Vulnerabilities > Medium

DATE CVE VULNERABILITY TITLE RISK
2017-04-10 CVE-2016-5078 Cross-site Scripting vulnerability in Paessler Prtg Network Monitor
Paessler PRTG before 16.2.24.4045 has XSS via SNMP.
network
low complexity
paessler CWE-79
6.1
2017-04-10 CVE-2016-5077 Cross-site Scripting vulnerability in Netikus Eventsentry 3.2.1.22/3.2.1.30/3.2.1.8
Netikus EventSentry before 3.2.1.44 has XSS via SNMP.
network
low complexity
netikus CWE-79
6.1
2017-04-10 CVE-2016-5075 Cross-site Scripting vulnerability in Cloudviewnms Cloudview NMS
CloudView NMS before 2.10a has XSS via a TELNET login.
network
low complexity
cloudviewnms CWE-79
6.1
2017-04-10 CVE-2016-5073 Cross-site Scripting vulnerability in Cloudviewnms Cloudview NMS
CloudView NMS before 2.10a has XSS via SNMP.
network
low complexity
cloudviewnms CWE-79
6.1
2017-04-10 CVE-2016-5059 Information Exposure vulnerability in Osram Lightify PRO
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 allows attackers to obtain sensitive information by reading screenshots under /private/var/mobile/Containers/Data/Application.
network
low complexity
osram CWE-200
6.5
2017-04-10 CVE-2016-5055 Cross-site Scripting vulnerability in Osram Lightify PRO
OSRAM SYLVANIA Osram Lightify Pro before 2016-07-26 has XSS in the username field and Wireless Client Mode configuration page.
network
low complexity
osram CWE-79
6.1
2017-04-10 CVE-2016-4334 Open Redirect vulnerability in Jivesoftware Jive
Jive before 2016.3.1 has an open redirect from the external-link.jspa page.
network
low complexity
jivesoftware CWE-601
6.1
2017-04-10 CVE-2016-4320 Path Traversal vulnerability in Atlassian Bitbucket
Atlassian Bitbucket Server before 4.7.1 allows remote attackers to read the first line of an arbitrary file via a directory traversal attack on the pull requests resource.
network
low complexity
atlassian CWE-22
4.3
2017-04-10 CVE-2016-4318 Cross-site Scripting vulnerability in Atlassian Jira
Atlassian JIRA Server before 7.1.9 has XSS in project/ViewDefaultProjectRoleActors.jspa via a role name.
network
low complexity
atlassian CWE-79
4.8
2017-04-10 CVE-2016-4317 Cross-site Scripting vulnerability in Atlassian Confluence
Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
network
low complexity
atlassian CWE-79
5.4