National Vulnerability Database

Subscribe to National Vulnerability Database feed
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
Updated: 22 hours 15 min ago

CVE-2017-14535

Thu, 02/15/2018 - 23:29
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
Categories: Security News

CVE-2017-14536

Thu, 02/15/2018 - 23:29
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.
Categories: Security News

CVE-2017-14537

Thu, 02/15/2018 - 23:29
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.
Categories: Security News

CVE-2018-6189

Thu, 02/15/2018 - 23:29
F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested metadata tags for assets" issue.
Categories: Security News

CVE-2018-6324

Thu, 02/15/2018 - 23:29
F-Secure Radar (on-premises) before 2018-02-15 has an Unvalidated Redirect via the ReturnUrl parameter that triggers upon a user login.
Categories: Security News

CVE-2018-7176

Thu, 02/15/2018 - 23:29
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
Categories: Security News

CVE-2018-1000067

Thu, 02/15/2018 - 19:29
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.
Categories: Security News

CVE-2018-1000068

Thu, 02/15/2018 - 19:29
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenkins home directory is on a case-insensitive file system.
Categories: Security News

CVE-2018-5767

Thu, 02/15/2018 - 18:29
An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.
Categories: Security News

CVE-2018-6316

Thu, 02/15/2018 - 18:29
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.
Categories: Security News

CVE-2017-8973

Thu, 02/15/2018 - 17:29
An improper input validation vulnerability in HPE Matrix Operating Environment version 7.6 LR1 was found.
Categories: Security News

CVE-2017-8974

Thu, 02/15/2018 - 17:29
A Local Authentication Restriction Bypass vulnerability in HPE NonStop Server version L-Series: T6533L01 through T6533L01^ADN; J-Series and H-series: T6533H02 through T6533H04^ADF and T6533H05 through T6533H05^ADL was found.
Categories: Security News

CVE-2017-8975

Thu, 02/15/2018 - 17:29
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
Categories: Security News

CVE-2017-8976

Thu, 02/15/2018 - 17:29
A Remote Code Execution vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
Categories: Security News

CVE-2017-8977

Thu, 02/15/2018 - 17:29
A Remote Denial of Service vulnerability in Hewlett Packard Enterprise Moonshot Provisioning Manager Appliance version v1.20 was found.
Categories: Security News

CVE-2017-8978

Thu, 02/15/2018 - 17:29
A Remote Unauthorized Disclosure of Information vulnerability in HPE IceWall Products version MFA 4.0 proxy was found.
Categories: Security News

CVE-2017-8979

Thu, 02/15/2018 - 17:29
Security vulnerabilities in the HPE Integrated Lights-Out 2 (iLO 2) firmware could be exploited remotely to allow authentication bypass, code execution, and denial of service.
Categories: Security News

CVE-2017-8980

Thu, 02/15/2018 - 17:29
A Remote Disclosure of Information vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
Categories: Security News

CVE-2017-8981

Thu, 02/15/2018 - 17:29
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506 was found.
Categories: Security News

CVE-2017-8982

Thu, 02/15/2018 - 17:29
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
Categories: Security News

Pages