Latest CVE Feed
-
5.5
MEDIUMCVE-2015-7847
Huawei MBB (Mobile Broadband) product E3272s with software versions earlier than E3272s-153TCPU-V200R002B491D09SP00C00 has a Denial of Service (DoS) vulnerability. An attacker could send a malicious packet to the Common Gateway Interface (CGI) of a target... Read more
- EPSS Score: %0.02
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-7780
Directory traversal vulnerability in ManageEngine Firewall Analyzer before 8.0.... Read more
Affected Products : manageengine_firewall_analyzer- EPSS Score: %36.22
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1208
IBM Maximo Asset Management 7.1, 7.5, and 7.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
- EPSS Score: %0.27
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12068
The Event List plugin 0.7.9 for WordPress has XSS in the slug array parameter to wp-admin/admin.php in an el_admin_categories delete_bulk action.... Read more
Affected Products : event_list- EPSS Score: %0.21
- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1193
IBM Sterling B2B Integrator Standard Edition 5.2 could allow user to obtain sensitive information using an HTTP GET request. IBM X-Force ID: 123667.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.28
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11631
dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.... Read more
Affected Products : fiyo_cms- EPSS Score: %0.23
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1183
IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.... Read more
Affected Products : tivoli_monitoring- EPSS Score: %0.91
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11797
ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2... Read more
Affected Products : chakracore- EPSS Score: %26.10
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11741
HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.... Read more
Affected Products : vagrant_vmware_fusion- EPSS Score: %0.31
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11682
Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) version, (2) url, or (3) rootdir parameter in hashcat.php.... Read more
Affected Products : hashtopolis- EPSS Score: %0.22
- Published: Jul. 27, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-11667
OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.... Read more
Affected Products : openproject- EPSS Score: %0.82
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11630
dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.... Read more
Affected Products : fiyo_cms- EPSS Score: %0.78
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-11615
A sandbox escape in the Lua interface in Wube Factorio before 0.15.31 allows remote game servers or user-assisted attackers to execute arbitrary C code by including and loading a C library.... Read more
Affected Products : factorio- EPSS Score: %0.20
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11594
Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.... Read more
Affected Products : loomio- EPSS Score: %0.23
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-0783
The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.... Read more
Affected Products : zenworks_configuration_management- EPSS Score: %1.26
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11416
Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.... Read more
Affected Products : fiyo_cms- EPSS Score: %0.23
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-0780
SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : zenworks_configuration_management- EPSS Score: %3.54
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11585
dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.... Read more
Affected Products : finecms- EPSS Score: %1.14
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1154
IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.... Read more
Affected Products : algo_one- EPSS Score: %0.25
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11480
Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker coul... Read more
Affected Products : packetbeat- EPSS Score: %0.54
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025