Latest CVE Feed
-
6.5
MEDIUMCVE-2017-7620
MantisBT before 1.3.11, 2.x before 2.3.3, and 2.4.x before 2.4.1 omits a backslash check in string_api.php and consequently has conflicting interpretations of an initial \/ substring as introducing either a local pathname or a remote hostname, which leads... Read more
Affected Products : mantisbt- EPSS Score: %0.32
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9090
reg.php in Allen Disk 1.6 doesn't check if isset($_SESSION['captcha']['code'])==1, which makes it possible to bypass the CAPTCHA via an empty $_POST['captcha'].... Read more
- EPSS Score: %0.20
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7968
An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the sy... Read more
Affected Products : wonderware_indusoft_web_studio- EPSS Score: %0.04
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2017-7907
An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attack... Read more
Affected Products : wonderware_historian_client- EPSS Score: %0.08
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6027
An Arbitrary File Upload issue was discovered in 3S-Smart Software Solutions GmbH CODESYS Web Server. The following versions of CODESYS Web Server, part of the CODESYS WebVisu web browser visualization software, are affected: CODESYS Web Server Versions 2... Read more
Affected Products : web_server- EPSS Score: %1.99
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5174
An Authentication Bypass issue was discovered in Geutebruck IP Camera G-Cam/EFD-2250 Version 1.11.0.12. An authentication bypass vulnerability has been identified. The existing file system architecture could allow attackers to bypass the access control th... Read more
- EPSS Score: %38.22
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-4013
Banner Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to obtain product information via HTTP response header.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.23
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9030
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a directory traversal attack that bypasses a uniqid protection mechanism, and makes it easier to read arbitrary uploaded files.... Read more
Affected Products : b2j_contact- EPSS Score: %2.08
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
9.6
CRITICALCVE-2017-3882
A vulnerability in the Universal Plug-and-Play (UPnP) implementation in the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, Layer 2-adjacent attacker to execute arbitrary code or cause a denial of service (DoS) condition. The remote co... Read more
Affected Products : rv110w rv215w small_business_rv_router_firmware small_business_rv_router_firmware_1.0 rv132w rv134w rv042 rv042g rv320 rv325 +7 more products- EPSS Score: %0.79
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.9
HIGHCVE-2017-3873
A vulnerability in the Plug-and-Play (PnP) subsystem of the Cisco Aironet 1800, 2800, and 3800 Series Access Points running a Lightweight Access Point (AP) or Mobility Express image could allow an unauthenticated, adjacent attacker to execute arbitrary co... Read more
Affected Products : aironet_access_point_firmware aironet_access_point_software aironet_access_point_software aironet_1830e aironet_1830i aironet_1850e aironet_1850i aironet_2800e aironet_2800i aironet_3800e +2 more products- EPSS Score: %0.25
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10238
In QSEE in all Android releases from CAF using the Linux kernel access control may potentially be bypassed due to a page alignment issue.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6885
An error when handling certain external commands and services related to the FlexNet Inventory Agent and FlexNet Beacon of the Flexera Software FlexNet Manager Suite 2017 before 2017 R1 and 2014 R3 through 2016 R1 SP1 can be exploited to gain elevated pri... Read more
Affected Products : flexnet_manager_suite- EPSS Score: %0.41
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-10372
The Eir D1000 modem does not properly restrict the TR-064 protocol, which allows remote attackers to execute arbitrary commands via TCP port 7547, as demonstrated by opening WAN access to TCP port 80, retrieving the login password (which defaults to the W... Read more
- EPSS Score: %91.13
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-10242
A time-of-check time-of-use race condition could potentially exist in the secure file system in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10239
In TrustZone access control policy may potentially be bypassed in all Android releases from CAF using the Linux kernel due to improper input validation an integer overflow vulnerability leading to a buffer overflow could potentially occur and a buffer ove... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-10237
If shared content protection memory were passed as the secure camera memory buffer by the HLOS to a trusted application (TA) in all Android releases from CAF using the Linux kernel, the TA would not detect an issue and it would be treated as secure memory... Read more
Affected Products : android- EPSS Score: %0.05
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-8998
In TrustZone an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2015-8997
In TrustZone a time-of-check time-of-use race condition could potentially exist in a listener routine in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2014-9936
In TrustZone a time-of-check time-of-use race condition could potentially exist in an authentication routine in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- EPSS Score: %0.10
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9932
In TrustZone, an integer overflow vulnerability can potentially occur in all Android releases from CAF using the Linux kernel due to an improper address range computation.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025