Latest CVE Feed
-
9.3
HIGHCVE-2017-6549
Session hijack vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, ... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-6548
Buffer overflows in networkmap on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900P, RT-N300, and RT-... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6547
Cross-site scripting (XSS) vulnerability in httpd on ASUS RT-N56U, RT-N66U, RT-AC66U, RT-N66R, RT-AC66R, RT-AC68U, RT-AC68R, RT-N66W, RT-AC66W, RT-AC87R, RT-AC87U, RT-AC51U, RT-AC68P, RT-N11P, RT-N12+, RT-N12E B1, RT-AC3200, RT-AC53U, RT-AC1750, RT-AC1900... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6544
Gargaj/wuhu through 2017-03-08 is vulnerable to a reflected XSS in wuhu-master/www_admin/users.php (id parameter).... Read more
Affected Products : wuhu- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-6543
Tenable Nessus before 6.10.2 (as used alone or in Tenable Appliance before 4.5.0) was found to contain a flaw that allowed a remote, authenticated attacker to upload a crafted file that could be written to anywhere on the system. This could be used to sub... Read more
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-1150
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 could allow an authenticated attacker with specialized access to tables that they should not be permitted to view. IBM Reference #: 1999515.... Read more
Affected Products : db2- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9985
IBM Cognos Server 10.1.1 and 10.2 stores highly sensitive information in log files that could be read by a local user. IBM Reference #: 1999671.... Read more
Affected Products : cognos_business_intelligence- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-9006
IBM UrbanCode Deploy 6.1 and 6.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a truste... Read more
Affected Products : urbancode_deploy- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2016-5933
IBM Tivoli Monitoring 6.2 and 6.3 is vulnerable to possible host header injection attack that could lead to HTTP cache poisoning or firewall bypass. IBM Reference #: 1997223.... Read more
Affected Products : tivoli_monitoring- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2016-5894
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 is vulnerable to information disclosure vulnerability. A local user could view a plain text password in a Unix console. IBM Reference #: 1997408.... Read more
Affected Products : websphere_commerce- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6541
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/viewtest.php URL. An attacker c... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6540
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (configs) passed to the webpagetest-master/www/benchmarks/compare.php URL. An attacker could exec... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6539
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/delta.php URL. An attacker coul... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6538
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (video) passed to the webpagetest-master/www/speedindex/index.php URL. An attacker could execute arbitrary ... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6537
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (bgcolor) passed to the webpagetest-master/www/video/view.php URL. An attacker could execute arbitrary HTML... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6536
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (url, pssid) passed to the webpagetest-master/www/weblite.php URL. An attacker could execute arbi... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6535
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, url) passed to the webpagetest-master/www/benchmarks/trendurl.php URL. An attacker co... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6534
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (pssid) passed to the webpagetest-master/www/pss.php URL. An attacker could execute arbitrary HTML and scri... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6533
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (benchmark) passed to the webpagetest-master/www/benchmarks/view.php URL. An attacker could execute arbitra... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5178
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is difficult... Read more
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025