Latest CVE Feed
-
5.9
MEDIUMCVE-2016-4832
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.... Read more
Affected Products : waon- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4830
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.... Read more
Affected Products : sushiro- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4829
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.... Read more
Affected Products : ppv_play_player- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1194
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.... Read more
Affected Products : garoon- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1184
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.... Read more
Affected Products : tokyo_star_bank- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1148
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.... Read more
Affected Products : akerun- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-0833
Android allows users to cause a denial of service.... Read more
Affected Products : android- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7951
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.... Read more
Affected Products : wondercms- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7409
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.... Read more
Affected Products : pan-os- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7220
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exis... Read more
Affected Products : documentum_content_server- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4075
Opera Mini 13 and Opera Stable 36 allow remote attackers to spoof the displayed URL via a crafted HTML document, related to the about:blank URL.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7990
The Reporting Module 1.12.0 for OpenMRS allows CSRF attacks with resultant XSS, in which administrative authentication is hijacked to insert JavaScript into a name field in webapp/reports/manageReports.jsp.... Read more
Affected Products : openmrs_module_reporting- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6619
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary commands on an affected system. The vulnerability exists because the affected software does not... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6618
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to perform a cross-site scripting (XSS) attack. The vulnerability is due to insufficient validation of user-supplied... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6617
A vulnerability in the session identification management functionality of the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an unauthenticated, remote attacker to hijack a valid user session on an affected system. The v... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6616
A vulnerability in the web-based GUI of Cisco Integrated Management Controller (IMC) 3.0(1c) could allow an authenticated, remote attacker to execute arbitrary code on an affected system. The vulnerability exists because the affected software does not suf... Read more
Affected Products : integrated_management_controller_supervisor- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-6615
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem of Cisco IOS XE 3.16 could allow an authenticated, remote attacker to cause a denial of service (DoS) condition. The vulnerability is due to a race condition that could occur when ... Read more
Affected Products : ios_xe- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-6614
A vulnerability in the file-download feature of the web user interface for Cisco FindIT Network Probe Software 1.0.0 could allow an authenticated, remote attacker to download and view any system file by using the affected software. The vulnerability is du... Read more
Affected Products : findit_network_probe- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-6613
A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the aff... Read more
Affected Products : prime_network_registrar- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6611
A vulnerability in the web framework code of Cisco Prime Infrastructure 2.2(2) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against the user of the web interface of the affected system. The vulnerability i... Read more
Affected Products : prime_infrastructure- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025