Latest CVE Feed
-
9.8
CRITICALCVE-2017-14698
ASUS DSL-AC51, DSL-AC52U, DSL-AC55U, DSL-N55U C1, DSL-N55U D1, DSL-AC56U, DSL-N10_C1, DSL-N12U C1, DSL-N12E C1, DSL-N14U, DSL-N14U-B1, DSL-N16, DSL-N16U, DSL-N17U, DSL-N66U, and DSL-AC750 routers allow remote attackers to change passwords of arbitrary use... Read more
Affected Products : dsl-n12e_c1_firmware dsl-n17u_firmware dsl-n14u-b1_firmware dsl-ac51_firmware dsl-ac52u_firmware dsl-ac55u_firmware dsl-n55u_c1_firmware dsl-n55u_d1_firmware dsl-ac56u_firmware dsl-n10_c1_firmware +22 more products- Published: Jan. 29, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2017-14612
"Shpock Boot Sale & Classifieds" app before 3.17.0 -- aka shpock-boot-sale-classifieds/id557153158 -- for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information v... Read more
Affected Products : shpock- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
9.1
CRITICALCVE-2017-14611
SSRF (Server Side Request Forgery) in Cockpit 0.13.0 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter, related to use of the discontinued aheinze/fetch_url_contents component.... Read more
Affected Products : cockpit- Published: Apr. 10, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-14594
The printable searchrequest issue resource in Atlassian Jira before version 7.2.12 and from version 7.3.0 before 7.6.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in the jqlQuery query para... Read more
- Published: Jan. 12, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-14593
Sourcetree for Windows had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for Windows is able to exploit this issue to gain code execution on... Read more
Affected Products : sourcetree- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-14592
Sourcetree for macOS had several argument and command injection bugs in Mercurial and Git repository handling. An attacker with permission to commit to a repository linked in Sourcetree for macOS is able to exploit this issue to gain code execution on the... Read more
Affected Products : sourcetree- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2017-14537
trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.... Read more
Affected Products : trixbox- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2017-14536
trixbox 2.8.0.4 has XSS via the PATH_INFO to /maint/index.php or /user/includes/language/langChooser.php.... Read more
Affected Products : trixbox- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2017-14535
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.... Read more
Affected Products : trixbox- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2017-14523
WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as... Read more
Affected Products : wondercms- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2017-14522
In WonderCMS 2.3.1, the application's input fields accept arbitrary user input resulting in execution of malicious JavaScript. NOTE: the vendor disputes this issue stating that this is a feature that enables only a logged in administrator to write execute... Read more
Affected Products : wondercms- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2017-14521
In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.... Read more
Affected Products : wondercms- Published: Jan. 26, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14481
In the MMM::Agent::Helpers::Network::send_arp function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution wi... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14480
In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution wi... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14479
In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution wi... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14478
In the MMM::Agent::Helpers::Network::clear_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14477
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for FreeBSD), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14476
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Solaris), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14475
In the MMM::Agent::Helpers::Network::add_ip function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1 (for Linux), a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with t... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2017-14474
In the MMM::Agent::Helpers::_execute function in MySQL Multi-Master Replication Manager (MMM) mmm_agentd 2.2.1, a specially crafted MMM protocol message can cause a shell command injection resulting in arbitrary command execution with the privileges of th... Read more
Affected Products : mysql_multi-master_replication_manager- Published: May. 09, 2018
- Modified: Nov. 21, 2024