Latest CVE Feed
-
9.8
CRITICALCVE-2017-1002027
Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.... Read more
Affected Products : rk-responsive-contact-form- EPSS Score: %1.08
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10842
SQL injection vulnerability in the baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : basercms- EPSS Score: %0.67
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10898
SQL injection vulnerability in the A-Member and A-Member for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : a-member- EPSS Score: %0.22
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11187
phpMyFAQ before 2.9.8 does not properly mitigate brute-force attacks that try many passwords in attempted logins quickly.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.27
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11329
GLPI before 9.1.5 allows SQL injection via an ajax/getDropdownValue.php request with an entity_restrict parameter that is not a list of integers.... Read more
Affected Products : glpi- EPSS Score: %0.29
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11386
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x4707 due to lack of proper user input validation in cmdHandlerNewReportScheduler.dll. Formerly ZDI-CAN-4549.... Read more
Affected Products : control_manager- EPSS Score: %7.24
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11502
Technicolor DPC3928AD DOCSIS devices allow remote attackers to read arbitrary files via a request starting with "GET /../" on TCP port 4321.... Read more
- EPSS Score: %8.00
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7273
Dell Integrated Remote Access Controller (iDRAC) 7/8 before 2.21.21.21 has XXE.... Read more
- EPSS Score: %0.71
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11582
dayrui FineCms 5.0.9 has SQL Injection via the num parameter in an action=related or action=tags request to libraries/Template.php.... Read more
Affected Products : finecms- EPSS Score: %0.29
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11583
dayrui FineCms 5.0.9 has SQL Injection via the catid parameter in an action=related request to libraries/Template.php.... Read more
Affected Products : finecms- EPSS Score: %0.25
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1175
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID... Read more
- EPSS Score: %0.68
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12199
The Etoile Ultimate Product Catalog plugin 4.2.11 for WordPress has SQL injection with these wp-admin/admin-ajax.php POST actions: catalogue_update_order list-item, video_update_order video-item, image_update_order list-item, tag_group_update_order list_i... Read more
Affected Products : ultimate_product_catalog- EPSS Score: %1.96
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1221
IBM Tivoli Endpoint Manager (IBM BigFix 9.2 and 9.5) does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. IBM X-Force ID: 123861.... Read more
Affected Products : bigfix_platform- EPSS Score: %0.26
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7988
The handle_regservice_request function in mDNSResponder before 625.41.2 allows remote attackers to execute arbitrary code or cause a denial of service (NULL pointer dereference) via unspecified vectors.... Read more
Affected Products : mac_os_x iphone_os watchos mdnsresponder airport_base_station_firmware airport_base_station- EPSS Score: %1.93
- Published: Jun. 26, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-12466
CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors related to ssl_halen when running ccn-lite-sim, which trigger an out-of-bounds access.... Read more
Affected Products : ccn-lite- EPSS Score: %0.41
- Published: Feb. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2015-8360
An unspecified resource in Atlassian Bamboo before 5.9.9 and 5.10.x before 5.10.0 allows remote attackers to execute arbitrary Java code via serialized data to the JMS port.... Read more
Affected Products : bamboo- EPSS Score: %1.19
- Published: Feb. 08, 2016
- Modified: Apr. 12, 2025
-
9.8
CRITICALCVE-2017-13771
Lexmark Scan To Network (SNF) 3.2.9 and earlier stores network configuration credentials in plaintext and transmits them in requests, which allows remote attackers to obtain sensitive information via requests to (1) cgi-bin/direct/printer/prtappauth/apps/... Read more
Affected Products : scan_to_network- EPSS Score: %1.53
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14080
Authentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific part of the console using a blank password.... Read more
Affected Products : mobile_security- EPSS Score: %2.88
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14145
HelpDEZk 1.1.1 has SQL Injection in app\modules\admin\controllers\loginController.php via the admin/login/getWarningInfo/id/ PATH_INFO, related to the selectWarning function.... Read more
Affected Products : helpdezk- EPSS Score: %0.25
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14147
An issue was discovered on FiberHome User End Routers Bearing Model Number AN1020-25 which could allow an attacker to easily restore a router to its factory settings by simply browsing to the link http://[Default-Router-IP]/restoreinfo.cgi & execute it. D... Read more
- EPSS Score: %73.44
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025