Latest CVE Feed
-
4.3
MEDIUMCVE-2016-1220
Cybozu Garoon before 4.2.2 does not properly restrict access.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-1218
SQL injection vulnerability in Cybozu Garoon before 4.2.2.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1219
Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.... Read more
Affected Products : garoon- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16244
Cross-Site Request Forgery exists in OctoberCMS 1.0.426 (aka Build 426) due to improper validation of CSRF tokens for postback handling, allowing an attacker to successfully take over the victim's account. The attack bypasses a protection mechanism involv... Read more
Affected Products : october- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-15643
An active network attacker (MiTM) can achieve remote code execution on a machine that runs IKARUS Anti Virus 2.16.7. IKARUS AV for Windows uses cleartext HTTP for updates along with a CRC32 checksum and an update value for verification of the downloaded f... Read more
Affected Products : ikarus_antivirus- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15989
Online Exam Test Application allows SQL Injection via the resources.php sort parameter in a category action.... Read more
Affected Products : online_exam_test_application- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-15933
SQL injection vulnerability vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the host parameter to module/capacity_per_device/index.php.... Read more
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15877
Insecure Permissions vulnerability in db.php file in GPWeb 8.4.61 allows remote attackers to view the password and user database.... Read more
Affected Products : gpweb- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-4689
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allows remote attackers to reset arbitrary passwords via unspecified vectors, aka "Weak Password Reset."... Read more
Affected Products : banner_student- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15788
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x0000000000002d83."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15727
In phpMyFAQ before 2.9.9, there is Stored Cross-site Scripting (XSS) via an HTML attachment.... Read more
Affected Products : phpmyfaq- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15639
tasks/feed/readRSS.cfm in Mura CMS before 6.2 allows attackers to bypass intended access restrictions by leveraging the "draggable feeds" feature.... Read more
Affected Products : mura_cms- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10363
Logstash versions prior to 2.3.3, when using the Netflow Codec plugin, a remote attacker crafting malicious Netflow v5, Netflow v9 or IPFIX packets could perform a denial of service attack on the Logstash instance. The errors resulting from these crafted ... Read more
Affected Products : logstash- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-10377
In Open vSwitch (OvS) 2.5.0, a malformed IP packet can cause the switch to read past the end of the packet buffer due to an unsigned integer underflow in `lib/flow.c` in the function `miniflow_extract`, permitting remote bypass of the access control list ... Read more
Affected Products : openvswitch- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-10295
An information disclosure vulnerability in the Qualcomm LED driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. Pro... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10292
A denial of service vulnerability in the Qualcomm Wi-Fi driver could enable a proximate attacker to cause a denial of service in the Wi-Fi subsystem. This issue is rated as High due to the possibility of remote denial of service. Product: Android. Version... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-10291
An elevation of privilege vulnerability in the Qualcomm Slimbus driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged p... Read more
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15384
rate-me.php in Rate Me 1.0 has XSS via the id field in a rate action.... Read more
Affected Products : rate_me- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1527
IBM Business Process Manager 7.5, 8.0, and 8.5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Fo... Read more
Affected Products : business_process_manager- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15213
Stored XSS vulnerability in Flyspray before 1.0-rc6 allows an authenticated user to inject JavaScript to gain administrator privileges, via the real_name or email_address field to themes/CleanFS/templates/common.editallusers.tpl.... Read more
Affected Products : flyspray- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025