Atlassian Confluence Server before 5.9.11 has XSS on the viewmyprofile.action page.
Category Archives: NVD
National Vulnerability Database – This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
CVE-2015-2886
iBaby M6 allows remote attackers to obtain sensitive information, related to the ibabycloud.com service.
CVE-2016-6534
Opmantek NMIS before 4.3.7c has command injection via man, finger, ping, trace, and nslookup in the tools.pl CGI script. Versions before 8.5.12G might be affected in non-default configurations.
CVE-2016-5073
CloudView NMS before 2.10a has XSS via SNMP.
CVE-2016-5057
OSRAM SYLVANIA Osram Lightify Pro through 2016-07-26 does not use SSL pinning.
CVE-2015-6035
Opsview before 2015-11-06 has XSS via SNMP.
CVE-2016-4319
Atlassian JIRA Server before 7.1.9 has CSRF in auditing/settings.
CVE-2015-2885
Lens Peek-a-View has a password of 2601hx for the backdoor admin account, a password of user for the backdoor user account, and a password of guest for the backdoor guest account.
CVE-2016-5682
Swagger-UI before 2.2.1 has XSS via the Default field in the Definitions section.
CVE-2015-8276
LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC files.