Latest CVE Feed
-
7.5
HIGHCVE-2016-1000032
TGCaptcha2 version 0.3.0 is vulnerable to a replay attack due to a missing nonce allowing attackers to use a single solved CAPTCHA multiple times.... Read more
Affected Products : tgcaptcha2- EPSS Score: %0.58
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-1000031
Apache Commons FileUpload before 1.3.3 DiskFileItem File Manipulation Remote Code Execution... Read more
Affected Products : commons_fileupload- EPSS Score: %50.09
- Published: Oct. 25, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0377
The Administrative Console in IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.x before 8.0.0.13, and 8.5.x before 8.5.5.10 mishandles CSRFtoken cookies, which allows remote authenticated users to obtain sensitive information via unspecifie... Read more
Affected Products : websphere_application_server- EPSS Score: %0.29
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0328
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain administrator privileges for command execution via unspecified vectors.... Read more
Affected Products : security_guardium_database_activity_monitor- EPSS Score: %0.14
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-0326
IBM Rational Quality Manager (RQM) and Rational Collaborative Lifecycle Management 3.0.1.6 before iFix8, 4.x before 4.0.7 iFix11, 5.x before 5.0.2 iFix17, and 6.x before 6.0.1 ifix3 allow remote authenticated users to execute arbitrary OS commands via a c... Read more
- EPSS Score: %0.89
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-0247
IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows local users to obtain sensitive cleartext information via unspecified vectors, as demonstrated by password information.... Read more
- EPSS Score: %0.04
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
6.1
MEDIUMCVE-2016-0246
Cross-site scripting (XSS) vulnerability in IBM Security Guardium 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.... Read more
- EPSS Score: %0.22
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0242
IBM Security Guardium 10.x through 10.1 before p100 allows remote authenticated users to obtain sensitive information by reading an Application Error message.... Read more
- EPSS Score: %0.16
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-0241
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to spoof administrator accounts by sending a modified login request over HTTP.... Read more
Affected Products : security_guardium_database_activity_monitor- EPSS Score: %0.57
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0240
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 does not enable the HSTS protection mechanism, which makes it easier for remote attackers to obtain sensitive information by le... Read more
Affected Products : security_guardium_database_activity_monitor- EPSS Score: %0.17
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-0239
IBM Security Guardium Database Activity Monitor 9.x through 9.5 before p700 and 10.x through 10.0.1 before p100 allows remote authenticated users to make HTTP requests with administrator privileges via unspecified vectors.... Read more
Affected Products : security_guardium_database_activity_monitor- EPSS Score: %0.72
- Published: Oct. 22, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-7854
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %5.09
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-7853
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %5.32
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
10.0
HIGHCVE-2016-7852
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service... Read more
- EPSS Score: %5.09
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-0236
IBM Security Guardium Database Activity Monitor 8.2 before p310, 9.x through 9.5 before p700, and 10.x through 10.1 before p100 allows remote authenticated users to execute arbitrary commands with root privileges via the search field.... Read more
Affected Products : security_guardium_database_activity_monitor- EPSS Score: %2.99
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGHCVE-2016-1000119
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla... Read more
Affected Products : catalog- EPSS Score: %2.04
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGH- EPSS Score: %2.04
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGH- EPSS Score: %2.04
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGH- EPSS Score: %0.40
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025
-
7.2
HIGH- EPSS Score: %0.79
- Published: Oct. 21, 2016
- Modified: Apr. 12, 2025