Latest CVE Feed
-
9.8
CRITICALCVE-2017-6094
CPEs used by subscribers on the access network receive their individual configuration settings from a central GAPS instance. A CPE identifies itself by the MAC address of its WAN interface and a certain "chk" value (48bit) derived from the MAC. The algori... Read more
Affected Products : gaps- EPSS Score: %0.44
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17954
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.... Read more
Affected Products : php_multivendor_ecommerce- EPSS Score: %0.24
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15892
Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter... Read more
Affected Products : chat- EPSS Score: %0.19
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15886
Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.... Read more
Affected Products : chat- EPSS Score: %0.18
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-17941
PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.23
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1262
IBM Security Guardium 10.0 is vulnerable to HTTP response splitting attacks. A remote attacker could exploit this vulnerability using specially-crafted URL to cause the server to return a split response, once the URL is clicked. This would allow the attac... Read more
Affected Products : security_guardium- EPSS Score: %0.32
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17939
PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.11
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17938
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.22
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10910
MQTT.js 2.x.x prior to 2.15.0 issue in handling PUBLISH tickets may lead to an attacker causing a denial-of-service condition.... Read more
Affected Products : mqtt.js- EPSS Score: %0.79
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-7889
The SecEmailComposer/EmailComposer application in the Samsung S6 Edge before the October 2015 MR uses weak permissions for the com.samsung.android.email.intent.action.QUICK_REPLY_BACKGROUND service action, which might allow remote attackers with knowledge... Read more
- EPSS Score: %2.45
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7669
Multiple directory traversal vulnerabilities in (1) includes/MapImportCSV2.php and (2) includes/MapImportCSV.php in the Easy2Map plugin before 1.3.0 for WordPress allow remote attackers to include and execute arbitrary files via the csvfile parameter rela... Read more
Affected Products : easy2map- EPSS Score: %3.62
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7667
Multiple cross-site scripting (XSS) vulnerabilities in (1) templates/admanagement/admanagement.php and (2) templates/adspot/adspot.php in the ResAds plugin before 1.0.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the pa... Read more
Affected Products : resads- EPSS Score: %0.42
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7666
Multiple cross-site scripting (XSS) vulnerabilities in the (1) cp_updateMessageItem and (2) cp_deleteMessageItem functions in cp_ppp_admin_int_message_list.inc.php in the Payment Form for PayPal Pro plugin before 1.0.2 for WordPress allow remote attackers... Read more
Affected Products : payment_form_for_paypal_pro- EPSS Score: %0.59
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7324
Multiple cross-site scripting (XSS) vulnerabilities in helpers/comment.php in the StackIdeas Komento (com_komento) component before 2.0.5 for Joomla! allow remote attackers to inject arbitrary web script or HTML via the (1) img or (2) url tag of a new com... Read more
Affected Products : komento- EPSS Score: %0.32
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-6237
The RPC service in Tripwire (formerly nCircle) IP360 VnE Manager 7.2.2 before 7.2.6 allows remote attackers to bypass authentication and (1) enumerate users, (2) reset passwords, or (3) manipulate IP filter restrictions via crafted "privileged commands."... Read more
Affected Products : ip360- EPSS Score: %0.77
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-16768
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.... Read more
Affected Products : mailplus_server- EPSS Score: %0.18
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-13056
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.... Read more
Affected Products : pdf-xchange_viewer- EPSS Score: %1.69
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9944
A vulnerability has been identified in Siemens 7KT PAC1200 data manager (7KT1260) in all versions < V2.03. The integrated web server (port 80/tcp) of the affected devices could allow an unauthenticated remote attacker to perform administrative operations ... Read more
- EPSS Score: %2.60
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17930
PHP Scripts Mall Professional Service Script has CSRF via admin/general_settingupd.php, as demonstrated by modifying a setting in the user panel.... Read more
Affected Products : professional_service_script- EPSS Score: %0.13
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17929
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.... Read more
Affected Products : professional_service_script- EPSS Score: %0.24
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025