Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-13 CVE-2017-7626 Cross-site Scripting vulnerability in Smart Related Articles Project Smart Related Articles 1.1
The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method).
network
low complexity
smart-related-articles-project CWE-79
6.1
2017-04-12 CVE-2017-7700 Infinite Loop vulnerability in multiple products
In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file.
network
low complexity
wireshark debian CWE-835
6.5
2017-04-12 CVE-2016-6348 Cross-site Scripting vulnerability in Redhat Resteasy
JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack.
network
low complexity
redhat CWE-79
6.1
2017-04-12 CVE-2016-4897 Cross-site Scripting vulnerability in Webmin Usermin
Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690.
network
low complexity
webmin CWE-79
6.1
2017-04-12 CVE-2016-4896 Permissions, Privileges, and Access Controls vulnerability in Setucocms Project Setucocms
SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors.
network
low complexity
setucocms-project CWE-264
6.5
2017-04-12 CVE-2016-4894 Unspecified vulnerability in Setucocms Project Setucocms
SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
setucocms-project
5.3
2017-04-12 CVE-2016-4892 Cross-site Scripting vulnerability in Setucocms Project Setucocms
Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
network
low complexity
setucocms-project CWE-79
6.1
2017-04-12 CVE-2016-2803 Cross-site Scripting vulnerability in Mozilla Bugzilla
Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML.
network
low complexity
mozilla CWE-79
6.1
2017-04-12 CVE-2016-1179 Cross-site Scripting vulnerability in Appleple A-Blog CMS
Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML.
network
low complexity
appleple CWE-79
6.1
2017-04-12 CVE-2016-1178 Improper Access Control vulnerability in Appleple A-Blog CMS
The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors.
network
low complexity
appleple CWE-284
6.5