Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 7.5

    HIGH
    CVE-2017-18594

    nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-methods.nse.... Read more

    Affected Products : nmap
    • Published: Aug. 29, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18593

    The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.... Read more

    Affected Products : updraftplus
    • Published: Aug. 28, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-18592

    The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.... Read more

    Affected Products : wc_catalog_enquiry
    • Published: Aug. 27, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18590

    The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.... Read more

    Affected Products : timesheet
    • Published: Aug. 27, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-18589

    An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.... Read more

    Affected Products : cookie
    • Published: Aug. 26, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2017-18588

    An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.... Read more

    Affected Products : security-framework
    • Published: Aug. 26, 2019
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2017-18587

    An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.... Read more

    Affected Products : hyper
    • Published: Aug. 26, 2019
    • Modified: Nov. 21, 2024
  • 9.1

    CRITICAL
    CVE-2017-18586

    The insert-pages plugin before 3.2.4 for WordPress has directory traversal via custom template paths.... Read more

    Affected Products : insert_pages
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2017-18585

    The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.... Read more

    Affected Products : posts_in_page
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2017-18584

    The post-pay-counter plugin before 2.731 for WordPress has no permissions check for an update-settinga action.... Read more

    Affected Products : post_pay_counter post_pay_counter
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2017-18583

    The post-pay-counter plugin before 2.731 for WordPress has PHP Object Injection.... Read more

    Affected Products : post_pay_counter post_pay_counter
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18582

    The time-sheets plugin before 1.5.2 for WordPress has multiple XSS issues.... Read more

    Affected Products : time_sheets
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18581

    The time-sheets plugin before 1.5.0 for WordPress has XSS via the old timesheet list.... Read more

    Affected Products : time_sheets
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2017-18580

    The shortcodes-ultimate plugin before 5.0.1 for WordPress has remote code execution via a filter in a meta, post, or user shortcode.... Read more

    Affected Products : shortcodes_ultimate
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18579

    The corner-ad plugin before 1.0.8 for WordPress has XSS.... Read more

    Affected Products : corner_ad
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18578

    The crafty-social-buttons plugin before 1.5.8 for WordPress has XSS.... Read more

    Affected Products : crafty_social_buttons
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18577

    The mailchimp-for-wp plugin before 4.1.8 for WordPress has XSS via the return value of add_query_arg.... Read more

    Affected Products : mailchimp
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18576

    The event-notifier plugin before 1.2.1 for WordPress has XSS via the loading animation.... Read more

    Affected Products : event_notifier
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18575

    The newstatpress plugin before 1.2.5 for WordPress has multiple stored XSS issues.... Read more

    Affected Products : newstatpress
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2017-18574

    The ninja-forms plugin before 3.0.31 for WordPress has insufficient HTML escaping in the builder.... Read more

    Affected Products : ninja_forms newstatpress
    • Published: Aug. 22, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 292864 Results