Latest CVE Feed
-
5.4
MEDIUMCVE-2016-3054
Cross-site scripting (XSS) vulnerability in IBM FileNet Workplace 4.0.2 allows remote authenticated users to inject arbitrary web script or HTML by uploading a file.... Read more
Affected Products : filenet_workplace- EPSS Score: %0.17
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-2989
Open redirect vulnerability in the Connections Portlets component 5.x before 5.0.2 for IBM WebSphere Portal allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.... Read more
Affected Products : connections_portlets- EPSS Score: %0.31
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-2960
IBM WebSphere Application Server (WAS) 7.x before 7.0.0.43, 8.0.0.x before 8.0.0.13, 8.5.0.x before 8.5.5.10, 8.5.0.x and 16.0.0.x Liberty before Liberty Fix Pack 16.0.0.3, and 9.0.0.x before 9.0.0.1 allows remote attackers to cause a denial of service vi... Read more
Affected Products : websphere_application_server- EPSS Score: %0.68
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2925
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 6.1.0.x through 6.1.0.6 CF27, 6.1.5.x through 6.1.5.3 CF27, 7.x through 7.0.0.2 CF30, 8.0.0.x through 8.0.0.1 CF21, and 8.5.0 before CF10 allows remote authenticated users to inject arbitrar... Read more
Affected Products : websphere_portal- EPSS Score: %0.20
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.5
MEDIUMCVE-2016-2914
Unrestricted file upload vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to execute arbitrary code by specifying an unexpected file extension.... Read more
- EPSS Score: %1.13
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-2912
Cross-site scripting (XSS) vulnerability in the Document Builder in IBM Rational Publishing Engine (aka RPENG) 2.0.1 before ifix002 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.... Read more
- EPSS Score: %0.17
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-2875
IBM Security QRadar SIEM 7.1.x and 7.2.x before 7.2.7 allows remote authenticated users to execute arbitrary OS commands as root via unspecified vectors.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %1.22
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
3.3
LOWCVE-2016-0380
IBM Sterling Connect:Direct for Unix 4.1.0 before 4.1.0.4 iFix073 and 4.2.0 before 4.2.0.4 iFix003 uses default file permissions of 0664, which allows local users to obtain sensitive information via standard filesystem operations.... Read more
Affected Products : sterling_connect\- EPSS Score: %0.04
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
6.5
MEDIUMCVE-2016-0361
IBM General Parallel File System (GPFS) 3.5 before 3.5.0.29 efix 6 and 4.1.1 before 4.1.1.4 efix 9, when the Spectrum Scale GUI is used with DB2 on Linux, UNIX and Windows, allows remote authenticated users to obtain sensitive information via unspecified ... Read more
Affected Products : general_parallel_file_system- EPSS Score: %0.32
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0281
The mustendd driver in IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x, when the jumbo_frames feature is not enabled, allows remote attackers to cause a denial of service (FC1763 or FC5899 adapter crash) via crafted packets.... Read more
- EPSS Score: %2.82
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
5.4
MEDIUMCVE-2016-0280
Cross-site scripting (XSS) vulnerability in IBM Information Server Framework 8.5, Information Server Framework and InfoSphere Information Server Business Glossary 8.7 before FP2, Information Server Framework and InfoSphere Information Server Business Glos... Read more
- EPSS Score: %0.15
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-0266
IBM AIX 5.3, 6.1, 7.1, and 7.2 and VIOS 2.2.x do not default to the latest TLS version, which makes it easier for man-in-the-middle attackers to obtain sensitive information via unspecified vectors.... Read more
- EPSS Score: %0.70
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-6486
Siemens SINEMA Server uses weak permissions for the application folder, which allows local users to gain privileges via unspecified vectors.... Read more
Affected Products : sinema_server- EPSS Score: %0.07
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5792
SQL injection vulnerability in Moxa SoftCMS before 1.5 allows remote attackers to execute arbitrary SQL commands via unspecified fields.... Read more
Affected Products : softcms- EPSS Score: %1.70
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
7.7
HIGHCVE-2016-4374
HPE Release Control (RC) 9.13, 9.20, and 9.21 before 9.21.0005 p4 allows remote authenticated users to conduct server-side request forgery (SSRF) attacks, and consequently obtain sensitive information or cause a denial of service, via unspecified vectors.... Read more
Affected Products : release_control- EPSS Score: %0.22
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1478
Cisco IOS 15.5(3)S3, 15.6(1)S2, 15.6(2)S1, and 15.6(2)T1 does not properly dequeue invalid NTP packets, which allows remote attackers to cause a denial of service (interface wedge) by sending many crafted NTP packets, aka Bug ID CSCva35619.... Read more
Affected Products : ios- EPSS Score: %0.74
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
4.3
MEDIUMCVE-2016-1474
Cisco Prime Infrastructure 2.2(2) does not properly restrict use of IFRAME elements, which makes it easier for remote attackers to conduct clickjacking attacks and unspecified other attacks via a crafted web site, related to a "cross-frame scripting (XFS)... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.43
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
8.8
HIGHCVE-2016-1468
The administrative web interface in Cisco TelePresence Video Communication Server Expressway X8.5.2 allows remote authenticated users to execute arbitrary commands via crafted fields, aka Bug ID CSCuv12531.... Read more
- EPSS Score: %0.67
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
7.8
HIGHCVE-2016-1466
Cisco Unified Communications Manager IM and Presence Service 9.1(1) SU6, 9.1(1) SU6a, 9.1(1) SU7, 10.5(2) SU2, 10.5(2) SU2a, 11.0(1) SU1, and 11.5(1) allows remote attackers to cause a denial of service (sipd process restart) via crafted headers in a SIP ... Read more
Affected Products : unified_communications_manager_im_and_presence_service- EPSS Score: %1.34
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025
-
9.0
HIGHCVE-2016-1430
Cisco RV180 and RV180W devices allow remote authenticated users to execute arbitrary commands as root via a crafted HTTP request, aka Bug ID CSCuz48592.... Read more
Affected Products : rv180_vpn_router_firmware rv180w_vpn_router_firmware rv180_vpn_router rv180w_vpn_router- EPSS Score: %0.26
- Published: Aug. 08, 2016
- Modified: Apr. 12, 2025