Latest CVE Feed
-
7.5
HIGHCVE-2017-17738
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) allows renaming and modifying files via /tools.html.... Read more
- EPSS Score: %16.15
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17733
Maccms 8.x allows remote command execution via the wd parameter in an index.php?m=vod-search request.... Read more
Affected Products : maccms- EPSS Score: %40.05
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17727
DedeCMS through 5.6 allows arbitrary file upload and PHP code execution by embedding the PHP code in a .jpg file, which is used in the templet parameter to member/article_edit.php.... Read more
Affected Products : dedecms- EPSS Score: %0.66
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17717
Sonatype Nexus Repository Manager through 2.14.5 has weak password encryption with a hardcoded CMMDwoV value in the LDAP integration feature.... Read more
Affected Products : nexus_repository_manager- EPSS Score: %0.12
- Published: Dec. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17714
Trape before 2017-11-05 has XSS via the /nr red parameter, the /nr vId parameter, the /register User-Agent HTTP header, the /register country parameter, the /register countryCode parameter, the /register cpu parameter, the /register isp parameter, the /re... Read more
Affected Products : trape- EPSS Score: %0.40
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17715
The saveFile method in MediaController.java in the Telegram Messenger application before 2017-12-08 for Android allows directory traversal via a pathname obtained in a file-transfer request from a remote peer, as demonstrated by writing to tgnet.dat or tg... Read more
- EPSS Score: %0.53
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14134
A Reflected XSS Vulnerability affects the forgotten password page of Maplesoft Maple T.A. 2016.0.6 (Customer Hosted) via the emailAddress parameter to passwordreset/PasswordReset.do, aka Open Bug Bounty ID OBB-286688.... Read more
Affected Products : maple_t.a.- EPSS Score: %0.22
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3194
Pandora iOS app prior to version 8.3.2 fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.... Read more
Affected Products : pandora- EPSS Score: %0.47
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3191
D-Link DIR-130 firmware version 1.23 and DIR-330 firmware version 1.12 are vulnerable to authentication bypass of the remote login page. A remote attacker that can access the remote management login page can manipulate the POST request in such a manner as... Read more
- EPSS Score: %40.18
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3190
Flash Seats Mobile App for Android version 1.7.9 and earlier and for iOS version 1.9.51 and earlier fails to properly validate SSL certificates provided by HTTPS connections, which may enable an attacker to conduct man-in-the-middle (MITM) attacks.... Read more
Affected Products : flash_seats- EPSS Score: %0.10
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3184
ACTi cameras including the D, B, I, and E series using firmware version A1D-500-V6.11.31-AC fail to properly restrict access to the factory reset page. An unauthenticated, remote attacker can exploit this vulnerability by directly accessing the http://x.x... Read more
Affected Products : camera_firmware- EPSS Score: %13.98
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11397
A service DLL preloading vulnerability in Trend Micro Encryption for Email versions 5.6 and below could allow an unauthenticated remote attacker to execute arbitrary code on a vulnerable system.... Read more
Affected Products : encryption_for_email- EPSS Score: %0.51
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-10905
A vulnerability in applications created using Qt for Android prior to 5.9.3 allows attackers to alter environment variables via unspecified vectors.... Read more
Affected Products : qt- EPSS Score: %0.13
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10904
Qt for Android prior to 5.9.0 allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : qt- EPSS Score: %0.97
- Published: Dec. 16, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-16776
Security researchers discovered an authentication bypass vulnerability in version 2.0.2 of the Conserus Workflow Intelligence application by McKesson Medical Imaging Company, which is now a Change Healthcare company. The attacker must send a malicious HTT... Read more
Affected Products : conserus_workflow_intelligence- EPSS Score: %1.45
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15890
Cross-site scripting (XSS) vulnerability in Disclaimer in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary web script or HTML via the NAME parameter.... Read more
Affected Products : mailplus_server- EPSS Score: %0.17
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-17697
The Ping() function in ui/api/target.go in Harbor through 1.3.0-rc4 has SSRF via the endpoint parameter to /api/targets/ping.... Read more
Affected Products : harbor- EPSS Score: %0.28
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-17696
Techno - Portfolio Management Panel through 2017-11-16 allows full path disclosure via an invalid s parameter to panel/search.php.... Read more
Affected Products : techno_-_portfolio_management_panel- EPSS Score: %0.20
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17535
lib/gui.py in Bob Hepple gjots2 2.4.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL.... Read more
Affected Products : gjots2- EPSS Score: %0.54
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17534
uiutil.c in Mensis 0.0.080507 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL, a different vulnerability than ... Read more
Affected Products : mensis- EPSS Score: %0.54
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025