Latest CVE Feed
-
6.5
MEDIUMCVE-2017-10280
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Test Framework). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows low privileged attacker wi... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.73
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10259
Vulnerability in the Oracle Access Manager component of Oracle Fusion Middleware (subcomponent: Web Server Plugin). The supported version that is affected is 11.1.2.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access ... Read more
Affected Products : coreid_access- EPSS Score: %2.12
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10158
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Core). Supported versions that are affected are 8.54, 8.55 and 8.56. Easily exploitable vulnerability allows unauthenticated attacker with networ... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.46
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10055
Vulnerability in the Oracle iPlanet Web Server component of Oracle Fusion Middleware (subcomponent: Admin Graphical User Interface). The supported version that is affected is 7.0. Easily exploitable vulnerability allows unauthenticated attacker with netwo... Read more
Affected Products : iplanet_web_server- EPSS Score: %0.45
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12288
A vulnerability in the web-based management interface of Cisco Unified Contact Center Express could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected device. The vulnerability is due to ... Read more
Affected Products : finesse- EPSS Score: %0.20
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12296
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some paramete... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.23
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12287
A vulnerability in the cluster database (CDB) management component of Cisco Expressway Series Software and Cisco TelePresence Video Communication Server (VCS) Software could allow an authenticated, remote attacker to cause the CDB process on an affected s... Read more
- EPSS Score: %0.50
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.7
MEDIUMCVE-2017-14956
AlienVault USM v5.4.2 and earlier offers authenticated users the functionality of exporting generated reports via the "/ossim/report/wizard_email.php" script. Besides offering an export via a local download, the script also offers the possibility to send ... Read more
Affected Products : unified_security_management- EPSS Score: %0.71
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-7715
Cross-site request forgery (CSRF) vulnerability in the Realtyna RPL (com_rpl) component before 8.9.5 for Joomla! allows remote attackers to hijack the authentication of administrators for requests that add a user via an add_user action to administrator/in... Read more
Affected Products : realtyna_property_listing- EPSS Score: %0.14
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2014-7242
The SumaHo application 3.0.0 and earlier for Android and the SumaHo "driving capability" diagnosis result transmission application 1.2.2 and earlier for Android allow man-in-the-middle attackers to spoof servers and obtain sensitive information by leverag... Read more
- EPSS Score: %0.26
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9367
A directory traversal vulnerability in the BlackBerry Workspaces Server could potentially allow an attacker to execute or upload arbitrary files, or reveal the content of arbitrary files anywhere on the web server by crafting a URL with a manipulated POST... Read more
- EPSS Score: %0.62
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14009
An Information Exposure issue was discovered in ProMinent MultiFLEX M10a Controller web interface. When an authenticated user uses the Change Password feature on the application, the current password for the user is specified in plaintext. This may allow ... Read more
- EPSS Score: %0.26
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3758
Improper access controls on several Android components in the Lenovo Service Framework application can be exploited to enable remote code execution.... Read more
Affected Products : service_framework- EPSS Score: %2.36
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2014-9118
The web administrative portal in Zhone zNID GPON 2426A before S3.0.501 allows remote attackers to execute arbitrary commands via shell metacharacters in the ipAddr parameter to zhnping.cmd.... Read more
- EPSS Score: %52.29
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15296
The Java component in SAP CRM has CSRF. This is SAP Security Note 2478964.... Read more
Affected Products : customer_relationship_management- EPSS Score: %0.11
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-9147
Fiyo CMS 2.0.1.8 allows remote attackers to obtain sensitive information via a direct request to the database backup file in .backup/.... Read more
Affected Products : fiyo_cms- EPSS Score: %17.92
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15363
Directory traversal vulnerability in public/examples/resources/getsource.php in Luracast Restler through 3.0.0, as used in the restler extension before 1.7.1 for TYPO3, allows remote attackers to read arbitrary files via the file parameter.... Read more
Affected Products : restler- EPSS Score: %66.72
- Published: Oct. 15, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-10617
The ifmap service that comes bundled with Contrail has an XML External Entity (XXE) vulnerability that may allow an attacker to retrieve sensitive system files. Affected releases are Juniper Networks Contrail 2.2 prior to 2.21.4; 3.0 prior to 3.0.3.4; 3.1... Read more
Affected Products : contrail- EPSS Score: %8.57
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15276
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows an authenticated user to gain superuser privileges: Content Server allows uploading content using batches (TAR archives... Read more
Affected Products : documentum_content_server- EPSS Score: %2.61
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15014
OpenText Documentum Content Server (formerly EMC Documentum Content Server) through 7.3 contains the following design gap, which allows authenticated users to download arbitrary content files regardless of the attacker's repository permissions: When an au... Read more
Affected Products : documentum_content_server- EPSS Score: %3.97
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025