Latest CVE Feed
-
6.1
MEDIUMCVE-2017-14347
NexusPHP 1.5.beta5.20120707 has XSS in the returnto parameter to fun.php in a delete action.... Read more
Affected Products : nexusphp- EPSS Score: %0.24
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14346
upload.php in tianchoy/blog through 2017-09-12 allows unrestricted file upload and PHP code execution by using the image/jpeg, image/pjpeg, image/png, or image/gif content type for a .php file.... Read more
- EPSS Score: %0.97
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14266
tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.... Read more
Affected Products : tcpreplay- EPSS Score: %1.78
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-9227
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.... Read more
Affected Products : alegrocart- EPSS Score: %4.41
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-9226
Multiple SQL injection vulnerabilities in AlegroCart 1.2.8 allow remote administrators to execute arbitrary SQL commands via the download parameter in the (1) check_download and possibly (2) check_filename function in upload/admin2/model/products/model_ad... Read more
Affected Products : alegrocart- EPSS Score: %1.75
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8353
Cross-site scripting (XSS) vulnerability in the Role Scoper plugin before 1.3.67 for WordPress allows remote attackers to inject arbitrary web script or HTML via the object_name parameter in a rs-object_role_edit page to wp-admin/admin.php.... Read more
Affected Products : role_scoper- EPSS Score: %0.45
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8349
Cross-site scripting (XSS) vulnerability in SourceBans before 2.0 pre-alpha allows remote attackers to inject arbitrary web script or HTML via the advSearch parameter to index.php.... Read more
Affected Products : sourcebans- EPSS Score: %10.33
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-4688
Ellucian (formerly SunGard) Banner Student 8.5.1.2 through 8.7 allow remote attackers to enumerate user accounts via a series of requests.... Read more
Affected Products : banner_student- EPSS Score: %0.23
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14308
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllUnregisterServer+0x0000000000006ddd."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14306
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllUnregisterServer+0x0000000000006e10."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14304
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllGetClassObject+0x00000000000043e0."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14303
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at STDUJBIG2File!DllGetClassObject+0x0000000000003047."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14301
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllUnregisterServer+0x00000000000076d3.... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14299
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Data from Faulting Address controls subsequent Write Address starting at STDUJBIG2File!DllGetClassObject+0x000000000000384b."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14293
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to "Heap Corruption starting at wow64!Wow64LdrpInitialize+0x00000000000008e1."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14291
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllUnregisterServer+0x00000000000076d8."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14289
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "User Mode Write AV starting at STDUJBIG2File!DllGetClassObject+0x000000000000303e."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14287
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .jb2 file, related to a "Read Access Violation on Control Flow starting at STDUJBIG2File+0x00000000000015eb."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14285
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlInterlo... Read more
- EPSS Score: %0.05
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14284
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77400000!RtlGetCurr... Read more
- EPSS Score: %0.05
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025