Latest CVE Feed
-
7.5
HIGHCVE-2017-3771
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.... Read more
- EPSS Score: %0.20
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15911
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as th... Read more
Affected Products : openfire- EPSS Score: %0.42
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15907
SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php.... Read more
Affected Products : phpcollab- EPSS Score: %0.49
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1363
IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.25
- Published: Oct. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1169
IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.27
- Published: Oct. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1212
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.24
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1210
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.26
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15863
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.... Read more
Affected Products : wp_no_external_links- EPSS Score: %0.19
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2015-6839
The parse function in MSA vot.Ar 3.1 does not check whether a candidate receives more than one vote, which allows physically proximate attackers to cast multiple votes for a candidate via a crafted RFID ballot tag.... Read more
Affected Products : vot.ar- EPSS Score: %0.07
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-5533
SQL injection vulnerability in counter-options.php in the Count Per Day plugin before 3.4.1 for WordPress allows remote authenticated administrators to execute arbitrary SQL commands via the cpd_keep_month parameter to wp-admin/options-general.php. NOTE:... Read more
Affected Products : count_per_day- EPSS Score: %9.52
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-5379
Cross-site scripting (XSS) vulnerability in actions.hsp in the Ajax WebMail interface in AXIGEN Mail Server before 9.0 allows remote attackers to inject arbitrary web script or HTML via an email attachment.... Read more
Affected Products : axigen_mail_server- EPSS Score: %0.10
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-2878
Multiple cross-site request forgery (CSRF) vulnerabilities in Hexis HawkEye G 3.0.1.4912 allow remote attackers to hijack the authentication of administrators for requests that (1) add arbitrary accounts via the name parameter to interface/rest/accounts/j... Read more
Affected Products : hawkeye_g- EPSS Score: %0.33
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2012-4570
SQL injection vulnerability in LetoDMS_Core/Core/inc.ClassDMS.php in LetoDMS (formerly MyDMS) before 3.3.8 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : letodms- EPSS Score: %0.57
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2012-4567
Multiple cross-site scripting (XSS) vulnerabilities in LetoDMS (formerly MyDMS) before 3.3.8 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters in (1) inc/inc.ClassUI.php or (2) out/out.DocumentNotify.php.... Read more
Affected Products : letodms- EPSS Score: %0.26
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2011-4334
edit.php in LabWiki 1.1 and earlier does not properly verify uploaded user files, which allows remote authenticated users to upload arbitrary PHP files via a PHP file with a .gif extension in the userfile parameter.... Read more
Affected Products : labwiki- EPSS Score: %3.85
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15808
In phpMyFaq before 2.9.9, there is CSRF in admin/ajax.config.php.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.11
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15805
Cisco Small Business SA520 and SA540 devices with firmware 2.1.71 and 2.2.0.7 allow ../ directory traversal in scgi-bin/platform.cgi via the thispage parameter, for reading arbitrary files.... Read more
- EPSS Score: %0.53
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15567
The certificate import component in IDEMIA (formerly Morpho) MorphoSmart 1300 Series (aka MSO 1300 Series) devices allows local users to obtain a command shell, and consequently gain privileges, via unspecified vectors. NOTE: the vendor disputes this bec... Read more
- EPSS Score: %0.02
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12796
The Reporting Compatibility Add On before 2.0.4 for OpenMRS, as distributed in OpenMRS Reference Application before 2.6.1, does not authenticate users when deserializing XML input into ReportSchema objects. The result is that remote unauthenticated users ... Read more
Affected Products : openmrs- EPSS Score: %5.73
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15782
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADImage+0x00000000000032eb."... Read more
- EPSS Score: %0.36
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025