Latest CVE Feed
-
5.3
MEDIUMCVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.... Read more
Affected Products : craft_cms- EPSS Score: %0.28
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8339
PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.... Read more
Affected Products : panda_antivirus- EPSS Score: %0.15
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an ... Read more
- EPSS Score: %25.73
- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8593
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %4.89
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8592
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %3.54
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8590
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %3.54
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2156
Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : vivaldi_installer_for_windows- EPSS Score: %0.51
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2154
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUS... Read more
Affected Products : just_school hanako hanako_police hanako_pro just_frontier just_government just_jump_class just_office just_police- EPSS Score: %0.30
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2151
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : booking_calendar- EPSS Score: %0.23
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2139
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php.... Read more
Affected Products : cs-cart- EPSS Score: %0.15
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2136
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via specially crafted HTTP Referer headers.... Read more
- EPSS Score: %1.08
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2108
Untrusted search path vulnerability in PrimeDrive Desktop Application 1.4.3 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : primedrive_desktop_application- EPSS Score: %0.47
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-2104
The Business LaLa Call App for Android 1.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : business_lala_call- EPSS Score: %0.29
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2094
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in Workflow and the "MultiReport" function to alter or delete information via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.15
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2093
Cybozu Garoon 3.0.0 to 4.2.3 allow remote attackers to obtain tokens used for CSRF protection via unspecified vectors.... Read more
Affected Products : garoon- EPSS Score: %0.30
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3620
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the... Read more
Affected Products : automatic_service_request- EPSS Score: %0.08
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8305
The UDFclient (before 0.8.8) custom strlcpy implementation has a buffer overflow. UDFclient's strlcpy is used only on systems with a C library (e.g., glibc) that lacks its own strlcpy.... Read more
Affected Products : udfclient- EPSS Score: %0.62
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8298
cnvs.io Canvas 3.3.0 has XSS in the title and content fields of a "Posts > Add New" action, and during creation of new tags and users.... Read more
Affected Products : canvas- EPSS Score: %0.19
- Published: Apr. 27, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1170
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 8.0 could allow a local user to hijack a user's session. IBM X-Force ID: 123230.... Read more
Affected Products : websphere_commerce- EPSS Score: %0.08
- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8283
dpkg-source in dpkg 1.3.0 through 1.18.23 is able to use a non-GNU patch program and does not offer a protection mechanism for blank-indented diff hunks, which allows remote attackers to conduct directory traversal attacks via a crafted Debian source pack... Read more
Affected Products : dpkg- EPSS Score: %1.07
- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025