Vulnerabilities > Medium
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2017-04-13 | CVE-2017-7626 | Cross-site Scripting vulnerability in Smart Related Articles Project Smart Related Articles 1.1 The "Smart related articles" extension 1.1 for Joomla! has XSS in dialog.php (n_art,type in GET Method). | 6.1 |
2017-04-12 | CVE-2017-7700 | Infinite Loop vulnerability in multiple products In Wireshark 2.2.0 to 2.2.5 and 2.0.0 to 2.0.11, the NetScaler file parser could go into an infinite loop, triggered by a malformed capture file. | 6.5 |
2017-04-12 | CVE-2016-6348 | Cross-site Scripting vulnerability in Redhat Resteasy JacksonJsonpInterceptor in RESTEasy might allow remote attackers to conduct a cross-site script inclusion (XSSI) attack. | 6.1 |
2017-04-12 | CVE-2016-4897 | Cross-site Scripting vulnerability in Webmin Usermin Multiple cross-site scripting (XSS) vulnerabilities in (1) filter/save_forward.cgi, (2) filter/save.cgi, (3) /man/search.cgi in Usermin before 1.690. | 6.1 |
2017-04-12 | CVE-2016-4896 | Permissions, Privileges, and Access Controls vulnerability in Setucocms Project Setucocms SetsucoCMS all versions does not properly manage sessions, which allows remote attackers to disclose or alter unauthorized information via unspecified vectors. | 6.5 |
2017-04-12 | CVE-2016-4894 | Unspecified vulnerability in Setucocms Project Setucocms SetsucoCMS all versions allows remote attackers to cause a denial of service via unspecified vectors. | 5.3 |
2017-04-12 | CVE-2016-4892 | Cross-site Scripting vulnerability in Setucocms Project Setucocms Cross-site scripting vulnerability in SetsucoCMS all versions allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | 6.1 |
2017-04-12 | CVE-2016-2803 | Cross-site Scripting vulnerability in Mozilla Bugzilla Cross-site scripting (XSS) vulnerability in the dependency graphs in Bugzilla 2.16rc1 through 4.4.11, and 4.5.1 through 5.0.2 allows remote attackers to inject arbitrary web script or HTML. | 6.1 |
2017-04-12 | CVE-2016-1179 | Cross-site Scripting vulnerability in Appleple A-Blog CMS Cross-site scripting (XSS) vulnerability in the standard template of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML. | 6.1 |
2017-04-12 | CVE-2016-1178 | Improper Access Control vulnerability in Appleple A-Blog CMS The session management of the comment functionality in appleple a-blog cms 2.6.0.1 and earlier allows remote attackers to obtain or modify sensitive data via unspecified vectors. | 6.5 |