CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2015-8864

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in Roundcube Webmail before 1.0.9 and 1.1.x before 1.1.5 allows remote attackers to inject arbitrary web script or HTML via a crafted SVG, a different vulnerability than CVE-2016-4068.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2016-10117

    Last Modified: 20 Apr 2025

    Firejail does not restrict access to --tmpfs, which allows local users to gain privileges, as demonstrated by mounting over /etc.

    Published: 13 Apr 2017
    3.3
    Low

    CVE-2016-10118

    Last Modified: 20 Apr 2025

    Firejail allows local users to truncate /etc/resolv.conf via a chroot command to /.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2016-10119

    Last Modified: 20 Apr 2025

    Firejail uses 0777 permissions when mounting /tmp, which allows local users to gain privileges.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2016-10121

    Last Modified: 20 Apr 2025

    Firejail uses weak permissions for /dev/shm/firejail and possibly other files, which allows local users to gain privileges.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2016-10122

    Last Modified: 20 Apr 2025

    Firejail does not properly clean environment variables, which allows local users to gain privileges.

    Published: 13 Apr 2017
    7.8
    High

    CVE-2016-10123

    Last Modified: 20 Apr 2025

    Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.

    Published: 13 Apr 2017
    7.5
    High

    CVE-2016-1132

    Last Modified: 20 Apr 2025

    Shoplat App for iOS 1.10.00 through 1.18.00 does not properly verify SSL certificates.

    Published: 13 Apr 2017
    8.8
    High

    CVE-2016-1914

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrary SQL commands via the imageName parameter to (1) mydevice/client/image, (2) admin/client/image, (3) myapps/client/image, (4) ssam/client/image, or (5) all/client/image.

    Published: 13 Apr 2017
    8.8
    High

    CVE-2017-7219

    Last Modified: 20 Apr 2025

    A heap overflow vulnerability in Citrix NetScaler Gateway versions 10.1 before 135.8/135.12, 10.5 before 65.11, 11.0 before 70.12, and 11.1 before 52.13 allows a remote authenticated attacker to run arbitrary commands via unspecified vectors.

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2016-2555

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.

    Published: 13 Apr 2017
    5.3
    Medium

    CVE-2017-7627

    Last Modified: 20 Apr 2025

    The "Smart related articles" extension 1.1 for Joomla! does not prevent direct requests to dialog.php (there is a missing _JEXEC check).

    Published: 13 Apr 2017
    9.8
    Critical

    CVE-2017-7628

    Last Modified: 20 Apr 2025

    The "Smart related articles" extension 1.1 for Joomla! has SQL injection in dialog.php (attacker must use search_cats variable in POST method to exploit this vulnerability).

    Published: 13 Apr 2017
    6.1
    Medium

    CVE-2017-7626

    Last Modified: 20 Apr 2025

    The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).

    Published: 13 Apr 2017
    3.8
    Low

    CVE-2017-7995

    Last Modified: 20 Apr 2025

    Xen PV guest before Xen 4.3 checked access permissions to MMIO ranges only after accessing them, allowing host PCI device space memory reads, leading to information disclosure. This is an error in the get_user function. NOTE: the upstream Xen Project considers versions before 4.5.x to be EOL.

    Published: 13 Apr 2017
    8.8
    High

    CVE-2016-4893

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the SetsucoCMS all versions allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2017-7281

    Last Modified: 20 Apr 2025

    An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file on disk with a user-controlled extension, contents, and path, leading to remote code execution, aka Unrestricted File Upload.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2015-7562

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) label value of an item or (2) name of a role.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2015-7563

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.

    Published: 12 Apr 2017
    9.8
    Critical

    CVE-2015-7564

    Last Modified: 20 Apr 2025

    Multiple SQL injection vulnerabilities in TeamPass 2.1.24 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) id parameter in an action_on_quick_icon action to item.query.php or the (2) order or (3) direction parameter in an (a) connections_logs, (b) errors_logs or (c) access_logs action to view.query.php.

    Published: 12 Apr 2017
    6.5
    Medium

    CVE-2016-1178

    Last Modified: 20 Apr 2025

    The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2016-1179

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2016-5313

    Last Modified: 20 Apr 2025

    Symantec Web Gateway (SWG) before 5.2.5 allows remote authenticated users to execute arbitrary OS commands.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2016-2803

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML.

    Published: 12 Apr 2017
    9.8
    Critical

    CVE-2016-4337

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2016-4891

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in SetsucoCMS all versions allows remote attackers to hijack the authentication of an administrator to change settings via unspecified vectors.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2016-4892

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 12 Apr 2017
    5.3
    Medium

    CVE-2016-4894

    Last Modified: 20 Apr 2025

    SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2016-4895

    Last Modified: 20 Apr 2025

    SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.

    Published: 12 Apr 2017
    6.5
    Medium

    CVE-2016-4896

    Last Modified: 20 Apr 2025

    SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2016-4897

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.

