Latest CVE Feed
-
9.8
CRITICALCVE-2017-5949
JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 22, allows remote attackers to cause a denial of service (heap-based out-of-bounds write and application crash) or possibly have unspecified other impact via crafted JavaScript ... Read more
Affected Products : safari- EPSS Score: %1.82
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-10315
Jensen of Scandinavia AS Air:Link 3G (AL3G) version 2.23m (Rev. 3), Air:Link 5000AC (AL5000AC) version 1.13, and Air:Link 59300 (AL59300) version 1.04 (Rev. 4) devices allow remote attackers to conduct Open Redirect attacks via the submit-url parameter to... Read more
- EPSS Score: %0.22
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-8803
The maintenance module in Huawei FusionStorage V100R003C30U1 allows attackers to create documents according to special rules to obtain the OS root privilege of FusionStorage.... Read more
Affected Products : fusionstorage- EPSS Score: %0.03
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2016-8802
The security policy processing module in Huawei Secospace USG6300 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6500 with software V500R001C20SPC100, V500R001C20SPC101, V500R001C20SPC200; Secospace USG6600 with softwa... Read more
- EPSS Score: %0.21
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8801
Huawei OceanStor 5600 V3 with V300R003C00C10 and earlier versions allows attackers with administrator privilege to inject a command into a specific command's parameters, and run this injected command with root privilege.... Read more
- EPSS Score: %0.23
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8796
Huawei USG9520 V300R001C01, USG9560 V300R001C01, and USG9580 V300R001C01 allow unauthenticated attackers to send abnormal DHCP request packets to the affected products to trigger a DoS condition.... Read more
- EPSS Score: %0.20
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2016-8790
Huawei CloudEngine 5800 with software before V200R001C00SPC700, CloudEngine 6800 with software before V200R001C00SPC700, CloudEngine 7800 with software before V200R001C00SPC700, CloudEngine 8800 with software before V200R001C00SPC700, CloudEngine 12800 wi... Read more
- EPSS Score: %0.04
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-8781
Huawei Secospace USG6300 with software V500R001C20 and V500R001C20SPC200PWE, Secospace USG6500 with software V500R001C20, Secospace USG6600 with software V500R001C20 and V500R001C20SPC200PWE allow remote attackers with specific permission to log in to a d... Read more
- EPSS Score: %0.28
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-8274
Huawei PC client software HiSuite 4.0.5.300_OVE has a dynamic link library (DLL) hijack vulnerability; an attacker can make the system load malicious DLL files to execute arbitrary code.... Read more
Affected Products : hisuite- EPSS Score: %0.02
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-8670
Huawei LogCenter V100R001C10 could allow an authenticated attacker to add abnormal device information to the log collection module, causing denial of service.... Read more
Affected Products : logcenter- EPSS Score: %0.16
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2014-8571
Apps on Huawei Ascend P6 mobile phones with software EDGE-U00 V100R001C17B508SP01 and earlier versions before V100R001C17B508SP02; EDGE-T00 V100R001C01B508SP01 and earlier versions before V100R001C01B508SP02; EDGE-C00 V100R001C92B508SP02 and earlier versi... Read more
- EPSS Score: %0.09
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2014-8570
Huawei S9300, S9303, S9306, S9312 with software V100R002; S7700, S7703, S7706, S7712 with software V100R003, V100R006, V200R001, V200R002, V200R003, V200R005; S9300E, S9303E, S9306E, S9312E with software V200R001; S9700, S9703, S9706, S9712 with software ... Read more
Affected Products : s7700_firmware s9300_firmware s9700_firmware s9300e_firmware s9303_firmware s9306_firmware s9312_firmware s7703_firmware s7706_firmware s7712_firmware +42 more products- EPSS Score: %0.11
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7386
citymont/symetrie v.0.9.6 is vulnerable to a reflected XSS in symetrie-master/app/commands/page.php (model parameter).... Read more
Affected Products : symetrie- EPSS Score: %0.24
- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9990
IBM iNotes 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : inotes- EPSS Score: %0.25
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7359
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.... Read more
- EPSS Score: %0.28
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5185
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.... Read more
Affected Products : sentinel- EPSS Score: %0.56
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7318
Siklu EtherHaul devices before 7.4.0 are vulnerable to a remote command execution (RCE) vulnerability. This vulnerability allows a remote attacker to execute commands and retrieve information such as usernames and plaintext passwords from the device with ... Read more
- EPSS Score: %10.09
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-4977
EMC RSA Archer Security Operations Management with RSA Unified Collector Framework versions prior to 1.3.1.52 contain a sensitive information disclosure vulnerability that could potentially be exploited by malicious users to compromise an affected system.... Read more
Affected Products : rsa_archer_security_operations_management- EPSS Score: %0.07
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6846
Cross-site scripting (XSS) vulnerability in Open-Xchange (OX) AppSuite backend before 7.6.2-rev59, 7.8.0 before 7.8.0-rev38, 7.8.2 before 7.8.2-rev8; AppSuite frontend before 7.6.2-rev47, 7.8.0 before 7.8.0-rev30, and 7.8.2 before 7.8.2-rev8; Office Web b... Read more
Affected Products : open-xchange_appsuite_backend open-xchange_appsuite_frontend documentconverter-api office_web- EPSS Score: %0.30
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2687
Siemens RUGGEDCOM ROX I (all versions) contain a vulnerability in the integrated web server at port 10000/TCP which is prone to reflected Cross-Site Scripting attacks if an unsuspecting user is induced to click on a malicious link.... Read more
Affected Products : ruggedcom_rox_i- EPSS Score: %0.32
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025