Total
19979 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2016-5605 | 1 Oracle | 1 Vm Virtualbox | 2017-07-29 | 6.4 MEDIUM | 9.1 CRITICAL |
Unspecified vulnerability in the Oracle VM VirtualBox component before 5.1.4 in Oracle Virtualization allows remote attackers to affect confidentiality and integrity via vectors related to VRDE. | |||||
CVE-2016-8565 | 1 Siemens | 1 Automation License Manager | 2017-07-29 | 6.4 MEDIUM | 9.1 CRITICAL |
Siemens Automation License Manager (ALM) before 5.3 SP3 allows remote attackers to write to files, rename files, create directories, or delete directories via crafted packets. | |||||
CVE-2017-11324 | 1 Tilde Cms Project | 1 Tilde Cms | 2017-07-28 | 7.5 HIGH | 9.8 CRITICAL |
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php with the id parameter. | |||||
CVE-2017-11585 | 1 Finecms | 1 Finecms | 2017-07-28 | 7.5 HIGH | 9.8 CRITICAL |
dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection. | |||||
CVE-2016-7784 | 1 Exponentcms | 1 Exponent Cms | 2017-07-28 | 7.5 HIGH | 9.8 CRITICAL |
SQL injection vulnerability in the getSection function in framework/core/subsystems/expRouter.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the section parameter. | |||||
CVE-2016-7460 | 1 Vmware | 1 Vrealize Automation | 2017-07-28 | 6.4 MEDIUM | 9.1 CRITICAL |
The Single Sign-On feature in VMware vCenter Server 5.5 before U3e and 6.0 before U2a and vRealize Automation 6.x before 6.2.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML document containing an external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |||||
CVE-2016-9481 | 1 Exponentcms | 1 Exponent Cms | 2017-07-28 | 7.5 HIGH | 9.8 CRITICAL |
In framework/modules/core/controllers/expCommentController.php of Exponent CMS 2.4.0, content_id input is passed into showComments. The method showComments is defined in the expCommentControllercontroller with the parameter '$this->params['content_id']' used directly in SQL. Impact is a SQL injection. | |||||
CVE-2016-9288 | 1 Exponentcms | 1 Exponent Cms | 2017-07-28 | 7.5 HIGH | 9.8 CRITICAL |
In framework/modules/navigation/controllers/navigationController.php in Exponent CMS v2.4.0 or older, the parameter "target" of function "DragnDropReRank" is directly used without any filtration which caused SQL injection. The payload can be used like this: /navigation/DragnDropReRank/target/1. | |||||
CVE-2017-11583 | 1 Finecms | 1 Finecms | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php. | |||||
CVE-2017-11584 | 1 Finecms | 1 Finecms | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
dayrui FineCms 5.0.9 has SQL Injection via the field parameter in an action=module, action=member, action=form, or action=related request to libraries/Template.php. | |||||
CVE-2017-11582 | 1 Finecms | 1 Finecms | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php. | |||||
CVE-2017-11174 | 1 Xoops | 1 Xoops | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
In install/page_dbsettings.php in the Core distribution of XOOPS 2.5.8.1, unfiltered data passed to CREATE and ALTER SQL queries caused SQL Injection in the database settings page, related to use of GBK in CHARACTER SET and COLLATE clauses. | |||||
CVE-2017-1000002 | 1 Atutor | 1 Atutor | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the Course Icon component resulting in information disclosure. | |||||
CVE-2017-2126 | 1 Buffalo | 4 Wapm-1166d, Wapm-1166d Firmware, Wapm-apg600h and 1 more | 2017-07-27 | 10.0 HIGH | 9.8 CRITICAL |
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors. | |||||
CVE-2017-7336 | 1 Fortinet | 1 Fortiwlm | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges. | |||||
CVE-2016-0360 | 1 Ibm | 1 Websphere Mq Jms | 2017-07-27 | 7.5 HIGH | 9.8 CRITICAL |
IBM Websphere MQ JMS 7.0.1, 7.1, 7.5, 8.0, and 9.0 client provides classes that deserialize objects from untrusted sources which could allow a malicious user to execute arbitrary Java code by adding vulnerable classes to the classpath. IBM Reference #: 1983457. | |||||
CVE-2016-7399 | 1 Veritas | 2 Netbackup Appliance, Netbackup Appliance Firmware | 2017-07-27 | 10.0 HIGH | 9.8 CRITICAL |
scripts/license.pl in Veritas NetBackup Appliance 2.6.0.x through 2.6.0.4, 2.6.1.x through 2.6.1.2, 2.7.x through 2.7.3, and 3.0.x allow remote attackers to execute arbitrary commands via shell metacharacters in the hostName parameter to appliancews/getLicense. | |||||
CVE-2017-1000362 | 1 Jenkins | 1 Jenkins | 2017-07-26 | 5.0 MEDIUM | 9.8 CRITICAL |
The re-key admin monitor was introduced in Jenkins 1.498 and re-encrypted all secrets in JENKINS_HOME with a new key. It also created a backup directory with all old secrets, and the key used to encrypt them. These backups were world-readable and not removed afterwards. Jenkins now deletes the backup directory, if present. Upgrading from before 1.498 will no longer create a backup directory. Administrators relying on file access permissions in their manually created backups are advised to check them for the directory $JENKINS_HOME/jenkins.security.RekeySecretAdminMonitor/backups, and delete it if present. | |||||
CVE-2017-11517 | 1 Geutebrueck | 1 Gcore | 2017-07-26 | 7.5 HIGH | 9.8 CRITICAL |
Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary code via a long URI in a GET request. | |||||
CVE-2017-11329 | 1 Glpi-project | 1 Glpi | 2017-07-26 | 7.5 HIGH | 9.8 CRITICAL |
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers. |