CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2016-3734

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-9978

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 5.2, 6.0, and 7.0 could allow an authenticated attacker to disclose sensitive information. IBM X-Force ID: 120254.

    Published: 20 Apr 2017
    5.4
    Medium

    CVE-2016-9979

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120255.

    Published: 20 Apr 2017
    5.4
    Medium

    CVE-2016-9980

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 5.2, 6.0, and 7.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 120256.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-8923

    Last Modified: 20 Apr 2025

    IBM Curam Social Program Management 5.2, 6.0, and 7.0 contains a vulnerability that would allow an authorized user to obtain sensitive information from the profile of a higher privileged user that they should not have access to. IBM X-Force ID: 118536.

    Published: 20 Apr 2017
    7.5
    High

    CVE-2015-8285

    Last Modified: 20 Apr 2025

    The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.

    Published: 20 Apr 2017
    8
    High

    CVE-2016-1161

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).

    Published: 20 Apr 2017
    5.3
    Medium

    CVE-2016-3731

    Last Modified: 20 Apr 2025

    Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, and 2.8 through 2.8.11 allows remote attackers to obtain the names of hidden forums and forum discussions.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-3733

    Last Modified: 20 Apr 2025

    The "restore teacher" feature in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to overwrite the course idnumber.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-3732

    Last Modified: 20 Apr 2025

    The capability check to access other badges in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to read the badges of other users.

    Published: 20 Apr 2017
    6.5
    Medium

    CVE-2016-3729

    Last Modified: 20 Apr 2025

    The user editing form in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13, and earlier allows remote authenticated users to edit profile fields locked by the administrator.

    Published: 20 Apr 2017
    7.4
    High

    CVE-2017-1122

    Last Modified: 20 Apr 2025

    IBM Security Guardium 8.2, 9.0, and 10.0 contains a vulnerability that could allow a local attacker with CLI access to inject arbitrary commands which would be executed as root. IBM X-Force ID: 121174.

    Published: 20 Apr 2017
    5.3
    Medium

    CVE-2017-5160

    Last Modified: 20 Apr 2025

    An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.

    Published: 20 Apr 2017
    8.8
    High

    CVE-2017-5156

    Last Modified: 20 Apr 2025

    A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.

    Published: 20 Apr 2017
    9.8
    Critical

    CVE-2017-5158

    Last Modified: 20 Apr 2025

    An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.

    Published: 20 Apr 2017
    8.1
    High

    CVE-2017-2784

    Last Modified: 5 Jun 2026

    An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2. A specially crafted x509 certificate, when parsed by mbed TLS library, can cause an invalid free of a stack pointer leading to a potential remote code execution. In order to exploit this vulnerability, an attacker can act as either a client or a server on a network to deliver malicious x509 certificates to vulnerable applications.

    Published: 20 Apr 2017
    8.8
    High

    CVE-2016-1218

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in Cybozu Garoon before 4.2.2.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-1220

    Last Modified: 20 Apr 2025

    Cybozu Garoon before 4.2.2 does not properly restrict access.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-1215

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "User details" function in Cybozu Garoon before 4.2.2.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-1216

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "New appointment" function in Cybozu Garoon before 4.2.2.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-1217

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "Check available times" function in Cybozu Garoon before 4.2.2.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-1213

    Last Modified: 20 Apr 2025

    The "Scheduler" function in Cybozu Garoon before 4.2.2 allows remote attackers to redirect users to arbitrary websites.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-1214

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the "Response request" function in Cybozu Garoon before 4.2.2.

    Published: 20 Apr 2017
    5.9
    Medium

    CVE-2016-4818

    Last Modified: 20 Apr 2025

    DMMFX Trade for Android 1.5.0 and earlier, DMMFX DEMO Trade for Android 1.5.0 and earlier, and GAITAMEJAPAN FX Trade for Android 1.4.0 and earlier do not verify SSL certificates.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-4842

    Last Modified: 20 Apr 2025

    Cybozu Mailwise before 5.4.0 allows remote attackers to obtain information on when an email is read.

    Published: 20 Apr 2017
    6.5
    Medium

    CVE-2016-4843

    Last Modified: 20 Apr 2025

    Cybozu Mailwise before 5.4.0 allows remote attackers to obtain sensitive cookie information.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2016-4844

    Last Modified: 20 Apr 2025

    Cybozu Mailwise before 5.4.0 allows remote attackers to conduct clickjacking attacks.

    Published: 20 Apr 2017
    8.1
    High

    CVE-2016-4850

    Last Modified: 20 Apr 2025

    LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.

    Published: 20 Apr 2017
    8.8
    High

    CVE-2016-4862

    Last Modified: 20 Apr 2025

    Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.

    Published: 20 Apr 2017
    9.1
    Critical

    CVE-2016-8721

    Last Modified: 20 Apr 2025

    An exploitable OS Command Injection vulnerability exists in the web application 'ping' functionality of Moxa AWK-3131A Wireless Access Points running firmware 1.1. Specially crafted web form input can cause an OS Command Injection resulting in complete compromise of the vulnerable device. An attacker can exploit this vulnerability remotely.

