Latest CVE Feed
-
10.0
HIGHCVE-2017-11767
ChakraCore allows an attacker to gain the same user rights as the current user, due to the way that the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Memory Corruption Vulnerability".... Read more
Affected Products : chakracore- EPSS Score: %17.16
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12294
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected system. The vulnerability is due to insufficient input validation of some parameters... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.24
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12283
A vulnerability in the handling of 802.11w Protected Management Frames (PAF) by Cisco Aironet 3800 Series Access Points could allow an unauthenticated, adjacent attacker to terminate a valid user connection to an affected device, aka Denial of Service. Th... Read more
- EPSS Score: %0.40
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-12277
A vulnerability in the Smart Licensing Manager service of the Cisco Firepower 4100 Series Next-Generation Firewall (NGFW) and Firepower 9300 Security Appliance could allow an authenticated, remote attacker to inject arbitrary commands that could be execut... Read more
- EPSS Score: %0.55
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12274
A vulnerability in Extensible Authentication Protocol (EAP) ingress frame processing for the Cisco Aironet 1560, 2800, and 3800 Series Access Points could allow an unauthenticated, Layer 2 radio frequency (RF) adjacent attacker to cause the Access Point (... Read more
- EPSS Score: %0.71
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12243
A vulnerability in the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to obtain root shell privileges on t... Read more
Affected Products : unified_computing_system_manager_firmware firepower_9300_security_appliance_firmware firepower_4100_next-generation_firewall_firmware unified_computing_system_manager firepower_9300_security_appliance firepower_4110_next-generation_firewall firepower_4120_next-generation_firewall firepower_4140_next-generation_firewall firepower_4150_next-generation_firewall- EPSS Score: %40.22
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1552
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to link injection. By persuading a victim to click on a specially-crafted URL link, a remote attacker could exploit this vulnerability to conduct various attacks against the vulnerable system, inclu... Read more
Affected Products : infosphere_biginsights- EPSS Score: %0.19
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-1340
IBM Jazz Reporting Service (JRS) 6.0.4 could allow an authenticated user to obtain information on another server that the current report builder interacts with. IBM X-Force ID: 126455.... Read more
Affected Products : jazz_reporting_service- EPSS Score: %0.21
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1300
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 125162.... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.17
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1148
IBM OpenPages GRC Platform 7.2 and 7.3 with OpenPages Loss Event Entry (LEE) application could allow a user to obtain sensitive information including private APIs that could be used in further attacks against the system. IBM X-Force ID: 122201.... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.22
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1147
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.24
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12625
Apache Hive 2.1.x before 2.1.2, 2.2.x before 2.2.1, and 2.3.x before 2.3.1 expose an interface through which masking policies can be defined on tables or views, e.g., using Apache Ranger. When a view is created over a given table, the policy enforcement d... Read more
Affected Products : hive- EPSS Score: %0.47
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-3048
IBM OpenPages GRC Platform 7.1, 7.2, and 7.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wit... Read more
Affected Products : openpages_grc_platform- EPSS Score: %0.27
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16358
In radare 2.0.1, an out-of-bounds read vulnerability exists in string_scan_range() in libr/bin/bin.c when doing a string search.... Read more
Affected Products : radare2- EPSS Score: %0.18
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000245
The SSH Plugin stores credentials which allow jobs to access remote servers via the SSH protocol. User passwords and passphrases for encrypted SSH keys are stored in plaintext in a configuration file.... Read more
Affected Products : ssh- EPSS Score: %0.06
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000244
Jenkins Favorite Plugin version 2.2.0 and older is vulnerable to CSRF resulting in data modification... Read more
Affected Products : favorite- EPSS Score: %0.06
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-1000242
Jenkins Git Client Plugin 2.4.2 and earlier creates temporary file with insecure permissions resulting in information disclosure... Read more
Affected Products : git_client- EPSS Score: %0.01
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10953
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.0.14878. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %16.51
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-10940
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Joyent Smart Data Center prior to [email protected] (e469cf49-4de3-4658-8419-ab42837916ad). An attacker must firs... Read more
Affected Products : triton_datacenter- EPSS Score: %13.98
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14752
Mahara 15.04 before 15.04.15, 16.04 before 16.04.9, 16.10 before 16.10.6, and 17.04 before 17.04.4 are vulnerable to a user submitting a potential dangerous payload, e.g., XSS code, to be saved as their first name, last name, or display name in the profil... Read more
Affected Products : mahara- EPSS Score: %0.30
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025