Latest CVE Feed
-
6.5
MEDIUMCVE-2017-9307
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.... Read more
- EPSS Score: %0.19
- Published: May. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9297
Open Redirect vulnerability in Hitachi Device Manager before 8.5.2-01 allows remote attackers to redirect users to arbitrary web sites.... Read more
Affected Products : device_manager- EPSS Score: %0.19
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9033
Cross-site request forgery (CSRF) vulnerability in Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows remote attackers to hijack the authentication of users for requests to start an update from an arbitrary source via a crafted request to SProt... Read more
Affected Products : serverprotect- EPSS Score: %0.13
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-9035
Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.... Read more
Affected Products : serverprotect- EPSS Score: %0.68
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7439
NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 might allow remote attackers to obtain sensitive information via vectors involving error messages.... Read more
Affected Products : oncommand_unified_manager_core_package- EPSS Score: %0.30
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5868
CRLF injection vulnerability in the web interface in OpenVPN Access Server 2.1.4 allows remote attackers to inject arbitrary HTTP headers and consequently conduct session fixation attacks and possibly HTTP response splitting attacks via "%0A" characters i... Read more
Affected Products : openvpn_access_server- EPSS Score: %5.51
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-4977
When processing authorization requests using the whitelabel views in Spring Security OAuth 2.0.0 to 2.0.9 and 1.0.0 to 1.0.5, the response_type parameter value was executed as Spring SpEL which enabled a malicious user to trigger remote code execution via... Read more
- EPSS Score: %94.09
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-0780
It was discovered that cf-release v231 and lower, Pivotal Cloud Foundry Elastic Runtime 1.5.x versions prior to 1.5.17 and Pivotal Cloud Foundry Elastic Runtime 1.6.x versions prior to 1.6.18 do not properly enforce disk quotas in certain cases. An attack... Read more
- EPSS Score: %0.39
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2799
An exploitable heap corruption vulnerability exists in the AddSst functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker can sen... Read more
Affected Products : marklogic- EPSS Score: %0.61
- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-5966
Sitecore CRM 8.1 Rev 151207 allows remote authenticated administrators to read arbitrary files via an absolute path traversal attack on sitecore/shell/download.aspx with the file parameter.... Read more
Affected Products : crm- EPSS Score: %0.27
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-8914
sinopia, as used in SAP HANA XS 1.00 and 2.00, allows remote attackers to hijack npm packages or host arbitrary files by leveraging an insecure user creation policy, aka SAP Security Note 2407694.... Read more
Affected Products : hana_xs- EPSS Score: %0.49
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8913
The Visual Composer VC70RUNTIME component in SAP NetWeaver AS JAVA 7.5 allows remote authenticated users to conduct XML External Entity (XXE) attacks via a crafted XML document in a request to irj/servlet/prt/portal/prtroot/com.sap.visualcomposer.BIKit.de... Read more
- EPSS Score: %0.55
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6821
Directory traversal vulnerability in Zimbra Collaboration Suite (aka ZCS) before 8.7.6 allows attackers to have unspecified impact via unknown vectors.... Read more
- EPSS Score: %5.24
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-5682
upload.php in the Powerplay Gallery plugin 3.3 for WordPress allows remote attackers to create arbitrary directories via vectors related to the targetDir variable.... Read more
Affected Products : powerplay_gallery- EPSS Score: %0.26
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1159
IBM Business Process Manager 8.0 and 8.5 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof th... Read more
Affected Products : business_process_manager- EPSS Score: %0.10
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-6112
IBM Distributed Marketing and Marketing Platform 8.6, 9.0, 9.1, and 10.0 could allow an authenticated user to escalate their privileges and gain administrative permissions over the web application. IBM X-Force ID: 118282.... Read more
- EPSS Score: %0.35
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-5657
Several REST service endpoints of Apache Archiva are not protected against Cross Site Request Forgery (CSRF) attacks. A malicious site opened in the same browser as the archiva site, may send an HTML response that performs arbitrary actions on archiva ser... Read more
Affected Products : archiva- EPSS Score: %0.12
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-4863
The Toshiba FlashAir SD-WD/WC series Class 6 model with firmware version 1.00.04 and later, FlashAir SD-WD/WC series Class 10 model W-02 with firmware version 2.00.02 and later, FlashAir SD-WE series Class 10 model W-03, FlashAir Class 6 model with firmwa... Read more
Affected Products : flashair- EPSS Score: %0.12
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2162
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows default credentials to be set for wireless LAN connections to the product when enabling the PhotoSh... Read more
Affected Products : flashair- EPSS Score: %0.12
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-7804
Untrusted search path vulnerability in 7 Zip for Windows 16.02 and earlier allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : 7-zip- EPSS Score: %0.64
- Published: May. 22, 2017
- Modified: Apr. 20, 2025