Latest CVE Feed
-
6.1
MEDIUMCVE-2017-3828
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of a... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.32
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3756
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.... Read more
Affected Products : windows_10 windows_7 windows_8.1 thinkpad_x1_carbon thinkpad_x1_tablet thinkpad_x1_yoga thinkpad_10_ella_2_bios thinkpad_11e_beema_bios thinkpad_11e_braswell_bios thinkpad_11e_broadwell_bios +141 more products- EPSS Score: %0.06
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3744
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command d... Read more
Affected Products : system_x3100_m4 system_x3250_m4 system_x3300_m4 system_x3500_m4 system_x3530_m4 system_x3550_m4 system_x3630_m4 system_x3650_m4 system_x3650_m4_hd system_x3750_m4 +37 more products- EPSS Score: %0.26
- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3569
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Business Events). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily ... Read more
Affected Products : hospitality_opera_5_property_services- EPSS Score: %0.19
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-3536
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Security). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows low privileged attacker with network... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.23
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3527
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Fluid Core). Supported versions that are affected are 8.54 and 8.55. Easily "exploitable" vulnerability allows unauthenticated attacker with netw... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.49
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3502
Vulnerability in the PeopleSoft Enterprise FIN Receivables component of Oracle PeopleSoft Products (subcomponent: Receivables). The supported version that is affected is 9.2. Easily "exploitable" vulnerability allows unauthenticated attacker with network ... Read more
Affected Products : peoplesoft_enterprise_fin_receivables- EPSS Score: %0.61
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3311
Vulnerability in the Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test Manager for Web Apps). Supported versions that are affected are 12.5.0.3, 12.5.0.2 and 12.4.0.2. Easily exploitable vulnerability allows... Read more
Affected Products : application_testing_suite- EPSS Score: %0.64
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9799
It was found that under some situations and configurations of Apache Storm 1.x before 1.0.4 and 1.1.x before 1.1.1, it is theoretically possible for the owner of a topology to trick the supervisor to launch a worker as a different, non-root, user. In the ... Read more
Affected Products : storm- EPSS Score: %0.89
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-3234
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows unauthenticated attacker with network acc... Read more
Affected Products : automatic_service_request- EPSS Score: %1.90
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-9703
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in a Camera driver can lead to a Use After Free condition.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9571
The Citizens Community Bank (TN) ccb-mobile-banking/id610030469 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : ccb_mobile_banking- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-9497
The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to execute arbitrary commands as root by pulling up the diagnostics menu on the set-top box, and then posting to a Web Insp... Read more
- EPSS Score: %0.13
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9437
Openbravo Business Suite 3.0 is affected by SQL injection. This vulnerability could allow remote authenticated attackers to inject arbitrary SQL code.... Read more
Affected Products : openbravo_erp- EPSS Score: %0.35
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9427
SQL injection vulnerability in BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary SQL commands via core\admin\modules\developer\modules\designer\form-create.php. The attacker creates a crafted table name at admin/developer/m... Read more
Affected Products : bigtree_cms- EPSS Score: %0.35
- Published: Jun. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9415
Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.view.... Read more
Affected Products : subsonic- EPSS Score: %0.83
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9289
Bram Korsten Note through 1.2.0 is vulnerable to a reflected XSS in note-source\ui\editor.php (edit parameter).... Read more
Affected Products : note- EPSS Score: %0.24
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2720
FusionSphere OpenStack V100R006C00 has an information exposure vulnerability. The software uses hard-coded cryptographic key to encrypt messages between certain components, which significantly increases the possibility that encrypted data may be recovered... Read more
Affected Products : fusionsphere_openstack- EPSS Score: %0.10
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2700
AC6005 with software V200R006C10, AC6605 with software V200R006C10 have a DoS Vulnerability. An attacker can send malformed packets to the device, which causes the device memory leaks, leading to DoS attacks.... Read more
- EPSS Score: %0.22
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-9046
winpm-32.exe in Pegasus Mail (aka Pmail) v4.72 build 572 allows code execution via a crafted ssgp.dll file that must be installed locally. For example, if ssgp.dll is on the desktop and executes arbitrary code in the DllMain function, then clicking on a m... Read more
Affected Products : pegasus- EPSS Score: %0.11
- Published: May. 21, 2017
- Modified: Apr. 20, 2025