Latest CVE Feed
-
7.1
HIGHCVE-2017-12256
A vulnerability in the Akamai Connect feature of Cisco Wide Area Application Services (WAAS) Appliances could allow an unauthenticated, remote attacker to cause a denial-of-service (DoS) condition on an affected device. The vulnerability is due to certain... Read more
Affected Products : wide_area_application_services- EPSS Score: %0.31
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-13993
An Uncontrolled Search Path or Element issue was discovered in i-SENS SmartLog Diabetes Management Software, Version 2.4.0 and prior versions. An uncontrolled search path element vulnerability has been identified which could be exploited by placing a spec... Read more
Affected Products : smartlog_diabetes_management_software- EPSS Score: %0.15
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000120
[ERPNext][Frappe Version <= 7.1.27] SQL injection vulnerability in frappe.share.get_users allows remote authenticated users to execute arbitrary SQL commands via the fields parameter.... Read more
Affected Products : frappe- EPSS Score: %0.37
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000118
Akka HTTP versions <= 10.0.5 Illegal Media Range in Accept Header Causes StackOverflowError Leading to Denial of Service... Read more
Affected Products : http_server- EPSS Score: %0.39
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000109
The custom Details view of the Static Analysis Utilities based OWASP Dependency-Check Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into thi... Read more
Affected Products : owasp_dependency-check- EPSS Score: %0.05
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-1000106
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. Its SCM content REST API supports the pipeli... Read more
Affected Products : blue_ocean- EPSS Score: %0.03
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000104
The Config File Provider Plugin is used to centrally manage configuration files that often include secrets, such as passwords. Users with only Overall/Read access to Jenkins were able to access URLs directly that allowed viewing these files. Access to vie... Read more
Affected Products : config_file_provider- EPSS Score: %0.03
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000103
The custom Details view of the Static Analysis Utilities based DRY Plugin, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to this plugin could insert arbitrary HTML into this view.... Read more
Affected Products : dry- EPSS Score: %0.05
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000102
The Details view of some Static Analysis Utilities based plugins, was vulnerable to a persisted cross-site scripting vulnerability: Malicious users able to influence the input to these plugins, for example the console output which is parsed to extract bui... Read more
Affected Products : static_analysis_utilities- EPSS Score: %0.05
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000090
Role-based Authorization Strategy Plugin was not requiring requests to its API be sent via POST, thereby opening itself to Cross-Site Request Forgery attacks. This allowed attackers to add administrator role to any user, or to remove the authorization con... Read more
Affected Products : role-based_authorization_strategy- EPSS Score: %0.06
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000088
The Sidebar Link plugin allows users able to configure jobs, views, and agents to add entries to the sidebar of these objects. There was no input validation, which meant users were able to use javascript: schemes for these links.... Read more
Affected Products : sidebar_link- EPSS Score: %0.06
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000084
Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins.... Read more
Affected Products : parameterized_trigger- EPSS Score: %0.04
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14995
The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5... Read more
- EPSS Score: %0.30
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.9
CRITICALCVE-2017-12822
Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors.... Read more
Affected Products : sentinel_ldk_rte_firmware- EPSS Score: %0.30
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12820
Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.... Read more
Affected Products : sentinel_ldk_rte_firmware- EPSS Score: %0.88
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0829
An elevation of privilege vulnerability in the Motorola bootloader. Product: Android. Versions: Android kernel. Android ID: A-62345044.... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0827
An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-62539960. References: M-ALPS03353876, M-ALPS03353861, M-ALPS03353869, M-ALPS03353867, M-ALPS03353872.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0826
An elevation of privilege vulnerability in the HTC bootloader. Product: Android. Versions: Android kernel. Android ID: A-34949781.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0824
An elevation of privilege vulnerability in the Broadcom wifi driver. Product: Android. Versions: Android kernel. Android ID: A-37622847. References: B-V2017063001.... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-0823
An information disclosure vulnerability in the Android system (rild). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37896655.... Read more
Affected Products : android- EPSS Score: %0.28
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025