CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
Tenda AC7 through V15.03.06.44_CN, AC9 through V15.03.05.19(6318)_CN, and AC10 through V15.03.06.23_CN devices have a Stack-based Buffer Overflow via a long limitSpeed or limitSpeedup parameter to an unspecified /goform URI.
IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140044.
DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.
BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.
Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.
IBM DB2 for Linux, UNIX and Windows 9.7, 10.1, 10.5, and 11.1 (includes DB2 Connect Server) contains a vulnerability that could allow a local user to overwrite arbitrary files owned by the DB2 instance owner. IBM X-Force ID: 140043.
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
GeniXCMS 1.1.5 has XSS via the dbuser or dbhost parameter during step 1 of installation.
views/auth.go in Orange Forum 1.4.0 allows Open Redirection via the next parameter to /login or /signup.
OCS Inventory 2.4.1 lacks a proper XML parsing configuration, allowing the use of external entities. This issue can be exploited by an attacker sending a crafted HTTP request in order to exfiltrate information or cause a Denial of Service.
