Latest CVE Feed
-
9.1
CRITICALCVE-2017-10282
Vulnerability in the Core RDBMS component of Oracle Database Server. Supported versions that are affected are 12.1.0.2 and 12.2.0.1. Easily exploitable vulnerability allows high privileged attacker having Create Session, Execute Catalog Role privilege wit... Read more
- EPSS Score: %1.90
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
4.7
MEDIUMCVE-2017-10273
Vulnerability in the Oracle JDeveloper component of Oracle Fusion Middleware (subcomponent: Deployment). Supported versions that are affected are 11.1.1.7.0, 11.1.1.7.1, 11.1.1.9.0, 11.1.2.4.0, 12.1.3.0.0 and 12.2.1.2.0. Difficult to exploit vulnerability... Read more
Affected Products : jdeveloper- EPSS Score: %0.14
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2017-10262
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Difficult to exploit vulnerability allows unauthenticated attacker with network acces... Read more
Affected Products : access_manager- EPSS Score: %1.32
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-10140
Postfix before 2.11.10, 3.0.x before 3.0.10, 3.1.x before 3.1.6, and 3.2.x before 3.2.2 might allow local users to gain privileges by leveraging undocumented functionality in Berkeley DB 2.x and later, related to reading settings from DB_CONFIG in the cur... Read more
Affected Products : postfix- EPSS Score: %0.24
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
8.2
HIGHCVE-2017-10068
Vulnerability in the Oracle Business Intelligence Enterprise Edition component of Oracle Fusion Middleware (subcomponent: Analytics Web Dashboards). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthentica... Read more
Affected Products : business_intelligence- EPSS Score: %2.17
- Published: Jan. 18, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1002201
In haml versions prior to version 5.0.0.beta.2, when using user input to perform tasks on the server, characters like < > " ' must be escaped properly. In this case, the ' character was missed. An attacker can manipulate the input to introduce additional ... Read more
- EPSS Score: %0.82
- Published: Oct. 15, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1002157
modulemd 1.3.1 and earlier uses an unsafe function for processing externally provided data, leading to remote code execution.... Read more
Affected Products : modulemd- EPSS Score: %0.72
- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1002152
Bodhi 2.9.0 and lower is vulnerable to cross-site scripting resulting in code injection caused by incorrect validation of bug titles.... Read more
Affected Products : bodhi- EPSS Score: %0.30
- Published: Jan. 10, 2019
- Modified: Nov. 21, 2024
-
7.1
HIGHCVE-2017-1002102
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using a secret, configMap, projected or downwardAPI volume can trigger deletion of arbitrary files/directories from the nodes where they are running... Read more
Affected Products : kubernetes- EPSS Score: %0.36
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
9.6
CRITICALCVE-2017-1002101
In Kubernetes versions 1.3.x, 1.4.x, 1.5.x, 1.6.x and prior to versions 1.7.14, 1.8.9 and 1.9.4 containers using subpath volume mounts with any volume type (including non-privileged pods, subject to file permissions) can access files/directories outside o... Read more
Affected Products : kubernetes- EPSS Score: %33.57
- Published: Mar. 13, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-1000600
WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugin... Read more
Affected Products : wordpress- EPSS Score: %18.20
- Published: Sep. 06, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000510
Croogo version 2.3.1-17-g6f82e6c contains a Cross Site Scripting (XSS) vulnerability in Page name that can result in execution of javascript code.... Read more
Affected Products : croogo- EPSS Score: %0.32
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000509
Dolibarr version 6.0.2 contains a Cross Site Scripting (XSS) vulnerability in Product details that can result in execution of javascript code.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.18
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000508
Invoice Plane version 1.5.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Client's details that can result in execution of javascript code . This vulnerability appears to have been fixed in 1.5.5 and later.... Read more
Affected Products : invoiceplane- EPSS Score: %0.37
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000507
Canvs Canvas version 3.4.2 contains a Cross Site Scripting (XSS) vulnerability in User's details that can result in denial of service and execution of javascript code.... Read more
Affected Products : canvas- EPSS Score: %0.32
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000506
Mautic version 2.11.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in Company's name that can result in denial of service and execution of javascript code.... Read more
- EPSS Score: %0.40
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-1000505
In Jenkins Script Security Plugin version 1.36 and earlier, users with the ability to configure sandboxed Groovy scripts are able to use a type coercion feature in Groovy to create new `File` objects from strings. This allowed reading arbitrary files on t... Read more
Affected Products : script_security- EPSS Score: %0.32
- Published: Jan. 25, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2017-1000504
A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Pl... Read more
Affected Products : jenkins- EPSS Score: %1.40
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2017-1000503
A race condition during Jenkins 2.81 through 2.94 (inclusive); 2.89.1 startup could result in the wrong order of execution of commands during initialization. This could in rare cases result in failure to initialize the setup wizard on the first startup. T... Read more
Affected Products : jenkins- EPSS Score: %2.30
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-1000502
Users with permission to create or configure agents in Jenkins 1.37 and earlier could configure an EC2 agent to run arbitrary shell commands on the master node whenever the agent was supposed to be launched. Configuration of these agents now requires the ... Read more
Affected Products : ec2- EPSS Score: %0.67
- Published: Jan. 24, 2018
- Modified: Nov. 21, 2024