Latest CVE Feed
-
9.8
CRITICALCVE-2017-11519
passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.... Read more
- EPSS Score: %13.24
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11392
Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within mo... Read more
Affected Products : interscan_messaging_security_virtual_appliance- EPSS Score: %6.77
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1146
IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more
Affected Products : content_navigator- EPSS Score: %0.23
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11437
GitLab Enterprise Edition (EE) before 8.17.7, 9.0.11, 9.1.8, 9.2.8, and 9.3.8 allows an authenticated user with the ability to create a project to use the mirroring feature to potentially read repositories belonging to other users.... Read more
Affected Products : gitlab- EPSS Score: %0.09
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1140
IBM Business Process Manager 8.0 and 8.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within... Read more
Affected Products : business_process_manager- EPSS Score: %0.27
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11341
There is a heap based buffer over-read in lexer.hpp of LibSass 3.4.5. A crafted input will lead to a remote denial of service attack.... Read more
Affected Products : libsass- EPSS Score: %0.44
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1133
IBM QRadar 7.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM Ref... Read more
- EPSS Score: %0.26
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11320
Persistent XSS through the SSID of nearby Wi-Fi devices on Technicolor TC7337 routers 08.89.17.20.00 allows an attacker to cause DNS Poisoning and steal credentials from the router.... Read more
- EPSS Score: %0.40
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11196
Pulse Connect Secure 8.3R1 has CSRF in logout.cgi. The logout function of the admin panel is not protected by any CSRF tokens, thus allowing an attacker to logout a user by making them visit a malicious web page.... Read more
Affected Products : pulse_connect_secure- EPSS Score: %0.15
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11067
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the Athdiag procfs entry does not have a proper address sanity check which may potentially lead to the use of an out-of-range pointer offset.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11026
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while flashing FRP partition using reference FRP unlock, authentication method can be compromised for static keys.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11023
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, there is a possibility of out-of-bound buffer accesses due to no synchronization in accessing global variables by multiple threads.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1102
IBM Quality Manager (RQM) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure with... Read more
Affected Products : rational_quality_manager- EPSS Score: %0.27
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10993
Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.... Read more
- EPSS Score: %0.82
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10962
REDCap before 7.5.1 has XSS via the query string.... Read more
Affected Products : redcap- EPSS Score: %0.24
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-10950
This vulnerability allows local attackers to execute arbitrary code on vulnerable installations of Bitdefender Total Security 21.0.24.62. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit thi... Read more
Affected Products : total_security- EPSS Score: %0.05
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10860
Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : i-filter_installer- EPSS Score: %0.22
- Published: Sep. 15, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10850
Untrusted search path vulnerability in Installers of ART EX Driver for ApeosPort-VI C7771/C6671/C5571/C4471/C3371/C2271, DocuCentre-VI C7771/C6671/C5571/C4471/C3371/C2271 (Timestamp of code signing is before 12 Apr 2017 02:04 UTC.), PostScript? Driver + A... Read more
- EPSS Score: %0.14
- Published: Sep. 01, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10830
Untrusted search path vulnerability in Security Setup Tool all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : security_setup_tool- EPSS Score: %0.14
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10805
In Odoo 8.0, Odoo Community Edition 9.0 and 10.0, and Odoo Enterprise Edition 9.0 and 10.0, incorrect access control on OAuth tokens in the OAuth module allows remote authenticated users to hijack OAuth sessions of other users.... Read more
Affected Products : odoo- EPSS Score: %0.32
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025