Latest CVE Feed
-
6.1
MEDIUMCVE-2017-12813
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.... Read more
Affected Products : phpjabbers_file_sharing_script- EPSS Score: %0.24
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-17991
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.... Read more
Affected Products : biometric_shift_employee_management_system- EPSS Score: %0.21
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-17981
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.... Read more
Affected Products : muslim_matrimonial_script- EPSS Score: %0.19
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17901
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.... Read more
- EPSS Score: %0.50
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17974
BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allows remote attackers to obtain sensitive information via a request for isc/get_sid_js.aspx or isc/get_sid.aspx, as demonstrated by obtai... Read more
- EPSS Score: %0.46
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17933
cgi/surgeftpmgr.cgi (aka the Web Manager interface on TCP port 7021 or 9021) in NetWin SurgeFTP version 23f2 has XSS via the classid, domainid, or username parameter.... Read more
Affected Products : surgeftp- EPSS Score: %0.21
- Published: Dec. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17957
PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.... Read more
Affected Products : php_multivendor_ecommerce- EPSS Score: %0.25
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6094
CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN interface and a certain "chk" value (48bit) derived from the MAC. The algori... Read more
Affected Products : gaps- EPSS Score: %0.44
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-17941
PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.23
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1262
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attac... Read more
Affected Products : security_guardium- EPSS Score: %0.32
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17939
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.11
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17938
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.22
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7669
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter rela... Read more
Affected Products : easy2map- EPSS Score: %3.62
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7667
Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the pa... Read more
Affected Products : resads- EPSS Score: %0.42
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7666
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers... Read more
Affected Products : payment_form_for_paypal_pro- EPSS Score: %0.59
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-16768
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.... Read more
Affected Products : mailplus_server- EPSS Score: %0.18
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13056
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.... Read more
Affected Products : pdf-xchange_viewer- EPSS Score: %1.69
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17930
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.... Read more
Affected Products : professional_service_script- EPSS Score: %0.13
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1356
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID... Read more
Affected Products : atlas_ediscovery_process_management- EPSS Score: %0.57
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17925
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.... Read more
Affected Products : professional_service_script- EPSS Score: %0.24
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025