Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-27 CVE-2017-3008 Cross-site Scripting vulnerability in Adobe Coldfusion 10.0/11.0/2016
Adobe ColdFusion 2016 Update 3 and earlier, ColdFusion 11 update 11 and earlier, ColdFusion 10 Update 22 and earlier have a reflected cross-site scripting vulnerability.
network
low complexity
adobe CWE-79
6.1
2017-04-26 CVE-2017-3161 Cross-site Scripting vulnerability in Apache Hadoop
The HDFS web UI in Apache Hadoop before 2.7.0 is vulnerable to a cross-site scripting (XSS) attack through an unescaped query parameter.
network
low complexity
apache CWE-79
6.1
2017-04-26 CVE-2017-1170 Unspecified vulnerability in IBM Websphere Commerce
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session.
local
low complexity
ibm
5.3
2017-04-26 CVE-2016-8962 Credentials Management vulnerability in IBM Bigfix Inventory 9.0/9.2
IBM BigFix Inventory 9.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
network
high complexity
ibm CWE-255
5.9
2017-04-26 CVE-2016-8924 Cross-site Scripting vulnerability in IBM Maximo Asset Management 7.1/7.5/7.6
IBM Maximo Asset Management 7.1, 7.5 and 7.6 could allow a remote attacker to hijack a user's session, caused by the failure to invalidate an existing session identifier.
network
high complexity
ibm CWE-79
5.6
2017-04-25 CVE-2017-8219 Improper Input Validation vulnerability in Tp-Link C20I Firmware and C2 Firmware
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n allow DoSing the HTTP server via a crafted Cookie header to the /cgi/ansi URI.
network
low complexity
tp-link CWE-20
6.5
2017-04-25 CVE-2017-8217 Missing Authorization vulnerability in Tp-Link C20I Firmware and C2 Firmware
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.
network
low complexity
tp-link CWE-862
5.3
2017-04-25 CVE-2017-8115 Path Traversal vulnerability in Modx Revolution 2.5.7
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.
network
low complexity
modx CWE-22
5.3
2017-04-25 CVE-2017-8057 Information Exposure vulnerability in Joomla Joomla!
In Joomla! 3.4.0 through 3.6.5 (fixed in 3.7.0), multiple files caused full path disclosures on systems with enabled error reporting.
network
low complexity
joomla CWE-200
5.3
2017-04-25 CVE-2017-7989 Unrestricted Upload of File with Dangerous Type vulnerability in Joomla Joomla!
In Joomla! 3.2.0 through 3.6.5 (fixed in 3.7.0), inadequate MIME type checks allowed low-privilege users to upload swf files even if they were explicitly forbidden.
network
low complexity
joomla CWE-434
6.5