    Published: 12 Apr 2017
    7
    High

    CVE-2016-5856

    Last Modified: 20 Apr 2025

    Drivers/soc/qcom/spcom.c in the Qualcomm SPCom driver in the Android kernel 2017-03-05 allows local users to gain privileges, a different vulnerability than CVE-2016-5857.

    Published: 12 Apr 2017
    7.5
    High

    CVE-2017-5936

    Last Modified: 20 Apr 2025

    OpenStack Nova-LXD before 13.1.1 uses the wrong name for the veth pairs when applying Neutron security group rules for instances, which allows remote attackers to bypass intended security restrictions.

    Published: 12 Apr 2017
    9.8
    Critical

    CVE-2017-7279

    Last Modified: 20 Apr 2025

    An unprivileged user of the Unitrends Enterprise Backup before 9.0.0 web server can escalate to root privileges by modifying the "token" cookie issued at login.

    Published: 12 Apr 2017
    9.8
    Critical

    CVE-2017-7280

    Last Modified: 20 Apr 2025

    An issue was discovered in api/includes/systems.php in Unitrends Enterprise Backup before 9.0.0. User input is not properly filtered before being sent to a popen function. This allows for remote code execution by sending a specially crafted user variable.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2017-7284

    Last Modified: 20 Apr 2025

    An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.

    Published: 12 Apr 2017
    7.8
    High

    CVE-2016-9957

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in game-music-emu before 0.6.1.

    Published: 12 Apr 2017
    7.8
    High

    CVE-2016-9958

    Last Modified: 20 Apr 2025

    game-music-emu before 0.6.1 allows remote attackers to write to arbitrary memory locations.

    Published: 12 Apr 2017
    7.8
    High

    CVE-2016-9959

    Last Modified: 20 Apr 2025

    game-music-emu before 0.6.1 allows remote attackers to generate out of bounds 8-bit values.

    Published: 12 Apr 2017
    8.8
    High

    CVE-2016-8718

    Last Modified: 20 Apr 2025

    An exploitable Cross-Site Request Forgery vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. A specially crafted form can trick a client into making an unintentional request to the web server which will be treated as an authentic request.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2016-8719

    Last Modified: 20 Apr 2025

    An exploitable reflected Cross-Site Scripting vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. Specially crafted input, in multiple parameters, can cause a malicious scripts to be executed by a victim.

    Published: 12 Apr 2017
    7.5
    High

    CVE-2016-8716

    Last Modified: 20 Apr 2025

    An exploitable Cleartext Transmission of Password vulnerability exists in the Web Application functionality of Moxa AWK-3131A Wireless Access Point running firmware 1.1. The Change Password functionality of the Web Application transmits the password in cleartext. An attacker capable of intercepting this traffic is able to obtain valid credentials.

    Published: 12 Apr 2017
    10
    Critical

    CVE-2017-7722

    Last Modified: 20 Apr 2025

    In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiting a vulnerability in the restrictssh feature of the menuing script, an attacker can escape from the restricted shell.

    Published: 12 Apr 2017
    6.1
    Medium

    CVE-2017-3125

    Last Modified: 20 Apr 2025

    An unauthenticated XSS vulnerability with FortiMail 5.0.0 - 5.2.9 and 5.3.0 - 5.3.8 could allow an attacker to execute arbitrary scripts in the security context of the browser of a victim logged in FortiMail, assuming the victim is social engineered into clicking an URL crafted by the attacker.

    Published: 12 Apr 2017
    5.5
    Medium

    CVE-2017-7716

    Last Modified: 20 Apr 2025

    The read_u32_leb128 function in libr/util/uleb128.c in radare2 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted Web Assembly file.

    Published: 12 Apr 2017
    9.8
    Critical

    CVE-2017-7719

    Last Modified: 20 Apr 2025

    SQL injection in the Spider Event Calendar (aka spider-event-calendar) plugin before 1.5.52 for WordPress is exploitable with the order_by parameter to calendar_functions.php or widget_Theme_functions.php, related to front_end/frontend_functions.php.

    Published: 12 Apr 2017
    7.8
    High

    CVE-2017-0199

    Last Modified: 22 Apr 2026

    Microsoft Office 2007 SP3, Microsoft Office 2010 SP2, Microsoft Office 2013 SP1, Microsoft Office 2016, Microsoft Windows Vista SP2, Windows Server 2008 SP2, Windows 7 SP1, Windows 8.1 allow remote attackers to execute arbitrary code via a crafted document, aka "Microsoft Office/WordPad Remote Code Execution Vulnerability w/Windows API."

    Published: 12 Apr 2017
    7.8
    High

    CVE-2017-3055

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in JPEG 2000 parsing of the fragment list tag. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Apr 2017
    7.8
    High

    CVE-2017-3054

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable memory corruption vulnerability in the image conversion engine, related to manipulation of EMF files. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Apr 2017
    7.8
    High

    CVE-2017-3049

    Last Modified: 20 Apr 2025

    Adobe Acrobat Reader versions 11.0.19 and earlier, 15.006.30280 and earlier, 15.023.20070 and earlier have an exploitable heap overflow vulnerability in the image conversion engine, related to internal tile manipulation in TIFF files. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Apr 2017