Latest CVE Feed
-
9.8
CRITICALCVE-2017-1000501
Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.... Read more
- EPSS Score: %5.92
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-1000499
phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.... Read more
Affected Products : phpmyadmin- EPSS Score: %10.45
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-1000498
AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution... Read more
Affected Products : androidsvg- EPSS Score: %1.19
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000497
Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution... Read more
Affected Products : pepperminty-wiki- EPSS Score: %1.55
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-1000496
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.... Read more
Affected Products : commsy- EPSS Score: %0.83
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000495
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account... Read more
Affected Products : quickapps_cms- EPSS Score: %0.21
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-1000494
Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact... Read more
Affected Products : miniupnpd- EPSS Score: %0.17
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000493
Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover... Read more
Affected Products : rocket.chat- EPSS Score: %0.25
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000492
Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration... Read more
Affected Products : desktop- EPSS Score: %0.37
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000491
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.... Read more
Affected Products : shiba- EPSS Score: %0.37
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-1000490
Mautic versions 1.0.0 - 2.11.0 are vulnerable to allowing any authorized Mautic user session (must be logged into Mautic) to use the Filemanager to download any file from the server that the web user has access to.... Read more
- EPSS Score: %0.34
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2017-1000489
Mautic versions 2.0.0 - 2.11.0 with a SSO plugin installed could allow a disabled user to still login using email address... Read more
- EPSS Score: %0.27
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000488
Mautic version 2.1.0 - 2.11.0 is vulnerable to an inline JS XSS attack when using Mautic forms on a Mautic landing page using GET parameters to pre-populate the form.... Read more
- EPSS Score: %0.24
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000487
Plexus-utils before 3.0.16 is vulnerable to command injection because it does not correctly process the contents of double quoted strings.... Read more
- EPSS Score: %13.17
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2017-1000485
Nylas Mail Lives 2.2.2 uses 0755 permissions for $HOME/.nylas-mail, which allows local users to obtain sensitive authentication information via standard filesystem operations.... Read more
Affected Products : nylas_mail- EPSS Score: %0.04
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000484
By linking to a specific url in Plone 2.5-5.1rc1 with a parameter, an attacker could send you to his own website. On its own this is not so bad: the attacker could more easily link directly to his own website instead. But in combination with another attac... Read more
Affected Products : plone- EPSS Score: %0.20
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-1000483
Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.... Read more
Affected Products : plone- EPSS Score: %0.29
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-1000482
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.... Read more
Affected Products : plone- EPSS Score: %0.29
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-1000481
When you visit a page where you need to login, Plone 2.5-5.1rc1 sends you to the login form with a 'came_from' parameter set to the previous url. After you login, you get redirected to the page you tried to view before. An attacker might try to abuse this... Read more
Affected Products : plone- EPSS Score: %0.20
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-1000480
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.... Read more
Affected Products : smarty- EPSS Score: %0.86
- Published: Jan. 03, 2018
- Modified: Nov. 21, 2024