Latest CVE Feed
-
10.0
HIGHCVE-2017-8116
The management interface for the Teltonika RUT9XX routers (aka LuCI) with firmware 00.03.265 and earlier allows remote attackers to execute arbitrary commands with root privileges via shell metacharacters in the username parameter in a login request.... Read more
Affected Products : rut950_firmware rut900_firmware rut905_firmware rut955_firmware rut900 rut905 rut950 rut955- EPSS Score: %7.46
- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3997
NetApp Clustered Data ONTAP allows man-in-the-middle attackers to obtain sensitive information, gain privileges, or cause a denial of service by leveraging failure to enable SMB signing enforcement in its default state.... Read more
Affected Products : clustered_data_ontap- EPSS Score: %0.43
- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8894
AeroAdmin 4.1 uses an insecure protocol (HTTP) to perform software updates. An attacker can hijack an update via man-in-the-middle in order to execute code in the machine.... Read more
Affected Products : aeroadmin- EPSS Score: %0.96
- Published: Jul. 02, 2017
- Modified: Apr. 20, 2025
-
6.2
MEDIUMCVE-2017-10706
When Antiy Antivirus Engine before 5.0.0.05171547 scans a special ZIP archive, it crashes with a stack-based buffer overflow because a fixed path length is used.... Read more
Affected Products : antivirus_engine- EPSS Score: %0.06
- Published: Jul. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2298
The mcollective-sshkey-security plugin before 0.5.1 for Puppet uses a server-specified identifier as part of a path where a file is written. A compromised server could use this to write a file to an arbitrary location on the client with the filename appen... Read more
Affected Products : mcollective-sshkey-security- EPSS Score: %0.27
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-10709
The lockscreen on Elephone P9000 devices (running Android 6.0) allows physically proximate attackers to bypass a wrong-PIN lockout feature by pressing backspace after each PIN guess.... Read more
- EPSS Score: %0.03
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-9105
Multiple cross-site scripting (XSS) vulnerabilities in Synology Video Station 1.2 before 1.2-0455, 1.5 before 1.5-0772, and 1.6 before 1.6-0847 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) file name or (2) collec... Read more
Affected Products : video_station- EPSS Score: %0.25
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-10668
A Padding Oracle exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). Under an MITM condition within the OSCI infrastructure, an attacker needs to send crafted protocol messages to analyse the ... Read more
Affected Products : osci_transport_library- EPSS Score: %0.08
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6046
An Insufficiently Protected Credentials issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Sensitive information is insufficiently protected during transmission and v... Read more
Affected Products : airlink_raven_xe_firmware airlink_raven_xt_firmware airlink_raven_xe airlink_raven_xt- EPSS Score: %0.38
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6042
A Cross-Site Request Forgery issue was discovered in Sierra Wireless AirLink Raven XE, all versions prior to 4.0.14, and AirLink Raven XT, all versions prior to 4.0.11. Affected devices do not verify if a request was intentionally sent by the logged-in us... Read more
Affected Products : airlink_raven_xe_firmware airlink_raven_xt_firmware airlink_raven_xe airlink_raven_xt- EPSS Score: %0.13
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6041
An Unrestricted Upload issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dua... Read more
Affected Products : a320_firmware a325_firmware a371_firmware a520_master_firmware a520_slave_firmware a530_firmware a542_firmware a571_firmware check_bin_grader_firmware flowlineqc_t376_firmware +34 more products- EPSS Score: %0.63
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-6038
A Cross-Site Request Forgery issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. The web application does not sufficiently verify that requests were provided by the user who submitted the request.... Read more
- EPSS Score: %0.08
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6032
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.... Read more
- EPSS Score: %0.46
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-9358
A Hard-Coded Passwords issue was discovered in Marel Food Processing Systems M3000 terminal associated with the following systems: A320, A325, A371, A520 Master, A520 Slave, A530, A542, A571, Check Bin Grader, FlowlineQC T376, IPM3 Dual Cam v132, IPM3 Dua... Read more
Affected Products : a320_firmware a325_firmware a371_firmware a520_master_firmware a520_slave_firmware a530_firmware a542_firmware a571_firmware check_bin_grader_firmware flowlineqc_t376_firmware +34 more products- EPSS Score: %0.54
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10682
SQL injection vulnerability in the administrative backend in Piwigo through 2.9.1 allows remote users to execute arbitrary SQL commands via the cat_false or cat_true parameter in the comments or status page to cat_options.php.... Read more
Affected Products : piwigo- EPSS Score: %0.32
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2851
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can cause a buffer overflow.... Read more
- EPSS Score: %0.29
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2849
In the web management interface in Foscam C1 Indoor HD cameras with application firmware 2.52.2.37, a specially crafted HTTP request can allow for a user to inject arbitrary shell characters during NTP server configuration resulting in command injection. ... Read more
- EPSS Score: %1.62
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10671
Heap-based Buffer Overflow in the de_dotdot function in libhttpd.c in sthttpd before 2.27.1 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a crafted filename.... Read more
Affected Products : sthttpd- EPSS Score: %0.29
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10667
In index.php in Zen Cart 1.6.0, the products_id parameter can cause XSS.... Read more
Affected Products : zen_cart- EPSS Score: %0.22
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10042
Authorization Bypass in the Web interface of Arcadyan SLT-00 Star* (aka Swisscom Internet-Box) devices before R7.7 allows unauthorized reconfiguration of the static routing table via an unauthenticated HTTP request, leading to denial of service and inform... Read more
- EPSS Score: %0.20
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025