Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-04-20 CVE-2016-5401 Cross-Site Request Forgery (CSRF) vulnerability in Redhat Jboss BPM Suite and Jboss Enterprise Brms Platform
Cross-site request forgery (CSRF) vulnerability in Red Hat JBoss BRMS and BPMS 6 allows remote attackers to hijack the authentication of users for requests that modify instances via a crafted web page.
network
low complexity
redhat CWE-352
8.8
2017-04-20 CVE-2016-3734 Cross-Site Request Forgery (CSRF) vulnerability in Moodle
Cross-site request forgery (CSRF) vulnerability in markposts.php in Moodle 3.0 through 3.0.3, 2.9 through 2.9.5, 2.8 through 2.8.11, 2.7 through 2.7.13 and earlier allows remote attackers to hijack the authentication of users for requests that marks forum posts as read.
network
low complexity
moodle CWE-352
8.8
2017-04-20 CVE-2016-1161 Cross-Site Request Forgery (CSRF) vulnerability in Zohocorp Password Manager PRO 8.5
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).
network
low complexity
zohocorp CWE-352
8.0
2017-04-20 CVE-2015-8285 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Quickheal Total Security 16.00
The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
network
low complexity
quickheal CWE-119
7.5
2017-04-20 CVE-2017-5156 Cross-Site Request Forgery (CSRF) vulnerability in Aveva Wonderware Intouch Access Anywhere 11.5.2
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior.
network
low complexity
aveva CWE-352
8.8
2017-04-20 CVE-2017-2784 Improper Certificate Validation vulnerability in ARM Mbed TLS
An exploitable free of a stack pointer vulnerability exists in the x509 certificate parsing code of ARM mbed TLS before 1.3.19, 2.x before 2.1.7, and 2.4.x before 2.4.2.
network
high complexity
arm CWE-295
8.1
2017-04-20 CVE-2016-4862 Improper Input Validation vulnerability in Cs-Cart
Twigmo bundled with CS-Cart 4.3.9 and earlier and Twigmo bundled with CS-Cart Multi-Vendor 4.3.9 and earlier allow remote authenticated users to execute arbitrary PHP code on the servers.
network
low complexity
cs-cart CWE-20
8.8
2017-04-20 CVE-2016-4850 Improper Access Control vulnerability in Linecorp Line 4.3.0.724/4.7.0/4.8.2.1125
LINE for Windows before 4.8.3 allows man-in-the-middle attackers to execute arbitrary code.
network
high complexity
linecorp CWE-284
8.1
2017-04-20 CVE-2016-1218 SQL Injection vulnerability in Cybozu Garoon
SQL injection vulnerability in Cybozu Garoon before 4.2.2.
network
low complexity
cybozu CWE-89
8.8
2017-04-20 CVE-2016-6337 Improper Access Control vulnerability in Mediawiki 1.27.0
MediaWiki 1.27.x before 1.27.1 might allow remote attackers to bypass intended session access restrictions by leveraging a call to the UserGetRights function after Session::getAllowedUserRights.
network
low complexity
mediawiki CWE-284
7.5