Latest CVE Feed
-
9.8
CRITICALCVE-2017-15607
Inedo Otter before 1.7.4 has directory traversal in filesystem-based rafts via vectors involving '/' characters or initial '.' characters, aka OT-181.... Read more
Affected Products : otter- EPSS Score: %0.48
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000406
OpenDaylight Karaf 0.6.1-Carbon fails to clear the cache after a password change, allowing the old password to be used until the Karaf cache is manually cleared (e.g. via restart).... Read more
Affected Products : karaf- EPSS Score: %0.23
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14949
Restlet Framework before 2.3.12 allows remote attackers to access arbitrary files via a crafted REST API HTTP request that conducts an XXE attack, because only general external entities (not parameter external entities) are properly considered. This is re... Read more
Affected Products : restlet- EPSS Score: %0.51
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14868
Restlet Framework before 2.3.11, when using SimpleXMLProvider, allows remote attackers to access arbitrary files via an XXE attack in a REST API HTTP request. This affects use of the Jax-rs extension.... Read more
Affected Products : restlet- EPSS Score: %0.38
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12366
A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters... Read more
Affected Products : webex_meeting_center- EPSS Score: %0.23
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12365
A vulnerability in Cisco WebEx Event Center could allow an authenticated, remote attacker to view unlisted meeting information. The vulnerability is due to a design flaw in the product. An attacker could execute a query on an Event Center site to view sch... Read more
Affected Products : webex_meeting_center- EPSS Score: %0.25
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12362
A vulnerability in Cisco Meeting Server versions prior to 2.2.2 could allow an authenticated, remote attacker to cause the system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to video calls being made on systems wi... Read more
Affected Products : meeting_server- EPSS Score: %0.89
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12358
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface. The... Read more
Affected Products : jabber- EPSS Score: %0.17
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12357
A vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of an affected ... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.24
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12356
A vulnerability in the web-based management interface of Cisco Jabber for Windows, Mac, Android, and iOS could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of... Read more
Affected Products : jabber- EPSS Score: %0.17
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12348
Multiple vulnerabilities in the web-based management interface of Cisco UCS Central Software could allow a remote attacker to conduct a cross-site scripting (XSS) attack against a user of the affected interface or hijack a valid session ID from a user of ... Read more
Affected Products : unified_computing_system_central_software- EPSS Score: %0.24
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12344
Multiple vulnerabilities in Cisco Data Center Network Manager (DCNM) Software could allow a remote attacker to inject arbitrary values into DCNM configuration parameters, redirect a user to a malicious website, inject malicious content into a DCNM client ... Read more
Affected Products : data_center_network_manager- EPSS Score: %0.22
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14389
An issue was discovered in Cloud Foundry Foundation capi-release (all versions prior to 1.45.0), cf-release (all versions prior to v280), and cf-deployment (all versions prior to v1.0.0). The Cloud Controller does not prevent space developers from creatin... Read more
- EPSS Score: %0.18
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
5.0
MEDIUMCVE-2017-12297
A vulnerability in Cisco WebEx Meeting Center could allow an authenticated, remote attacker to initiate connections to arbitrary hosts, aka a "URL Redirection Vulnerability." The vulnerability is due to insufficient access control for HTTP traffic directe... Read more
Affected Products : webex_meeting_center- EPSS Score: %0.24
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14198
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.... Read more
Affected Products : matrix- EPSS Score: %1.49
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14197
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. There are multiple reflected Cross-Site Scripting (XSS) issues in Matrix WYSIWYG plugins.... Read more
Affected Products : matrix- EPSS Score: %0.22
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14196
An issue was discovered in Squiz Matrix from 5.3 through to 5.3.6.1 and 5.4.1.3. An information disclosure caused by a Path Traversal issue in the 'File Bridge' plugin allowed the existence of files outside of the bridged path to be confirmed.... Read more
Affected Products : matrix- EPSS Score: %0.52
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14189
An improper access control vulnerability in Fortinet FortiWebManager 5.8.0 allows anyone that can access the admin webUI to successfully log-in regardless the provided password.... Read more
Affected Products : fortiweb_manager- EPSS Score: %1.36
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-14378
EMC RSA Authentication Agent API 8.5 for C and RSA Authentication Agent SDK 8.6 for C allow attackers to bypass authentication, aka an "Error Handling Vulnerability."... Read more
- EPSS Score: %2.64
- Published: Nov. 29, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8020
An issue was discovered in EMC ScaleIO 2.0.1.x. A buffer overflow vulnerability in the SDBG service may potentially allow a remote unauthenticated attacker to execute arbitrary commands with root privileges on an affected server.... Read more
Affected Products : scaleio- EPSS Score: %8.59
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025