Latest CVE Feed
-
6.1
MEDIUMCVE-2017-7388
A Cross-Site Scripting (XSS) was discovered in 'wallacepos v1.4.1'. The vulnerability exists due to insufficient filtration of user-supplied data (token) passed to the 'wallacepos-master/myaccount/resetpassword.php' URL. An attacker could execute arbitrar... Read more
Affected Products : wallacepos- EPSS Score: %0.23
- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-7180
Net Monitor for Employees Pro through 5.3.4 has an unquoted service path, which allows a Security Feature Bypass of its documented "Block applications" design goal. The local attacker must have privileges to write to program.exe in a protected directory, ... Read more
Affected Products : net_monitor_for_employees- EPSS Score: %0.07
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7185
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via... Read more
- EPSS Score: %33.25
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7204
A Cross-Site Scripting (XSS) was discovered in imdbphp 5.1.1. The vulnerability exists due to insufficient filtration of user-supplied data (name) passed to the "imdbphp-master/demo/search.php" URL. An attacker could execute arbitrary HTML and script code... Read more
Affected Products : imdbphp- EPSS Score: %0.30
- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-17408
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security 2018. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a mal... Read more
Affected Products : internet_security_2018- EPSS Score: %6.34
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6996
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- EPSS Score: %0.68
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6957
Stack-based buffer overflow in the firmware in Broadcom Wi-Fi HardMAC SoC chips, when the firmware supports CCKM Fast and Secure Roaming and the feature is enabled in RAM, allows remote attackers to execute arbitrary code via a crafted reassociation respo... Read more
- EPSS Score: %14.93
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6950
SAP GUI 7.2 through 7.5 allows remote attackers to bypass intended security policy restrictions and execute arbitrary code via a crafted ABAP code, aka SAP Security Note 2407616.... Read more
- EPSS Score: %1.18
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17940
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.... Read more
Affected Products : single_theater_booking_script- EPSS Score: %0.22
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17909
PHP Scripts Mall Responsive Realestate Script has XSS via the admin/general.php gplus parameter.... Read more
Affected Products : responsive_realestate_script- EPSS Score: %0.22
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17908
PHP Scripts Mall Responsive Realestate Script has CSRF via admin/general.... Read more
Affected Products : responsive_realestate_script- EPSS Score: %0.11
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6880
Buffer overflow in Cerberus FTP Server 8.0.10.3 allows remote attackers to cause a denial of service (daemon crash) or possibly have unspecified other impact via a long MLST command.... Read more
Affected Products : cerberus_ftp_server- EPSS Score: %9.23
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6799
A cross-site scripting (XSS) vulnerability in view_filters_page.php in MantisBT before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'view_type' parameter.... Read more
Affected Products : mantisbt- EPSS Score: %0.72
- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6797
A cross-site scripting (XSS) vulnerability in bug_change_status_page.php in MantisBT before 1.3.7 and 2.x before 2.2.1 allows remote attackers to inject arbitrary JavaScript via the 'action_type' parameter.... Read more
Affected Products : mantisbt- EPSS Score: %0.83
- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-6758
A vulnerability in the web framework of Cisco Unified Communications Manager 11.5(1.10000.6) could allow an authenticated, remote attacker to access arbitrary files in the context of the web root directory structure on an affected device. The vulnerabilit... Read more
Affected Products : unified_communications_manager- EPSS Score: %1.24
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6757
A vulnerability in Cisco Unified Communications Manager 10.5(2.10000.5), 11.0(1.10000.10), and 11.5(1.10000.6) could allow an authenticated, remote attacker to conduct a blind SQL injection attack. The vulnerability is due to a failure to validate user-su... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.68
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17734
CMS Made Simple (CMSMS) before 2.2.5 does not properly cache login information in sessions.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.28
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-17553
The Dolphin Browser for Android 12.0.2 suffers from an insecure parsing implementation of the Intent URI scheme. This vulnerability could allow attackers to abuse this implementation through a malicious Intent URI, in order to invoke private Activities wi... Read more
Affected Products : dolphin- EPSS Score: %0.23
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6709
A vulnerability in the AutoVNF tool for the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to access administrative credentials for Cisco Elastic Services Controller (ESC) and Cisco OpenStack deployments in an affected syst... Read more
- EPSS Score: %0.51
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6644
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not suff... Read more
Affected Products : remote_expert_manager- EPSS Score: %0.37
- Published: May. 22, 2017
- Modified: Apr. 20, 2025