Latest CVE Feed
-
9.8
CRITICALCVE-2016-1557
Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-1556
Information disclosure in Netgear WN604 before 3.3.3; WNAP210, WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0; and WND930 before 2.0.11 allows remote attackers to read the wireless WPS PIN or passphrase by visiting unauthenticated webpages.... Read more
Affected Products : wnap320_firmware wnd930_firmware wn604_firmware wndap350_firmware wndap360_firmware wndap210v2_firmware wnap320 wndap350 wndap360 wndap210v2 +2 more products- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-1555
(1) boardData102.php, (2) boardData103.php, (3) boardDataJP.php, (4) boardDataNA.php, and (5) boardDataWW.php in Netgear WN604 before 3.3.3 and WN802Tv2, WNAP210v2, WNAP320, WNDAP350, WNDAP360, and WNDAP660 before 3.5.5.0 allow remote attackers to execute... Read more
Affected Products : wnap320_firmware wn604_firmware wndap660_firmware wndap350_firmware wndap360_firmware wndap210v2_firmware wn802tv2_firmware wnap320 wndap350 wndap360 +4 more products- Actively Exploited
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10091
Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function.... Read more
Affected Products : unrtf- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGH- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-0720
Cross-site request forgery (CSRF) vulnerability in pcsd web UI in pcs before 0.9.149.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7992
Heartland Payment Systems Payment Gateway PHP SDK hps/heartland-php v2.8.17 is vulnerable to a reflected XSS in examples/consumer-authentication/cruise.php via the URI, as demonstrated by the cavv parameter.... Read more
Affected Products : heartland-php- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-4846
Untrusted search path vulnerability in the installer of PhishWall Client Internet Explorer before 3.7.8.2.... Read more
Affected Products : phishwall_client- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4841
Cybozu Mailwise before 5.4.0 allows remote attackers to inject arbitrary email headers.... Read more
Affected Products : mailwise- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4840
Coordinate Plus App for Android 1.0.2 and earlier and Coordinate Plus App for iOS 1.0.2 and earlier do not verify SSL certificates.... Read more
Affected Products : coordinate_plus- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4832
WAON "Service Application" for Android 1.4.1 and earlier does not verify SSL certificates.... Read more
Affected Products : waon- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4830
Sushiro App for iOS 2.1.16 and earlier and Sushiro App for Android 2.1.16.1 and earlier do not verify SSL certificates.... Read more
Affected Products : sushiro- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4829
DMM Movie Player App for Android before 1.2.1, and DMM Movie Player App for iPhone/iPad before 2.1.3 does not verify SSL certificates.... Read more
Affected Products : ppv_play_player- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1194
Cybozu Garoon before 4.2.1 allows remote attackers to cause a denial of service.... Read more
Affected Products : garoon- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-1184
Tokyo Star bank App for Android before 1.4 and Tokyo Star bank App for iOS before 1.4 do not validate SSL certificates.... Read more
Affected Products : tokyo_star_bank- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-1148
Akerun - Smart Lock Robot App for iOS before 1.2.4 does not verify SSL certificates.... Read more
Affected Products : akerun- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-0833
Android allows users to cause a denial of service.... Read more
Affected Products : android- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7951
WonderCMS before 2.0.3 has CSRF because of lack of a token in an unspecified context.... Read more
Affected Products : wondercms- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7409
Palo Alto Networks PAN-OS before 7.0.15 has XSS in the GlobalProtect external interface via crafted request parameters, aka PAN-SA-2017-0011 and PAN-70674.... Read more
Affected Products : pan-os- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7220
OpenText Documentum Content Server allows superuser access via sys_obj_save or save of a crafted object, followed by an unauthorized "UPDATE dm_dbo.dm_user_s SET user_privileges=16" command, aka an "RPC save-commands" attack. NOTE: this vulnerability exis... Read more
Affected Products : documentum_content_server- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025