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the apikey parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7791
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload an evil 'exploit.tar.gz' file to the website, then extract it by visiting '/install/index.php?install_sample=../../files/exploit', which le... Read more
Affected Products : exponent_cms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-7790
Exponent CMS 2.3.9 suffers from a remote code execution vulnerability in /install/index.php. An attacker can upload 'php' file to the website through uploader_paste.php, then overwrite /framework/conf/config.php, which leads to arbitrary code execution.... Read more
Affected Products : exponent_cms- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-7150
Cross-site scripting (XSS) vulnerability in b2evolution 6.7.5 and earlier allows remote authenticated users to inject arbitrary web script or HTML via the site name.... Read more
Affected Products : b2evolution- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2016-6769
An elevation of privilege vulnerability in Smart Lock could enable a local malicious user to access Smart Lock settings without a PIN. This issue is rated as Moderate because it first requires physical access to an unlocked device where Smart Lock was the... Read more
Affected Products : android- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-6884
TLS cipher suites with CBC mode in TLS 1.1 and 1.2 in MatrixSSL before 3.8.3 allow remote attackers to cause a denial of service (out-of-bounds read) via a crafted message.... Read more
Affected Products : matrixssl- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6874
The array_*_recursive functions in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors, related to recursion.... Read more
Affected Products : hhvm- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6777
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6594
Blue Coat Advanced Secure Gateway 6.6, CacheFlow 3.4, ProxySG 6.5 and 6.6 allows remote attackers to bypass blocked requests, user authentication, and payload scanning.... Read more
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6125
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure w... Read more
Affected Products : kenexa_lms_on_cloud- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-6059
IBM InfoSphere Information Server is vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive information or consume a... Read more
Affected Products : infosphere_information_server infosphere_information_server_on_cloud infosphere_datastage- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6045
IBM Tivoli Storage Manager Operations Center is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts.... Read more
Affected Products : tivoli_storage_manager- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6022
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-5896
IBM Maximo Asset Management could disclose sensitive information from a stack trace after submitting incorrect login onto Cognos browser.... Read more
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2016-5894
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.... Read more
Affected Products : websphere_commerce- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-5862
When a control related to codec is issued from userspace in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, the type casting is done to the container structure instead of the codec's individual structure, resulting in a dev... Read more
Affected Products : android- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-5856
Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.... Read more
- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5054
OSRAM SYLVANIA Osram Lightify Home through 2016-07-26 allows Zigbee replay.... Read more
Affected Products : lightify_home- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-4898
The datamover module in the Linux version of NovaBACKUP DataCenter before 09.06.03.0353 is vulnerable to remote command execution via unspecified attack vectors.... Read more
Affected Products : novabackup_datacenter- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4875
Multiple cross-site scripting (XSS) vulnerabilities in the IVYWE (1) Assist plugin before 1.1.2.test20160906, (2) dataBox plugin before 0.0.0.20160906, and (3) userBox plugin before 0.0.0.20160906 for Geeklog allow remote attackers to inject arbitrary web... Read more
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025