Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2016-1000217 1 Zotpress Project 1 Zotpress 2016-12-22 7.5 HIGH 9.8 CRITICAL
Zotpress plugin for WordPress SQLi in zp_get_account()
CVE-2016-0489 1 Oracle 1 Application Testing Suite 2016-12-22 6.5 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote authenticated users to affect confidentiality, integrity, and availability via unknown vectors related to Test Manager for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the ActionServlet servlet, which allows remote authenticated users to upload and execute arbitrary files via directory traversal sequences in the tempfilename parameter in a ReportImage action.
CVE-2016-0492 1 Oracle 1 Application Testing Suite 2016-12-22 6.4 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0488. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function, which allows remote attackers to bypass authentication via directory traversal sequences following a URI entry that does not require authentication, as demonstrated by olt/Login.do/../../olt/UploadFileUpload.do.
CVE-2016-1000122 1 Huge-it 1 Slider 2016-12-22 6.5 MEDIUM 7.2 HIGH
XSS and SQLi in Huge IT Joomla Slider v1.0.9 extension
CVE-2016-1000137 1 Hero-maps-pro Project 1 Hero-maps-pro 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin hero-maps-pro v2.1.0
CVE-2016-1000152 1 Tidio-form Project 1 Tidio-form 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tidio-form v1.0
CVE-2016-0488 1 Oracle 1 Application Testing Suite 2016-12-22 6.4 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Load Testing for Web Apps, a different vulnerability than CVE-2016-0492. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the isAllowedUrl function in the admin pages, which allows remote attackers to bypass authentication and gain administrator access via directory traversal sequences following a URI entry that does not require authentication.
CVE-2016-0490 1 Oracle 1 Application Testing Suite 2016-12-22 6.4 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0487. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the UploadServlet servlet, which allows remote attackers to upload and execute arbitrary files via directory traversal sequences in a filename header.
CVE-2016-0491 1 Oracle 1 Application Testing Suite 2016-12-22 6.4 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect integrity and availability via unknown vectors related to Load Testing for Web Apps. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that the UploadFileAction servlet allows remote authenticated users to upload and execute arbitrary files via an * (asterisk) character in the fileType parameter.
CVE-2016-0485 1 Oracle 1 Application Testing Suite 2016-12-22 5.0 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0486. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the reportName parameter.
CVE-2016-1000120 1 Huge-it 1 Catalog 2016-12-22 6.5 MEDIUM 7.2 HIGH
SQLi and XSS in Huge IT catalog extension v1.0.4 for Joomla
CVE-2016-1000131 1 E-search Project 1 Esearch 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin e-search v1.0
CVE-2016-1000139 1 Infusionsoft Project 1 Infusionsoft 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin infusionsoft v1.5.11
CVE-2016-1000144 1 Photoxhibit Project 1 Photoxhibit 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin photoxhibit v2.1.8
CVE-2016-1000151 1 Tera-charts Project 1 Tera-charts 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tera-charts v1.0
CVE-2014-1301 1 Apple 2 Itunes, Safari 2016-12-22 6.8 MEDIUM N/A
WebKit, as used in Apple Safari before 6.1.3 and 7.x before 7.0.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2014-04-01-1.
CVE-2016-1000128 1 Anti-plagiarism Project 1 Anti-plagiarism 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin anti-plagiarism v3.60
CVE-2016-1000130 1 E-search Project 1 E-search 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin e-search v1.0
CVE-2016-1000135 1 Hdw-tube Project 1 Hdw-tube 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin hdw-tube v1.2
CVE-2016-1000150 1 Oxil 1 Simplified-content 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin simplified-content v1.0.0
CVE-2016-0487 1 Oracle 1 Application Testing Suite 2016-12-22 6.4 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality and integrity via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0490. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the process method in the ActionServlet servlet, which allows remote attackers to bypass authentication via directory traversal sequences following an unspecified URI string.
