Latest CVE Feed
-
8.8
HIGHCVE-2016-8917
IBM Sterling Order Management 9.2 - 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM Reference #: 2000943.... Read more
Affected Products : sterling_selling_and_fulfillment_foundation- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2016-6111
IBM Curam Social Program Management 6.0 and 7.0 are vulnerable to a denial of service, caused by an XML External Entity Injection (XXE) error when processing XML data. A remote attacker could exploit this vulnerability to expose highly sensitive informati... Read more
Affected Products : curam_social_program_management- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6036
IBM Rational Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6031
IBM Rational Quality Manager 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure ... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-6022
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3010
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable memory corruption vulnerability in the rendering engine. Successful exploitation could lead to arbitrary code execution.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3009
Adobe Acrobat Reader versions 15.020.20042 and earlier, 15.006.30244 and earlier, 11.0.18 and earlier have an exploitable buffer overflow vulnerability in the JPEG2000 parser. Successful exploitation could lead to information disclosure.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6209
Cross-site scripting (XSS) vulnerability in Nagios.... Read more
Affected Products : nagios- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGH- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2014-9114
Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-5009
Snoopy allows remote attackers to execute arbitrary commands. NOTE: this vulnerability exists due to an incomplete fix for CVE-2014-5008.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICAL- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-3931
fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.... Read more
Affected Products : multi-router_looking_glass- Actively Exploited
- Published: Mar. 31, 2017
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2008-7313
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7363
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7362
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7361
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7359
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-7309
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, ... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025