Latest CVE Feed
-
4.3
MEDIUMCVE-2016-4863
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmwa... Read more
Affected Products : flashair- EPSS Score: %0.12
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2162
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoSh... Read more
Affected Products : flashair- EPSS Score: %0.12
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-7804
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : 7-zip- EPSS Score: %0.64
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-4903
Cross-site scripting vulnerability in WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.32
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4901
Untrusted search path vulnerability in The installer of e-Tax Software all versions allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : e-tax- EPSS Score: %0.42
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4854
Cross-site request forgery (CSRF) vulnerability in L-04D firmware version V10a and V10b allows remote attackers to hijack the authentication of administrators to perform arbitrary operations via unspecified vectors.... Read more
- EPSS Score: %0.14
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6999
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- EPSS Score: %0.68
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6997
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- EPSS Score: %0.68
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6994
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- EPSS Score: %0.68
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2523
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. macOS before 10.12.5 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "Foundation" component. It allows remote attackers... Read more
- EPSS Score: %13.05
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6641
A vulnerability in the TCP connection handling functionality of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to disable TCP ports and cause a denial of service (DoS) condition on an affected system. The vulne... Read more
Affected Products : remote_expert_manager- EPSS Score: %1.36
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9137
Ceragon FibeAir IP-10 wireless radios through 7.2.0 have a default password of mateidu for the mateidu account (a hidden user account established by the vendor). This account can be accessed via both the web interface and SSH. In the web interface, this s... Read more
Affected Products : fiberair_ip-10_firmware- EPSS Score: %0.28
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9132
A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mosquitto, a lightweight message broker, to send information between devices.... Read more
- EPSS Score: %0.26
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9101
import.php (aka the Phonebook import feature) in PlaySMS 1.4 allows remote code execution via vectors involving the User-Agent HTTP header and PHP code in the name of a file.... Read more
Affected Products : playsms- EPSS Score: %78.87
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7620
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads... Read more
Affected Products : mantisbt- EPSS Score: %0.32
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9090
reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].... Read more
- EPSS Score: %0.20
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7968
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the sy... Read more
Affected Products : wonderware_indusoft_web_studio- EPSS Score: %0.04
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2017-7907
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attack... Read more
Affected Products : wonderware_historian_client- EPSS Score: %0.08
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6027
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2... Read more
Affected Products : web_server- EPSS Score: %1.99
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5174
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control th... Read more
- EPSS Score: %38.22
- Published: May. 19, 2017
- Modified: Apr. 20, 2025