CVE-2016-1000147 1 Recipes-writer Project 1 Recipes-writer 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin recipes-writer v1.0.4
CVE-2016-1000153 1 Tidio-gallery Project 1 Tidio-gallery 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin tidio-gallery v1.1
CVE-2016-0486 1 Oracle 1 Application Testing Suite 2016-12-22 5.0 MEDIUM N/A
Unspecified vulnerability in the Oracle Application Testing Suite component in Oracle Enterprise Manager Grid Control 12.4.0.2 and 12.5.0.2 allows remote attackers to affect confidentiality via unknown vectors related to Test Manager for Web Apps, a different vulnerability than CVE-2016-0480, CVE-2016-0481, CVE-2016-0482, and CVE-2016-0485. NOTE: the previous information is from the January 2016 CPU. Oracle has not commented on third-party claims that this is a directory traversal vulnerability in the DownloadServlet servlet, which allows remote attackers to read arbitrary files via directory traversal sequences in the exportFileName parameter.
CVE-2016-1000134 1 Hdw-tube Project 1 Hdw-tube 2016-12-22 4.3 MEDIUM 6.1 MEDIUM
Reflected XSS in wordpress plugin hdw-tube v1.2
CVE-2015-5410 1 Hp 1 Version Control Repository Manager 2016-12-22 6.5 MEDIUM N/A
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to execute arbitrary code or cause a denial of service via unspecified vectors.
CVE-2015-5411 1 Hp 1 Version Control Repository Manager 2016-12-22 6.8 MEDIUM N/A
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to obtain sensitive information via unspecified vectors.
CVE-2015-5412 1 Hp 1 Version Control Repository Manager 2016-12-22 6.0 MEDIUM N/A
Cross-site request forgery (CSRF) vulnerability in HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to hijack the authentication of unspecified victims via unknown vectors.
CVE-2015-5413 1 Hp 1 Version Control Repository Manager 2016-12-22 4.0 MEDIUM N/A
HP Version Control Repository Manager (VCRM) before 7.5.0 allows remote authenticated users to gain privileges and obtain sensitive information via unspecified vectors.
CVE-2015-5426 1 Hp 1 Loadrunner 2016-12-22 4.6 MEDIUM N/A
Unspecified vulnerability in HP LoadRunner Controller before 12.50 allows local users to gain privileges via unknown vectors, aka ZDI-CAN-2756.
CVE-2015-5440 1 Hp 1 Universal Configuration Management Database 2016-12-22 4.9 MEDIUM N/A
HP UCMDB 10.00 and 10.01 before 10.01CUP12, 10.10 and 10.11 before 10.11CUP6, and 10.2x before 10.21 allows local users to obtain sensitive information via unspecified vectors.
CVE-2015-5475 1 Bestpractical 1 Request Tracker 2016-12-22 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in Request Tracker (RT) 4.x before 4.2.12 allow remote attackers to inject arbitrary web script or HTML via vectors related to the (1) user and (2) group rights management pages.
CVE-2015-5481 1 Dev4press 1 Gd Bbpress Attachments 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in forms/panels.php in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote attackers to inject arbitrary web script or HTML via the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
CVE-2015-5482 1 Dev4press 1 Gd Bbpress Attachments 2016-12-22 4.0 MEDIUM N/A
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.
CVE-2015-5528 1 Wpbeginner 1 Floating Social Bar 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in the save_order function in class-floating-social-bar.php in the Floating Social Bar plugin before 1.1.6 for WordPress allows remote attackers to inject arbitrary web script or HTML via the items[] parameter in an fsb_save_order action to wp-admin/admin-ajax.php.
CVE-2015-5538 1 Citrix 2 Netscaler Application Delivery Controller Firmware, Netscaler Gateway Firmware 2016-12-22 10.0 HIGH N/A
Multiple unspecified vulnerabilities in Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway before 10.1 Build 132.8, 10.5 before Build 57.7, and 10.5e before Build 56.1505.e allow remote attackers to gain privileges via unknown vectors, related to the (1) Command Line Interface (CLI) and the (2) Web User Interface (UI).
