Latest CVE Feed
-
9.8
CRITICALCVE-2017-3962
Password recovery exploitation vulnerability in the non-certificate-based authentication mechanism in McAfee Network Security Management (NSM) before 8.2.7.42.2 allows attackers to crack user passwords via unsalted hashes.... Read more
Affected Products : network_security_manager- EPSS Score: %0.05
- Published: Jun. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20059
jaxb/JaxbEngine.java in Pippo 1.11.0 allows XXE.... Read more
Affected Products : pippo- EPSS Score: %0.40
- Published: Dec. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-20173
Zoho ManageEngine OpManager 12.3 before 123238 allows SQL injection via the getGraphData API.... Read more
Affected Products : manageengine_opmanager- EPSS Score: %12.83
- Published: Dec. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-15987
Fake Magazine Cover Script allows SQL Injection via the rate.php value parameter or the content.php id parameter.... Read more
Affected Products : fake_magazine_cover_script- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2018-20770
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. There is Blind SQL Injection.... Read more
- EPSS Score: %0.35
- Published: Feb. 10, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21042
An issue was discovered on Samsung mobile devices with N(7.x), O(8.x), and P(9.0) software. Dual Messenger allows installation of an arbitrary APK with resultant privileged code execution. The Samsung ID is SVE-2018-13299 (December 2018).... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Apr. 08, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-21161
Certain NETGEAR devices are affected by incorrect configuration of security settings. This affects D7800 before 1.0.1.34, R7800 before 1.0.2.46, and R9000 before 1.0.3.16.... Read more
- EPSS Score: %0.31
- Published: Apr. 23, 2020
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-5533
A vulnerability in the server content cache of TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analy... Read more
- EPSS Score: %0.54
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5600
The Data Warehouse component in NetApp OnCommand Insight before 7.2.3 allows remote attackers to obtain administrative access by leveraging a default privileged account.... Read more
Affected Products : oncommand_insight- EPSS Score: %0.82
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16846
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /manageApplications.do?method=AddSubGroup haid parameter.... Read more
- EPSS Score: %12.31
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16847
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /showresource.do resourceid parameter in a showPlasmaView action.... Read more
- EPSS Score: %12.31
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16783
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.... Read more
Affected Products : cms_made_simple- EPSS Score: %16.94
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16887
The portal on FiberHome Mobile WIFI Device Model LM53Q1 VH519R05C01S38 uses SOAP based web services in order to interact with the portal. Unauthorized Access to Web Services can result in disclosure of the WLAN key/password.... Read more
- EPSS Score: %5.62
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-2943
Vulnerability in the Oracle Fusion Middleware MapViewer component of Oracle Fusion Middleware (subcomponent: Map Builder). Supported versions that are affected are 12.2.1.2.0 and 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker... Read more
Affected Products : fusion_middleware_mapviewer- EPSS Score: %2.49
- Published: Jul. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-17464
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002570 DeviceIoControl request.... Read more
Affected Products : antivirus- EPSS Score: %0.35
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17598
Affiliate MLM Script 1.0 has SQL Injection via the product-category.php key parameter.... Read more
Affected Products : affiliate_mlm_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17602
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.... Read more
Affected Products : advance_b2b_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17618
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.... Read more
Affected Products : kickstarter_clone_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17739
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has directory traversal via the /storage.html rp parameter, allowing an attacker to read or write to files.... Read more
- EPSS Score: %21.26
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7576
DragonWave Horizon 1.01.03 wireless radios have hardcoded login credentials (such as the username of energetic and password of wireless) meant to allow the vendor to access the devices. These credentials can be used in the web interface or by connecting t... Read more
- EPSS Score: %0.34
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025