Latest CVE Feed
-
4.9
MEDIUMCVE-2016-5810
upAdminPg.asp in Advantech WebAccess before 8.1_20160519 allows remote authenticated administrators to obtain sensitive password information via unspecified vectors.... Read more
Affected Products : webaccess- EPSS Score: %25.40
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-4467
The C client and C-based client bindings in the Apache Qpid Proton library before 0.13.1 on Windows do not properly verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate wh... Read more
Affected Products : qpid_proton- EPSS Score: %0.41
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-4442
The rack-mini-profiler gem before 0.10.1 for Ruby allows remote attackers to obtain sensitive information about allocated strings and objects by leveraging incorrect ordering of security checks.... Read more
Affected Products : rack-mini-profiler- EPSS Score: %0.28
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2015-8257
The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_custom.shtml, (3) app_index.shtml, or (4) app_params.sht... Read more
Affected Products : network_camera_firmware cannon_network_camera explosion-protected_camera fixed_box_camera fixed_bullet_camera fixed_dome_camera modular_camera onboard_camera panoramic_camera ptz_camera +1 more products- EPSS Score: %19.13
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8388
GeniXCMS 1.0.2 allows remote attackers to bypass the alertDanger MSG_USER_EMAIL_EXIST protection mechanism via a register.php?act=edit&id=1 request.... Read more
- EPSS Score: %0.43
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8376
GeniXCMS 1.0.2 has XSS triggered by an authenticated comment that is mishandled during a mouse operation by an administrator.... Read more
- EPSS Score: %0.32
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8385
Craft CMS before 2.6.2976 does not prevent modification of the URL in a forgot-password email message.... Read more
Affected Products : craft_cms- EPSS Score: %0.28
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10351
Telegram Desktop 0.10.19 uses 0755 permissions for $HOME/.TelegramDesktop, which allows local users to obtain sensitive authentication information via standard filesystem operations.... Read more
Affected Products : telegram_desktop- EPSS Score: %0.05
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8081
Poor cryptographic salt initialization in admin/inc/template_functions.php in GetSimple CMS 3.3.13 allows a network attacker to escalate privileges to an arbitrary user or conduct CSRF attacks via calculation of a session cookie or CSRF nonce.... Read more
Affected Products : getsimple_cms- EPSS Score: %0.35
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-8339
PSKMAD.sys in Panda Free Antivirus 18.0 allows local users to cause a denial of service (BSoD) via a crafted DeviceIoControl request to \\.\PSMEMDriver.... Read more
Affected Products : panda_antivirus- EPSS Score: %0.15
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7981
Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before 1.5.5 with a syntax value in its first argument, and an ... Read more
- EPSS Score: %25.73
- Published: Apr. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-8593
Directory traversal vulnerability in upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via a .. (dot dot) in the dID parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %4.89
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8592
log_query_system.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %3.54
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8590
log_query_dlp.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %3.54
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2016-8587
dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sen... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %0.56
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2016-8586
detected_potential_files.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code as the root user via shell metacharacters in the cache_id parameter.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %3.54
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-8584
Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier uses predictable session values, which allows remote attackers to bypass authentication by guessing the value.... Read more
Affected Products : threat_discovery_appliance- EPSS Score: %4.08
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2156
Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : vivaldi_installer_for_windows- EPSS Score: %0.51
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2154
Untrusted search path vulnerability in Hanako 2017, Hanako 2016, Hanako 2015, Hanako Pro 3, JUST Office 3 [Standard], JUST Office 3 [Eco Print Package], JUST Office 3 & Tri-De DataProtect Package, JUST Government 3, JUST Jump Class 2, JUST Frontier 3, JUS... Read more
Affected Products : just_school hanako hanako_police hanako_pro just_frontier just_government just_jump_class just_office just_police- EPSS Score: %0.30
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2151
Cross-site scripting vulnerability in Booking Calendar version 7.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : booking_calendar- EPSS Score: %0.23
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025