CVE-2015-5625 1 Opendocman 1 Opendocman 2016-12-22 4.3 MEDIUM N/A
Cross-site scripting (XSS) vulnerability in OpenDocMan before 1.3.4 allows remote attackers to inject arbitrary web script or HTML via the redirection parameter.
CVE-2015-5689 1 Symantec 2 Deployment Solution, Ghost Solutions Suite 2016-12-22 6.8 MEDIUM N/A
ghostexp.exe in Ghost Explorer Utility in Symantec Ghost Solutions Suite (GSS) before 3.0 HF2 12.0.0.8010 and Symantec Deployment Solution (DS) before 7.6 HF4 12.0.0.7045 performs improper sign-extend operations before array-element accesses, which allows remote attackers to execute arbitrary code, cause a denial of service (application crash), or possibly obtain sensitive information via a crafted Ghost image.
CVE-2015-5690 1 Symantec 1 Web Gateway 2016-12-22 8.5 HIGH N/A
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to bypass intended access restrictions and execute arbitrary commands by leveraging a "redirect."
CVE-2015-5691 1 Symantec 1 Web Gateway 2016-12-22 4.3 MEDIUM N/A
Multiple cross-site scripting (XSS) vulnerabilities in PHP scripts in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors, as demonstrated an attack against admin_messages.php.
CVE-2015-5692 1 Symantec 1 Web Gateway 2016-12-22 7.9 HIGH N/A
admin_messages.php in the management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary code by uploading a file with a safe extension and content type, and then leveraging an improper Sudo configuration to make this a setuid-root file.
CVE-2015-5693 1 Symantec 1 Web Gateway 2016-12-22 7.9 HIGH N/A
The management console on Symantec Web Gateway (SWG) appliances with software before 5.2.2 DB 5.0.0.1277 allows remote authenticated users to execute arbitrary commands via vectors related to "traffic capture."
CVE-2015-5698 1 Siemens 2 Simatic S7 1200 Cpu, Simatic S7 1200 Cpu Firmware 2016-12-22 7.5 HIGH N/A
Cross-site request forgery (CSRF) vulnerability in the web server on Siemens SIMATIC S7-1200 CPU devices with firmware before 4.1.3 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
CVE-2015-5764 1 Apple 2 Iphone Os, Safari 2016-12-22 4.3 MEDIUM N/A
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5765 and CVE-2015-5767.
CVE-2015-5765 1 Apple 2 Iphone Os, Safari 2016-12-22 4.3 MEDIUM N/A
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5767.
CVE-2015-5767 1 Apple 2 Iphone Os, Safari 2016-12-22 4.3 MEDIUM N/A
The user interface in Safari in Apple iOS before 9 allows remote attackers to spoof URLs via unspecified vectors, a different vulnerability than CVE-2015-5764 and CVE-2015-5765.
CVE-2015-5788 1 Apple 2 Iphone Os, Safari 2016-12-22 4.3 MEDIUM N/A
The WebKit Canvas implementation in Apple iOS before 9 allows remote attackers to bypass the Same Origin Policy and obtain sensitive image information via vectors involving a CANVAS element.
CVE-2015-5789 1 Apple 3 Iphone Os, Itunes, Safari 2016-12-22 6.8 MEDIUM N/A
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
CVE-2015-5790 1 Apple 3 Iphone Os, Itunes, Safari 2016-12-22 6.8 MEDIUM N/A
WebKit, as used in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.
CVE-2015-5791 1 Apple 3 Iphone Os, Itunes, Safari 2016-12-22 6.8 MEDIUM N/A
WebKit, as used in JavaScriptCore in Apple iOS before 9 and iTunes before 12.3, allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site, a different vulnerability than other WebKit CVEs listed in APPLE-SA-2015-09-16-1 and APPLE-SA-2015-09-16-3.