Latest CVE Feed
-
7.5
HIGHCVE-2016-6799
Product: Apache Cordova Android 5.2.2 and earlier. The application calls methods of the Log class. Messages passed to these methods (Log.v(), Log.d(), Log.i(), Log.w(), and Log.e()) are stored in a series of circular buffers on the device. By default, a m... Read more
Affected Products : cordova- EPSS Score: %0.46
- Published: May. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-0893
Nextcloud Server before 9.0.58 and 10.0.5 and 11.0.3 are shipping a vulnerable JavaScript library for sanitizing untrusted user-input which suffered from a XSS vulnerability caused by a behaviour change in Safari 10.1 and 10.2. Note that Nextcloud employs... Read more
Affected Products : nextcloud_server- EPSS Score: %0.22
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8848
Allen Disk 1.6 has CSRF in setpass.php with an impact of changing a password.... Read more
- EPSS Score: %0.10
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8833
Zen Cart 1.6.0 has XSS in the main_page parameter to index.php. NOTE: 1.6.0 is not an official release but the vendor's README.md file offers a link to v160.zip with a description of "Download latest in-development version from github."... Read more
Affected Products : zen_cart- EPSS Score: %0.24
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6031
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execution.... Read more
Affected Products : atvise_scada- EPSS Score: %1.17
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2016-9692
IBM WebSphere Cast Iron Solution 7.0.0 and 7.5.0.0 is vulnerable to External Service Interaction attack, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability to induce the application to perform server-s... Read more
Affected Products : websphere_cast_iron_solution- EPSS Score: %0.61
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8792
An issue was discovered on Accellion FTA devices before FTA_9_12_180. There is XSS in home/seos/courier/user_add.html with the param parameter.... Read more
Affected Products : file_transfer_appliance- EPSS Score: %0.24
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5916
The America's First Federal Credit Union (FCU) Mobile Banking app 3.1.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : america\'s_first_fcu_mobile_banking- EPSS Score: %0.12
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8778
GitLab before 8.14.9, 8.15.x before 8.15.6, and 8.16.x before 8.16.5 has XSS via a SCRIPT element in an issue attachment or avatar that is an SVG document.... Read more
Affected Products : gitlab- EPSS Score: %0.07
- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8763
Cross-site scripting (XSS) vulnerability in modules/Base/Box/check_for_new_version.php in EPESI in Telaxus/EPESI 1.8.2 and earlier allows remote attackers to inject arbitrary web script or HTML via a crafted URI that lacks the cid parameter.... Read more
Affected Products : epesi- EPSS Score: %0.22
- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8762
GeniXCMS 1.0.2 has XSS triggered by an authenticated user who submits a page, as demonstrated by a crafted oncut attribute in a B element.... Read more
- EPSS Score: %0.32
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-6628
A vulnerability in SMART-SSL Accelerator functionality for Cisco Wide Area Application Services (WAAS) 6.2.1, 6.2.1a, and 6.2.3a could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition where the WAN optimization could ... Read more
Affected Products : wide_area_application_services- EPSS Score: %0.63
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5481
Trend Micro OfficeScan 11.0 before SP1 CP 6325 and XG before CP 1352 allows remote authenticated users to gain privileges by leveraging a leak of an encrypted password during a web-console operation.... Read more
Affected Products : officescan- EPSS Score: %0.48
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2016-5810
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.... Read more
Affected Products : webaccess- EPSS Score: %25.40
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4467
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate wh... Read more
Affected Products : qpid_proton- EPSS Score: %0.41
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-4442
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.... Read more
Affected Products : rack-mini-profiler- EPSS Score: %0.28
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8376
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.... Read more
- EPSS Score: %0.32
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.... Read more
Affected Products : craft_cms- EPSS Score: %0.28
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8339
PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.... Read more
Affected Products : panda_antivirus- EPSS Score: %0.15
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an ... Read more
- EPSS Score: %25.73
- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025