Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-03-05 CVE-2017-6486 Cross-site Scripting vulnerability in Reasoncms
A Cross-Site Scripting (XSS) issue was discovered in reasoncms before 4.7.1.
network
low complexity
reasoncms CWE-79
6.1
2017-03-05 CVE-2017-6485 Cross-site Scripting vulnerability in PHP-Calendar
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03.
network
low complexity
php-calendar CWE-79
6.1
2017-03-05 CVE-2017-6484 Cross-site Scripting vulnerability in Inter-Mediator 5.5
Multiple Cross-Site Scripting (XSS) issues were discovered in INTER-Mediator 5.5.
network
low complexity
inter-mediator CWE-79
6.1
2017-03-05 CVE-2017-6483 Cross-site Scripting vulnerability in Atutor
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2.
network
low complexity
atutor CWE-79
6.1
2017-03-05 CVE-2017-6481 Cross-site Scripting vulnerability in PHPipam
Multiple Cross-Site Scripting (XSS) issues were discovered in phpipam 1.2.
network
low complexity
phpipam CWE-79
6.1
2017-03-05 CVE-2017-6480 Cross-site Scripting vulnerability in Groovel Project Cmsgroovel 3.3.6
groovel/cmsgroovel before 3.3.7-beta is vulnerable to a reflected XSS in commons/browser.php (path parameter).
network
low complexity
groovel-project CWE-79
6.1
2017-03-05 CVE-2017-6479 Cross-site Scripting vulnerability in Fenix Hosting Fenix-Open-Source 20170221
FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).
network
low complexity
fenix-hosting CWE-79
6.1
2017-03-05 CVE-2017-6478 Cross-site Scripting vulnerability in Mangoswebv4 Project Mangoswebv4
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).
network
low complexity
mangoswebv4-project CWE-79
6.1
2017-03-03 CVE-2016-10070 Out-of-bounds Read vulnerability in multiple products
Heap-based buffer overflow in the CalcMinMax function in coders/mat.c in ImageMagick before 6.9.4-0 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted mat file.
local
low complexity
imagemagick opensuse CWE-125
5.5
2017-03-03 CVE-2016-10066 Classic Buffer Overflow vulnerability in Imagemagick
Buffer overflow in the ReadVIFFImage function in coders/viff.c in ImageMagick before 6.9.4-5 allows remote attackers to cause a denial of service (application crash) via a crafted file.
local
low complexity
imagemagick CWE-120
5.5