Latest CVE Feed
-
10.0
HIGHCVE-2016-10182
An issue was discovered on the D-Link DWR-932B router. qmiweb allows command injection with ` characters.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6605
Impala in CDH 5.2.0 through 5.7.2 and 5.8.0 allows remote attackers to bypass Setry authorization.... Read more
Affected Products : cdh- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6603
ZOHO WebNMS Framework 5.2 and 5.2 SP1 allows remote attackers to bypass authentication and impersonate arbitrary users via the UserName HTTP header.... Read more
Affected Products : webnms_framework- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7237
The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of the TFTP service for all clients who can reach UDP port 69... Read more
Affected Products : spiceworks- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2016-6111
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informati... Read more
Affected Products : curam_social_program_management- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6096
IBM Tivoli Key Lifecycle Manager 2.0.1, 2.5, and 2.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo... Read more
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-14331
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to bypass the "exsh restricted shell" protection mechanism and obtain an interactive shell.... Read more
Affected Products : extremexos- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-5860
In an audio driver in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a function is called with a very large length, an integer overflow could occur followed by a heap buffer overflow.... Read more
Affected Products : android- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3584
Vulnerability in the Sun ZFS Storage Appliance Kit (AK) component of Oracle Sun Systems Products Suite (subcomponent: RAS subsystems). The supported version that is affected is AK 2013. Difficult to exploit vulnerability allows low privileged attacker wit... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5811
An issue was discovered in Visonic PowerLink2, all versions prior to October 2016 firmware release. User controlled input is not neutralized prior to being placed in web page output (CROSS-SITE SCRIPTING).... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-3535
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.1, 12.0.2 and 12.0.3. Easily "exploitable" vulnerabili... Read more
Affected Products : flexcube_universal_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5754
Presence of a .htaccess file could leak information in NetIQ Access Manager 4.1 before 4.1.2 Hot Fix 1 and 4.2 before SP2.... Read more
Affected Products : access_manager- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-3493
Vulnerability in the Oracle FLEXCUBE Enterprise Limits and Collateral Management component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 12.0.0 and 12.1.0. Easily "exploitable" vulnerabi... Read more
Affected Products : flexcube_enterprise_limits_and_collateral_management- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-3485
Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent: Infrastructure). Supported versions that are affected are 11.3.0, 11.4.0, 12.0.0, 12.0.1, 12.0.2, 12.0.3, 12.1.0 and 12.2.0. Difficul... Read more
Affected Products : flexcube_universal_banking- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-3245
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Pre-Login). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows unauthenticated attacker... Read more
Affected Products : flexcube_direct_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-5059
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application.... Read more
Affected Products : lightify_pro- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5055
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.... Read more
Affected Products : lightify_pro- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6042
IBM AppScan Enterprise Edition could allow a remote attacker to execute arbitrary code on the system, caused by improper handling of objects in memory. By persuading a victim to open specially-crafted content, an attacker could exploit this vulnerability ... Read more
Affected Products : security_appscan- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4928
Cross site request forgery vulnerability in Junos Space before 15.2R2 allows remote attackers to perform certain administrative actions on Junos Space.... Read more
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2017-2882
An exploitable vulnerability exists in the servers update functionality of Circle with Disney running firmware 2.0.1. Specially crafted network packets can cause the device to overwrite sensitive files, resulting in code execution. An attacker needs to im... Read more
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025