Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-0489 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 6.5 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the ActionServlet servlet, which allows remote authenticated users to upload and execute arbitrary files via directory traversal sequences in the tempfilename parameter in a ReportImage action. | |||||
CVE-2016-0492 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do. | |||||
CVE-2016-1000122 | 1 Huge-it | 1 Slider | 2016-12-22 | 6.5 MEDIUM | 7.2 HIGH |
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension | |||||
CVE-2016-1000137 | 1 Hero-maps-pro Project | 1 Hero-maps-pro | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin hero-maps-pro v2.1.0 | |||||
CVE-2016-1000152 | 1 Tidio-form Project | 1 Tidio-form | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin tidio-form v1.0 | |||||
CVE-2016-0488 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0492. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function in the admin pages, which allows remote attackers to bypass authentication and gain administrator access via directory traversal sequences following a URI entry that does not require authentication. | |||||
CVE-2016-0490 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0487. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the UploadServlet servlet, which allows remote attackers to upload and execute arbitrary files via directory traversal sequences in a filename header. | |||||
CVE-2016-0491 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that the UploadFileAction servlet allows remote authenticated users to upload and execute arbitrary files via an * (asterisk) character in the fileType parameter. | |||||
CVE-2016-0485 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0486. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter. | |||||
CVE-2016-1000120 | 1 Huge-it | 1 Catalog | 2016-12-22 | 6.5 MEDIUM | 7.2 HIGH |
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla | |||||
CVE-2016-1000131 | 1 E-search Project | 1 Esearch | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin e-search v1.0 | |||||
CVE-2016-1000139 | 1 Infusionsoft Project | 1 Infusionsoft | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin infusionsoft v1.5.11 | |||||
CVE-2016-1000144 | 1 Photoxhibit Project | 1 Photoxhibit | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin photoxhibit v2.1.8 | |||||
CVE-2016-1000151 | 1 Tera-charts Project | 1 Tera-charts | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin tera-charts v1.0 | |||||
CVE-2014-1301 | 1 Apple | 2 Itunes, Safari | 2016-12-22 | 6.8 MEDIUM | N/A |
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1. | |||||
CVE-2016-1000128 | 1 Anti-plagiarism Project | 1 Anti-plagiarism | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin anti-plagiarism v3.60 | |||||
CVE-2016-1000130 | 1 E-search Project | 1 E-search | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin e-search v1.0 | |||||
CVE-2016-1000135 | 1 Hdw-tube Project | 1 Hdw-tube | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin hdw-tube v1.2 | |||||
CVE-2016-1000150 | 1 Oxil | 1 Simplified-content | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin simplified-content v1.0.0 | |||||
CVE-2016-0487 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 6.4 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0490. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the process method in the ActionServlet servlet, which allows remote attackers to bypass authentication via directory traversal sequences following an unspecified URI string. |