Latest CVE Feed
-
4.9
MEDIUMCVE-2017-15052
TeamPass before 2.1.27.9 does not properly enforce manager access control when requesting users.queries.php. It is then possible for a manager user to delete an arbitrary user (including admin), or modify attributes of any arbitrary user except administra... Read more
Affected Products : teampass- EPSS Score: %0.24
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14586
The Hipchat for Mac desktop client is vulnerable to client-side remote code execution via video call link parsing. Hipchat for Mac desktop clients at or above version 4.0 and before version 4.30 are affected by this vulnerability.... Read more
Affected Products : hipchat- EPSS Score: %2.51
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-14585
A Server Side Request Forgery (SSRF) vulnerability could lead to remote code execution for authenticated administrators. This issue was introduced in version 2.2.0 of Hipchat Server and version 3.0.0 of Hipchat Data Center. Versions of Hipchat Server star... Read more
- EPSS Score: %1.75
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8031
An issue was discovered in Cloud Foundry Foundation cf-release (all versions prior to v279) and UAA (30.x versions prior to 30.6, 45.x versions prior to 45.4, 52.x versions prior to 52.1). In some cases, the UAA allows an authenticated user for a particul... Read more
- EPSS Score: %0.42
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-0910
In Zulip Server before 1.7.1, on a server with multiple realms, a vulnerability in the invitation system lets an authorized user of one realm on the server create a user account on any other realm.... Read more
Affected Products : zulip_server- EPSS Score: %0.24
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1001004
typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.... Read more
Affected Products : typed_function- EPSS Score: %0.75
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1001003
math.js before 3.17.0 had an issue where private properties such as a constructor could be replaced by using unicode characters when creating an object.... Read more
Affected Products : mathjs- EPSS Score: %0.49
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1001002
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.... Read more
- EPSS Score: %1.04
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8038
In Cloud Foundry Foundation Credhub-release version 1.1.0, access control lists (ACLs) enforce whether an authenticated user can perform an operation on a credential. For installations using ACLs, the ACL was bypassed for the CredHub interpolate endpoint,... Read more
Affected Products : credhub-release- EPSS Score: %0.18
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15871
The deserialize function in serialize-to-js through 1.1.1 allows attackers to cause a denial of service via vectors involving an Immediately Invoked Function Expression "function()" substring, as demonstrated by a "function(){console.log(" call or a simpl... Read more
Affected Products : serialize-to-js- EPSS Score: %0.28
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16959
The locale feature in cgi-bin/luci on TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allows remote authenticated users to test for the existence of arbitrary files by making an operation=write;locale=%0d request, and then making an operation=read request... Read more
Affected Products : tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware tl-wvr900l_firmware +98 more products- EPSS Score: %0.38
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-10700
auth_login.php in Cacti before 1.0.0 allows remote authenticated users who use web authentication to bypass intended access restrictions by logging in as a user not in the cacti database, because the guest user is not considered. NOTE: this vulnerability ... Read more
Affected Products : cacti- EPSS Score: %0.73
- Published: Nov. 24, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8215
Honor 8,Honor V8,Honor 9,Honor V9,Nova 2,Nova 2 Plus,P9,P10 Plus,Toronto Huawei smart phones with software of versions earlier than FRD-AL00C00B391, versions earlier than FRD-DL00C00B391, versions earlier than KNT-AL10C00B391, versions earlier than KNT-AL... Read more
Affected Products : honor_8_firmware p10_plus_firmware p9_firmware honor_v9_firmware nova_2_firmware nova_2_plus_firmware honor_9_firmware honor_v8_firmware toronto_firmware p9 +8 more products- EPSS Score: %0.02
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8211
The driver of honor 5C,honor 6x Huawei smart phones with software of versions earlier than NEM-AL10C00B356, versions earlier than Berlin-L21HNC432B360 have a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user ... Read more
- EPSS Score: %0.18
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-8202
The CameraISP driver of some Huawei smart phones with software of versions earlier than Prague-AL00AC00B205,versions earlier than Prague-AL00BC00B205,versions earlier than Prague-AL00CC00B205,versions earlier than Prague-TL00AC01B205,versions earlier than... Read more
- EPSS Score: %0.07
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8201
MAX PRESENCE V100R001C00, TP3106 V100R002C00, TP3206 V100R002C00 have an a memory leak vulnerability in H323 protocol. An attacker logs in to the system as a user and send crafted packets to the affected products. Due to insufficient verification of the p... Read more
Affected Products : tp3106_firmware max_presence_firmware tp3206_firmware tp3106 max_presence tp3206- EPSS Score: %0.23
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14825
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14826
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14827
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14828
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025