    Published: 20 Apr 2017
    4.3
    Medium

    CVE-2017-2806

    Last Modified: 20 Apr 2025

    An exploitable arbitrary read exists in the XLS parsing of the Lexmark Perspective Document Filters conversion functionality. A crafted XLS document can lead to a arbitrary read resulting in memory disclosure. The vulnerability was confirmed on versions 11.3.0.2228 and 11.3.0.2400

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2017-5183

    Last Modified: 20 Apr 2025

    NetIQ Access Manager 4.2.2 and 4.3.x before 4.3.1+, when configured as an Identity Server, has XSS in the AssertionConsumerServiceURL field of a signed AuthnRequest in a samlp:AuthnRequest document.

    Published: 20 Apr 2017
    7.8
    High

    CVE-2016-4293

    Last Modified: 20 Apr 2025

    Multiple heap-based buffer overflows in the (1) CBookBase::SetDefTableStyle and (2) CBookBase::SetDefPivotStyle functions in Hancom Office 2014 VP allow remote attackers to execute arbitrary code via a crafted Hangul Hcell Document (.cell) file.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-6334

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the Parser::replaceInternalLinks2 method in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via vectors involving replacement of percent encoding in unclosed internal links.

    Published: 20 Apr 2017
    9.8
    Critical

    CVE-2016-1219

    Last Modified: 20 Apr 2025

    Cybozu Garoon before 4.2.2 allows remote attackers to bypass login authentication via vectors related to API use.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-4849

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Geeklog IVYWE edition 2.1.1 allow remote attackers to inject arbitrary web script or HTML by leveraging use of the COM_getCurrentURL function in (1) public_html/layout/default/header.thtml, (2) public_html/layout/bento/header.thtml, (3) public_html/layout/fotos/header.thtml, or (4) public_html/layout/default/article/article.thtml.

    Published: 20 Apr 2017
    7.8
    High

    CVE-2016-4650

    Last Modified: 20 Apr 2025

    Heap-based buffer overflow in IOHIDFamily in Apple iOS before 9.3.2, OS X before 10.11.5, and tvOS before 9.2.1 allows attackers to execute arbitrary code in a privileged context or cause a denial of service (memory corruption) via a crafted app.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-5760

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/install/login.jsp or (2) PATH_INFO to gwadmin-console/index.jsp.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-5761

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allows remote attackers to inject arbitrary web script or HTML via a crafted email.

    Published: 20 Apr 2017
    9.8
    Critical

    CVE-2016-5762

    Last Modified: 20 Apr 2025

    Integer overflow in the Post Office Agent in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 might allow remote attackers to execute arbitrary code via a long (1) username or (2) password, which triggers a heap-based buffer overflow.

    Published: 20 Apr 2017
    7.5
    High

    CVE-2016-6331

    Last Modified: 20 Apr 2025

    ApiParse in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to bypass intended per-title read restrictions via a parse action to api.php.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-6333

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the CSS user subpage preview feature in MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote attackers to inject arbitrary web script or HTML via the edit box in Special:MyPage/common.css.

    Published: 20 Apr 2017
    7.5
    High

    CVE-2016-6337

    Last Modified: 20 Apr 2025

    MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.

    Published: 20 Apr 2017
    6.1
    Medium

    CVE-2016-4847

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in site/search.php in OSSEC Web UI before 0.9 allows remote attackers to inject arbitrary web script or HTML by leveraging an unanchored regex.

    Published: 20 Apr 2017
    7.5
    High

    CVE-2016-6332

    Last Modified: 20 Apr 2025

    MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1, when $wgBlockDisablesLogin is true, might allow remote attackers to obtain sensitive information by leveraging failure to terminate sessions when a user account is blocked.

    Published: 20 Apr 2017
    7.5
    High

    CVE-2016-6335

    Last Modified: 20 Apr 2025

    MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 does not generate head items in the context of a given title, which allows remote attackers to obtain sensitive information via a parse action to api.php.

    Published: 20 Apr 2017
    6.5
    Medium

    CVE-2016-6336

    Last Modified: 20 Apr 2025

    MediaWiki before 1.23.15, 1.26.x before 1.26.4, and 1.27.x before 1.27.1 allows remote authenticated users with undelete permissions to bypass intended suppressrevision and deleterevision restrictions and remove the revision deletion status of arbitrary file revisions by using Special:Undelete.

    Published: 20 Apr 2017
    3.1
    Low

    CVE-2017-5190

    Last Modified: 20 Apr 2025

    NetIQ Access Manager 4.2 before SP3 HF1 and 4.3 before SP1 HF1, when configured as a SAML 2.0 Identity Server with Virtual Attributes, has a concurrency issue causing information leakage, related to a stale profile.

    Published: 20 Apr 2017
    Unknown

    CVE-2017-5181

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-7692. Reason: This candidate is a reservation duplicate of CVE-2017-7692. Notes: All CVE users should reference CVE-2017-7692 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 20 Apr 2017
    7.5
    High

    CVE-2017-6919

    Last Modified: 20 Apr 2025

    Drupal 8 before 8.2.8 and 8.3 before 8.3.1 allows critical access bypass by authenticated users if the RESTful Web Services (rest) module is enabled and the site allows PATCH requests.

    Published: 20 Apr 2017