Latest CVE Feed
-
5.3
MEDIUMCVE-2017-6644
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software does not suff... Read more
Affected Products : remote_expert_manager- EPSS Score: %0.37
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17614
Food Order Script 1.0 has SQL Injection via the /list city parameter.... Read more
Affected Products : hotel_restaurant_reviews_and_feedback_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17582
FS Grubhub Clone 1.0 has SQL Injection via the /food keywords parameter.... Read more
Affected Products : grubhub_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17580
FS Linkedin Clone 1.0 has SQL Injection via the group.php grid parameter, profile.php fid parameter, or company_details.php id parameter.... Read more
Affected Products : linkedin_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17577
FS Trademe Clone 1.0 has SQL Injection via the search_item.php search parameter or the general_item_details.php id parameter.... Read more
Affected Products : trademe_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17571
FS Foodpanda Clone 1.0 has SQL Injection via the /food keywords parameter.... Read more
Affected Products : foodpanda_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6600
A vulnerability in the CLI of the Cisco Unified Computing System (UCS) Manager, Cisco Firepower 4100 Series Next-Generation Firewall (NGFW), and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to perform a command inje... Read more
- EPSS Score: %0.37
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5721
Insufficient input validation in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to execute arbitrary code via manipulation of memory.... Read more
- EPSS Score: %6.66
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6571
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/campaign/view-campaign.php with the GET Parameter: id.... Read more
Affected Products : mail-masta- EPSS Score: %0.73
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6491
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (tooltip_id, callback, args, cid) passed to the EPESI-master/modules/Utils/Tooltip/req.php URL. An ... Read more
Affected Products : epesi- EPSS Score: %0.21
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6483
Multiple Cross-Site Scripting (XSS) issues were discovered in ATutor 2.2.2. The vulnerabilities exist due to insufficient filtration of user-supplied data passed to several pages (lang_code in themes/*/admin/system_preferences/language_edit.tmpl.php). An ... Read more
Affected Products : atutor- EPSS Score: %0.30
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17472
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730030.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.03
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17466
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to gain privileges or cause a denial of service (Arbitrary Write) via a \\.\Viragtlt DeviceIoControl request of 0x82730088.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.04
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6263
NVIDIA driver contains a vulnerability where it is possible a use after free malfunction can occur due to improper usage of the list_for_each kernel macro which could enable unauthorized code execution and possibly lead to elevation of privileges. This is... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6008
A kernel pool overflow in the driver hitmanpro37.sys in Sophos SurfRight HitmanPro before 3.7.20 Build 286 (included in the HitmanPro.Alert solution and Sophos Clean) allows local users to escalate privileges via a malformed IOCTL call.... Read more
Affected Products : hitmanpro- EPSS Score: %2.78
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5911
The Banco Santander Mexico SA Supermovil app 3.5 through 3.7 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : supermovil- EPSS Score: %0.12
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5867
ownCloud Server before 8.1.11, 8.2.x before 8.2.9, 9.0.x before 9.0.7, and 9.1.x before 9.1.3 allows remote authenticated users to cause a denial of service (server hang and logfile flooding) via a one bit BMP file.... Read more
Affected Products : owncloud- EPSS Score: %0.60
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16961
A SQL injection vulnerability in core/inc/auto-modules.php in BigTree CMS through 4.2.19 allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data from the database. The attack uses an ... Read more
Affected Products : bigtree_cms- EPSS Score: %0.17
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16902
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.... Read more
- EPSS Score: %18.29
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5688
There is an escalation of privilege vulnerability in the Intel Solid State Drive Toolbox versions before 3.4.5 which allow a local administrative attacker to load and execute arbitrary code.... Read more
Affected Products : solid_state_drive_toolbox- EPSS Score: %0.07
- Published: May. 31, 2017
- Modified: Apr. 20, 2025