Latest CVE Feed
-
9.8
CRITICALCVE-2017-15985
Basic B2B Script allows SQL Injection via the product_view1.php pid or id parameter.... Read more
Affected Products : basic_b2b_script- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15984
Creative Management System (CMS) Lite 1.4 allows SQL Injection via the S parameter to index.php.... Read more
Affected Products : creative_management_system_lite- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15980
US Zip Codes Database Script 1.0 allows SQL Injection via the state parameter.... Read more
Affected Products : us_zip_codes_database_script- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15979
Shareet - Photo Sharing Social Network 1.0 allows SQL Injection via the photo parameter.... Read more
Affected Products : shareet- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15977
Protected Links - Expiring Download Links 1.0 allows SQL Injection via the username parameter.... Read more
Affected Products : expiring_download_links- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16230
In admin/write-post.php in Typecho through 1.1, one can log in to the background page, write a new article, and add payload in the article content, resulting in XSS via index.php/action/contents-post-edit.... Read more
Affected Products : typecho- EPSS Score: %0.21
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-9377
A command injection was identified on Barco ClickShare Base Unit devices with CSM-1 firmware before 1.7.0.3 and CSC-1 firmware before 1.10.0.10. An attacker with access to the product's web API can exploit this vulnerability to completely compromise the v... Read more
Affected Products : clickshare_csm-1_firmware clickshare_csc-1_firmware clickshare_csc-1 clickshare_csm-1- EPSS Score: %5.71
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15971
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.... Read more
Affected Products : same_date_pro- EPSS Score: %2.22
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15968
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.... Read more
Affected Products : mybuildersite- EPSS Score: %2.34
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15963
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.... Read more
Affected Products : gigs_script- EPSS Score: %2.34
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15936
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.... Read more
Affected Products : pandora_fms- EPSS Score: %0.27
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-5996
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.... Read more
- EPSS Score: %0.14
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3771
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.... Read more
- EPSS Score: %0.20
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15911
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as th... Read more
Affected Products : openfire- EPSS Score: %0.42
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15907
SQL injection vulnerability in phpCollab 2.5.1 and earlier allows remote attackers to execute arbitrary SQL commands via the id parameter to newsdesk/newsdesk.php.... Read more
Affected Products : phpcollab- EPSS Score: %0.49
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1363
IBM Team Concert (RTC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.25
- Published: Oct. 25, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1169
IBM DOORS next Generation (DNG/RRC) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a tru... Read more
Affected Products : rational_collaborative_lifecycle_management- EPSS Score: %0.27
- Published: Oct. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1212
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 is vulnerable to a denial of service when viewing or opening a large file. IBM X-Force ID: 123852.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.24
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1210
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could allow an unauthenticated attacker to inject data into log files made to look legitimate. IBM X-Force ID: 123850.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.26
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15863
Cross Site Scripting (XSS) exists in the wp-noexternallinks plugin before 3.5.19 for WordPress via the date1 or date2 parameter to wp-admin/options-general.php.... Read more
Affected Products : wp_no_external_links- EPSS Score: %0.19
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025