Latest CVE Feed
-
9.8
CRITICALCVE-2016-4819
The printfDx function in Takumi Yamada DX Library for Borland C++ 3.13f through 3.16b, DX Library for Gnu C++ 3.13f through 3.16b, and DX Library for Visual C++ 3.13f through 3.16b allows remote attackers to execute arbitrary code via a crafted string.... Read more
Affected Products : dx_library- EPSS Score: %2.68
- Published: Jun. 19, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-5065
Sierra Wireless GX 440 devices with ALEOS firmware 4.3.2 allow Embedded_Ace_Set_Task.cgi command injection.... Read more
- EPSS Score: %0.66
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-6696
sound/soc/msm/qdsp6v2/msm-ds2-dap-config.c in a Qualcomm QDSP6v2 driver in Android before 2016-10-05 allows attackers to cause a denial of service or possibly have unspecified other impact via a large negative value for the data length, aka Qualcomm inter... Read more
Affected Products : android- EPSS Score: %0.22
- Published: Oct. 10, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2016-6875
Infinite recursion in wddx in Facebook HHVM before 3.15.0 allows attackers to have unspecified impact via unknown vectors.... Read more
Affected Products : hhvm- EPSS Score: %0.46
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8218
An issue was discovered in Cloud Foundry Foundation routing-release versions prior to 0.142.0 and cf-release versions 203 to 231. Incomplete validation logic in JSON Web Token (JWT) libraries can allow unprivileged attackers to impersonate other users to ... Read more
- EPSS Score: %0.58
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8902
SQL injection vulnerability in the categoriesServlet servlet in dotCMS before 3.3.1 allows remote not authenticated attackers to execute arbitrary SQL commands via the sort parameter.... Read more
Affected Products : dotcms- EPSS Score: %1.44
- Published: Nov. 14, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-0305
F5 SSL Intercept iApp version 1.5.0 - 1.5.7 is vulnerable to an unauthenticated, remote attack that may allow modification of the BIG-IP system configuration, extraction of sensitive system files, and possible remote command execution on the system when d... Read more
Affected Products : ssl_intercept_iapp- EPSS Score: %3.09
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000220
soyuka/pidusage <=1.1.4 is vulnerable to command injection in the module resulting in arbitrary command execution... Read more
Affected Products : pidusage- EPSS Score: %11.82
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000197
October CMS build 412 is vulnerable to file path modification in asset move functionality resulting in creating creating malicious files on the server.... Read more
Affected Products : october- EPSS Score: %0.41
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002027
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.... Read more
Affected Products : rk-responsive-contact-form- EPSS Score: %1.08
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10842
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.67
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10898
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : a-member- EPSS Score: %0.22
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11187
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.27
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11502
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.... Read more
- EPSS Score: %8.00
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11583
dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php.... Read more
Affected Products : finecms- EPSS Score: %0.25
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1175
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID... Read more
- EPSS Score: %0.68
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12199
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_i... Read more
Affected Products : ultimate_product_catalog- EPSS Score: %1.96
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1221
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.... Read more
Affected Products : bigfix_platform- EPSS Score: %0.26
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12466
CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access.... Read more
Affected Products : ccn-lite- EPSS Score: %0.41
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8360
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.... Read more
Affected Products : bamboo- EPSS Score: %1.19
- Published: Feb. 08, 2016
- Modified: Apr. 12, 2025