Latest CVE Feed
-
5.4
MEDIUMCVE-2017-1683
IBM Connections Engagement Center 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a t... Read more
- EPSS Score: %0.25
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1606
IBM Financial Transaction Manager (FTM) for Multi-Platform (MP) 3.0.0.0 through 3.0.0.7 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete informatio... Read more
Affected Products : financial_transaction_manager- EPSS Score: %0.57
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1549
IBM Sterling File Gateway 2.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted s... Read more
Affected Products : sterling_file_gateway- EPSS Score: %0.29
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1548
IBM Sterling File Gateway 2.2 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 131288.... Read more
Affected Products : sterling_file_gateway- EPSS Score: %0.50
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-8358
Huawei EC156, EC176, and EC177 USB Modem products with software before UTPS-V200R003B015D02SP07C1014 (23.015.02.07.1014) and before V200R003B015D02SP08C1014 (23.015.02.08.1014) use a weak ACL for the "Mobile Partner" directory, which allows remote attacke... Read more
- EPSS Score: %0.78
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17551
The Backup and Restore feature in Mobotap Dolphin Browser for Android 12.0.2 suffers from an arbitrary file write vulnerability when attempting to restore browser settings from a malicious Dolphin Browser backup file. This arbitrary file write vulnerabili... Read more
Affected Products : dolphin- EPSS Score: %0.32
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17110
Techno Portfolio Management Panel 1.0 allows an attacker to inject SQL commands via a single.php?id= request.... Read more
Affected Products : techno_-_portfolio_management_panel- EPSS Score: %17.71
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11319
Perspective ICM Investigation & Case 5.1.1.16 allows remote authenticated users to modify access level permissions and consequently gain privileges by leveraging insufficient validation methods and missing cross server side checking mechanisms.... Read more
Affected Products : perspective- EPSS Score: %2.37
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17497
In Tidy 5.7.0, the prvTidyTidyMetaCharset function in clean.c allows attackers to cause a denial of service (Segmentation Fault), because the currentNode variable in the "children of the head" processing feature is modified in the loop without validating ... Read more
Affected Products : tidy- EPSS Score: %0.27
- Published: Dec. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3111
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Sensitive tokens are included in http GET requests under certain circumstances.... Read more
Affected Products : experience_manager- EPSS Score: %9.61
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11296
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. A cross-site scripting vulnerability in Apache Sling Servlets Post 2.3.20 has been resolved in Adobe Experience Manager.... Read more
Affected Products : experience_manager- EPSS Score: %1.47
- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11482
The Kibana fix for CVE-2017-8451 was found to be incomplete. With X-Pack installed, Kibana versions before 6.0.1 and 5.6.5 have an open redirect vulnerability on the login page that would enable an attacker to craft a link that redirects to an arbitrary w... Read more
Affected Products : kibana- EPSS Score: %0.20
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11481
Kibana versions prior to 6.0.1 and 5.6.5 had a cross-site scripting (XSS) vulnerability via URL fields that could allow an attacker to obtain sensitive information from or perform destructive actions on behalf of other Kibana users.... Read more
Affected Products : kibana- EPSS Score: %0.27
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10897
Input validation issue in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to cause the device to become unresponsive via unspecified vectors.... Read more
- EPSS Score: %0.12
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17473
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730050.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.03
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17471
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82732140.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.03
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17468
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to gain privileges or cause a denial of service (Arbitrary Write) via a \\.\Viragtlt DeviceIoControl request of 0x82730020, a different vulnerability than CVE-2017-17050.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.04
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17465
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x95002574 DeviceIoControl request.... Read more
Affected Products : antivirus- EPSS Score: %0.35
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17463
Vivo modems allow remote attackers to obtain sensitive information by reading the index.cgi?page=wifi HTML source code, as demonstrated by ssid and psk_wepkey fields.... Read more
- EPSS Score: %0.32
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1498
IBM Connections 5.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IB... Read more
Affected Products : connections- EPSS Score: %0.25
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025