Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-5960 | 1 Ibm | 1 Security Privileged Identity Manager | 2017-06-13 | 2.1 LOW | 5.5 MEDIUM |
IBM Security Privileged Identity Manager 2.0.2 and 2.1.0 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 116171. | |||||
CVE-2017-9437 | 1 Openbravo | 1 Openbravo Erp | 2017-06-13 | 6.5 MEDIUM | 8.8 HIGH |
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code. | |||||
CVE-2017-9517 | 1 Atmail | 1 Atmail | 2017-06-13 | 6.8 MEDIUM | 8.8 HIGH |
atmail before 7.8.0.2 has CSRF, allowing an attacker to upload and import users via CSV. | |||||
CVE-2017-9518 | 1 Atmail | 1 Atmail | 2017-06-13 | 6.8 MEDIUM | 8.8 HIGH |
atmail before 7.8.0.2 has CSRF, allowing an attacker to change the SMTP hostname and hijack all emails. | |||||
CVE-2017-9519 | 1 Atmail | 1 Atmail | 2017-06-13 | 6.8 MEDIUM | 8.8 HIGH |
atmail before 7.8.0.2 has CSRF, allowing an attacker to create a user account. | |||||
CVE-2016-4909 | 1 Cybozu | 1 Garoon | 2017-06-13 | 4.3 MEDIUM | 4.3 MEDIUM |
Cross-site request forgery (CSRF) vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to hijack the authentication of a logged in user to force a logout via unspecified vectors. | |||||
CVE-2016-4910 | 1 Cybozu | 1 Garoon | 2017-06-13 | 4.0 MEDIUM | 4.3 MEDIUM |
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to delete other operational administrators' MultiReport filters via unspecified vectors. | |||||
CVE-2016-7801 | 1 Cybozu | 1 Garoon | 2017-06-13 | 4.0 MEDIUM | 4.3 MEDIUM |
Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to bypass access restrictions to delete other users' To-Dos via unspecified vectors. | |||||
CVE-2016-4907 | 1 Cybozu | 1 Garoon | 2017-06-13 | 6.8 MEDIUM | 8.8 HIGH |
Cybozu Garoon 3.0.0 to 4.2.2 allow remote attackers to obtain CSRF tokens via unspecified vectors. | |||||
CVE-2016-4906 | 1 Cybozu | 1 Garoon | 2017-06-13 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote attackers to inject arbitrary web script or HTML via "Messages" function of Cybozu Garoon Keitai. | |||||
CVE-2016-4908 | 1 Cybozu | 1 Garoon | 2017-06-13 | 4.0 MEDIUM | 4.3 MEDIUM |
Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to bypass access restriction to alter or delete another user's private RSS settings via unspecified vectors. | |||||
CVE-2016-7802 | 1 Cybozu | 1 Garoon | 2017-06-13 | 4.0 MEDIUM | 6.5 MEDIUM |
Directory traversal vulnerability in Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to read arbitrary files via unspecified vectors. | |||||
CVE-2016-7803 | 1 Cybozu | 1 Garoon | 2017-06-13 | 6.5 MEDIUM | 8.8 HIGH |
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function. | |||||
CVE-2016-9156 | 1 Siemens | 1 Sicam Pas | 2017-06-12 | 7.5 HIGH | 7.3 HIGH |
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to upload, download, or delete files in certain parts of the file system by sending specially crafted packets to port 19235/TCP. | |||||
CVE-2016-9157 | 1 Siemens | 1 Sicam Pas | 2017-06-12 | 7.5 HIGH | 9.8 CRITICAL |
A vulnerability in Siemens SICAM PAS (all versions before V8.09) could allow a remote attacker to cause a Denial of Service condition and potentially lead to unauthenticated remote code execution by sending specially crafted packets to port 19234/TCP. | |||||
CVE-2014-9310 | 1 Wordpress Backup To Dropbox Project | 1 Wordpress Backup To Dropbox | 2017-06-12 | 4.3 MEDIUM | 6.1 MEDIUM |
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress. | |||||
CVE-2015-7346 | 1 Zcms Project | 1 Zcms | 2017-06-12 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in ZCMS 1.1. | |||||
CVE-2016-6089 | 1 Ibm | 1 Websphere Mq | 2017-06-12 | 3.6 LOW | 5.5 MEDIUM |
IBM WebSphere MQ 9.0.0.1 and 9.0.2 could allow a local user to write to a file or delete files in a directory they should not have access to due to improper access controls. IBM X-Force ID: 117926. | |||||
CVE-2017-1125 | 1 Ibm | 1 Cognos Business Intelligence Server | 2017-06-12 | 2.1 LOW | 3.3 LOW |
IBM Cognos Analytics 10.1 and 10.2 could allow a local user to craft a URL which could confirm the existence of and expose postial contents of a file. IBM X-Force ID: 121340. | |||||
CVE-2016-8987 | 1 Ibm | 1 Maximo Asset Management | 2017-06-12 | 4.0 MEDIUM | 4.3 MEDIUM |
IBM Maximo Asset Management 7.1, 7.5, and 7.6 could allow an authenticated user to view incorrect item sets that they should not have access to view. |