Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-1000147 | 1 Recipes-writer Project | 1 Recipes-writer | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin recipes-writer v1.0.4 | |||||
CVE-2016-1000153 | 1 Tidio-gallery Project | 1 Tidio-gallery | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin tidio-gallery v1.1 | |||||
CVE-2016-0486 | 1 Oracle | 1 Application Testing Suite | 2016-12-22 | 5.0 MEDIUM | N/A |
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0485. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the exportFileName parameter. | |||||
CVE-2016-1000134 | 1 Hdw-tube Project | 1 Hdw-tube | 2016-12-22 | 4.3 MEDIUM | 6.1 MEDIUM |
Reflected XSS in wordpress plugin hdw-tube v1.2 | |||||
CVE-2015-5410 | 1 Hp | 1 Version Control Repository Manager | 2016-12-21 | 6.5 MEDIUM | N/A |
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to execute arbitrary code or cause a denial of service via unspecified vectors. | |||||
CVE-2015-5411 | 1 Hp | 1 Version Control Repository Manager | 2016-12-21 | 6.8 MEDIUM | N/A |
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-5412 | 1 Hp | 1 Version Control Repository Manager | 2016-12-21 | 6.0 MEDIUM | N/A |
Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors. | |||||
CVE-2015-5413 | 1 Hp | 1 Version Control Repository Manager | 2016-12-21 | 4.0 MEDIUM | N/A |
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors. | |||||
CVE-2015-5426 | 1 Hp | 1 Loadrunner | 2016-12-21 | 4.6 MEDIUM | N/A |
Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756. | |||||
CVE-2015-5440 | 1 Hp | 1 Universal Configuration Management Database | 2016-12-21 | 4.9 MEDIUM | N/A |
HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors. | |||||
CVE-2015-5475 | 1 Bestpractical | 1 Request Tracker | 2016-12-21 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages. | |||||
CVE-2015-5481 | 1 Dev4press | 1 Gd Bbpress Attachments | 2016-12-21 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php. | |||||
CVE-2015-5482 | 1 Dev4press | 1 Gd Bbpress Attachments | 2016-12-21 | 4.0 MEDIUM | N/A |
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php. | |||||
CVE-2015-5528 | 1 Wpbeginner | 1 Floating Social Bar | 2016-12-21 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php. | |||||
CVE-2015-5538 | 1 Citrix | 2 Netscaler Application Delivery Controller Firmware, Netscaler Gateway Firmware | 2016-12-21 | 10.0 HIGH | N/A |
Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the (1) Command Line Interface (CLI) and the (2) Web User Interface (UI). | |||||
CVE-2015-5625 | 1 Opendocman | 1 Opendocman | 2016-12-21 | 4.3 MEDIUM | N/A |
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter. | |||||
CVE-2015-5689 | 1 Symantec | 2 Deployment Solution, Ghost Solutions Suite | 2016-12-21 | 6.8 MEDIUM | N/A |
ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image. | |||||
CVE-2015-5690 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 8.5 HIGH | N/A |
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect." | |||||
CVE-2015-5691 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 4.3 MEDIUM | N/A |
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php. | |||||
CVE-2015-5692 | 1 Symantec | 1 Web Gateway | 2016-12-21 | 7.9 HIGH | N/A |
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file. |