Latest CVE Feed
-
9.8
CRITICALCVE-2015-7669
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter rela... Read more
Affected Products : easy2map- EPSS Score: %3.62
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7667
Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the pa... Read more
Affected Products : resads- EPSS Score: %0.42
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7666
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers... Read more
Affected Products : payment_form_for_paypal_pro- EPSS Score: %0.59
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-16768
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.... Read more
Affected Products : mailplus_server- EPSS Score: %0.18
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13056
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.... Read more
Affected Products : pdf-xchange_viewer- EPSS Score: %1.69
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17930
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.... Read more
Affected Products : professional_service_script- EPSS Score: %0.13
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1356
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID... Read more
Affected Products : atlas_ediscovery_process_management- EPSS Score: %0.57
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17925
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.... Read more
Affected Products : professional_service_script- EPSS Score: %0.24
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17896
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.... Read more
Affected Products : basic_job_site_script- EPSS Score: %0.24
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17892
Readymade Video Sharing Script has SQL Injection via the viewsubs.php chnlid parameter or the search_video.php search parameter.... Read more
Affected Products : readymade_video_sharing_script- EPSS Score: %0.25
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17891
Readymade Video Sharing Script has CSRF via user-profile-edit.php.... Read more
Affected Products : readymade_video_sharing_script- EPSS Score: %0.13
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17010
Untrusted search path vulnerability in Content Manager Assistant for PlayStation version 3.55.7671.0901 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : content_manager_assistant- EPSS Score: %0.17
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16897
A vulnerability has been discovered in the Auth0 passport-wsfed-saml2 library affecting versions < 3.0.5. This vulnerability allows an attacker to impersonate another user and potentially elevate their privileges if the SAML identity provider does not sig... Read more
Affected Products : passport-wsfed-saml2- EPSS Score: %0.42
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1365
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended function... Read more
- EPSS Score: %0.20
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15320
RP200 V500R002C00, V600R006C00; TE30 V100R001C10, V500R002C00, V600R006C00; TE40 V500R002C00, V600R006C00; TE50 V500R002C00, V600R006C00; TE60 V100R001C10, V500R002C00, V600R006C00 have an out-of-bounds read vulnerabilities in some Huawei products. Due to... Read more
Affected Products : te60_firmware rp200_firmware te30_firmware te40_firmware te50_firmware te30 te40 te50 te60 rp200- EPSS Score: %0.21
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5261
In versions 4.3.2-R4 and prior of Cambium Networks cnPilot firmware, the 'ping' and 'traceroute' functions of the web administrative console expose a file path traversal vulnerability, accessible to all authenticated users.... Read more
- EPSS Score: %24.14
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
2.3
LOWCVE-2017-15307
Huawei Honor 8 smartphone with software versions earlier than FRD-L04C567B389 and earlier than FRD-L14C567B389 have a permission control vulnerability due to improper authorization configuration on specific device information.... Read more
- EPSS Score: %0.02
- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17692
Samsung Internet Browser 5.4.02.3 allows remote attackers to bypass the Same Origin Policy and obtain sensitive information via crafted JavaScript code that redirects to a child tab and rewrites the innerHTML property.... Read more
Affected Products : internet_browser- EPSS Score: %61.07
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-17410
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : internet_security_2018- EPSS Score: %1.28
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-17409
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : internet_security_2018- EPSS Score: %1.28
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025