Latest CVE Feed
-
9.8
CRITICALCVE-2017-15971
Same Sex Dating Software Pro 1.0 allows SQL Injection via the viewprofile.php profid parameter, the viewmessage.php sender_id parameter, or the /admin Email field, a related issue to CVE-2017-15972.... Read more
Affected Products : same_date_pro- EPSS Score: %2.22
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15970
PHP CityPortal 2.0 allows SQL Injection via the nid parameter to index.php in a page=news action, or the cat parameter.... Read more
Affected Products : phpcityportal- EPSS Score: %2.51
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15968
MyBuilder Clone 1.0 allows SQL Injection via the phpsqlsearch_genxml.php subcategory parameter.... Read more
Affected Products : mybuildersite- EPSS Score: %2.34
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15967
Mailing List Manager Pro 3.0 allows SQL Injection via the edit parameter to admin/users in a sort=login action, or the edit parameter to admin/template.... Read more
Affected Products : mailing_list_manager_pro- EPSS Score: %2.34
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15966
The Zh YandexMap (aka com_zhyandexmap) component 6.1.1.0 for Joomla! allows SQL Injection via the placemarklistid parameter to index.php.... Read more
Affected Products : zh_yandexmap- EPSS Score: %4.15
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15965
The NS Download Shop (aka com_ns_downloadshop) component 2.2.6 for Joomla! allows SQL Injection via the id parameter in an invoice.create action.... Read more
Affected Products : ns_download_shop- EPSS Score: %4.15
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15964
Job Board Script Software allows SQL Injection via the PATH_INFO to a /job-details URI.... Read more
Affected Products : job_board_script- EPSS Score: %2.51
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15963
iTech Gigs Script 1.21 allows SQL Injection via the browse-scategory.php sc parameter or the service-provider.php ser parameter.... Read more
Affected Products : gigs_script- EPSS Score: %2.34
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15958
D-Park Pro Domain Parking Script 1.0 allows SQL Injection via the username to admin/loginform.php.... Read more
Affected Products : d-park_pro- EPSS Score: %2.51
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15956
ConverTo Video Downloader & Converter 1.4.1 allows Arbitrary File Download via the token parameter to download.php.... Read more
Affected Products : converto_video_downloader_\&_converter- EPSS Score: %22.84
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15948
Perch Content Management System 3.0.3 allows unrestricted file upload (with resultant XSS) via the Asset Title field in conjunction with the Select File field. This is exploitable with a Limited Admin account.... Read more
Affected Products : perch- EPSS Score: %0.22
- Published: Oct. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15936
In Artica Pandora FMS version 7.0, an Attacker with write Permission can create an agent with an XSS Payload; when a user enters the agent definitions page, the script will get executed.... Read more
Affected Products : pandora_fms- EPSS Score: %0.27
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15582
In net.MCrypt in the "Diary with lock" (aka WriteDiary) application 4.72 for Android, hardcoded SecretKey and iv variables are used for the AES parameters, which makes it easier for attackers to obtain the cleartext of stored diary entries.... Read more
Affected Products : diary_with_lock- EPSS Score: %0.22
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-3579
XML external entity (XXE) vulnerability in Apache ActiveMQ Apollo 1.x before 1.7.1 allows remote consumers to have unspecified impact via vectors involving an XPath based selector when dequeuing XML messages.... Read more
Affected Products : activemq_apollo- EPSS Score: %3.48
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15931
In radare2 2.0.1, an integer exception (negative number leading to an invalid memory access) exists in store_versioninfo_gnu_verneed() in libr/bin/format/elf/elf.c via crafted ELF files on 32bit systems.... Read more
Affected Products : radare2- EPSS Score: %0.21
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-2023
Multiple SQL injection vulnerabilities in the Tapatalk plugin 4.9.0 and earlier and 5.x through 5.2.1 for vBulletin allow remote attackers to execute arbitrary SQL commands via a crafted xmlrpc API request to (1) unsubscribe_forum.php or (2) unsubscribe_t... Read more
Affected Products : tapatalk- EPSS Score: %9.40
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-5996
The agent in Bomgar Remote Support 15.2.x before 15.2.3, 16.1.x before 16.1.5, and 16.2.x before 16.2.4 allows DLL hijacking because of weak %SYSTEMDRIVE%\ProgramData permissions.... Read more
- EPSS Score: %0.11
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3771
System boot process is not adequately secured In Lenovo E95 and ThinkCentre M710s/M710t because systems were shipped from factory without completing BIOS/UEFI initialization process.... Read more
- EPSS Score: %0.20
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15917
In Paessler PRTG Network Monitor 17.3.33.2830, it's possible to create a Map as a read-only user, by forging a request and sending it to the server.... Read more
Affected Products : prtg_network_monitor- EPSS Score: %0.16
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15911
The Admin Console in Ignite Realtime Openfire Server before 4.1.7 allows arbitrary client-side JavaScript code execution on victims who click a crafted setup/setup-host-settings.jsp?domain= link, aka XSS. Session ID and data theft may follow as well as th... Read more
Affected Products : openfire- EPSS Score: %0.42
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025