Latest CVE Feed
-
5.4
MEDIUMCVE-2016-9347
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SSH (Secure Shell)... Read more
- EPSS Score: %0.12
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2016-9463
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.1.2, 9.0.6, and 8.2.9 suffer from SMB User Authentication Bypass. Nextcloud/ownCloud include an optional and not by default enabled SMB authentication component that allows authenticatin... Read more
- EPSS Score: %3.86
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-4979
EMC Isilon OneFS 8.0.1.0, OneFS 8.0.0.0 - 8.0.0.2, OneFS 7.2.1.0 - 7.2.1.3, and OneFS 7.2.0.x is affected by an NFS export vulnerability. Under certain conditions, after upgrading a cluster from OneFS 7.1.1.x or earlier, users may have unexpected levels o... Read more
- EPSS Score: %0.35
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4980
EMC Isilon OneFS is affected by a path traversal vulnerability that may potentially be exploited by attackers to compromise the affected system. Affected versions are 7.1.0 - 7.1.1.10, 7.2.0 - 7.2.1.3, and 8.0.0 - 8.0.0.1.... Read more
- EPSS Score: %2.68
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4975
An issue was discovered in Pivotal PCF Tile Generator versions prior to 6.0.0. Tiles created by the PCF Tile Generator create a running open security group that overrides security groups set by the operator.... Read more
Affected Products : pcf_tile_generator- EPSS Score: %0.21
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-4955
An issue was discovered in Pivotal PCF Elastic Runtime 1.6.x versions prior to 1.6.65, 1.7.x versions prior to 1.7.48, 1.8.x versions prior to 1.8.28, and 1.9.x versions prior to 1.9.5. Several credentials were present in the logs for the Notifications er... Read more
Affected Products : cloud_foundry_elastic_runtime- EPSS Score: %0.41
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2143
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php.... Read more
- EPSS Score: %0.36
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-4930
VMware AirWatch Console 9.x prior to 9.2.0 contains a vulnerability that could allow an authenticated AWC user to add a malicious URL to an enrolled device's 'Links' page. Successful exploitation of this issue could result in an unsuspecting AWC user bein... Read more
Affected Products : airwatch- EPSS Score: %0.19
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-4017
User Name Disclosure in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to view user information via the appliance web interface.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.21
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3935
Network Data Loss Prevention is vulnerable to MIME type sniffing which allows older versions of Internet Explorer to perform MIME-sniffing on the response body, potentially causing the response body to be interpreted and displayed as a content type other ... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.25
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3871
A RADIUS Secret Disclosure vulnerability in the web network management interface of Cisco Prime Optical for Service Providers could allow an authenticated, remote attacker to disclose sensitive information in the configuration generated for a device. The ... Read more
Affected Products : prime_optical- EPSS Score: %0.14
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-3853
A vulnerability in the Data-in-Motion (DMo) process installed with the Cisco IOx application environment could allow an unauthenticated, remote attacker to cause a stack overflow that could allow remote code execution with root privileges in the virtual i... Read more
Affected Products : iox- EPSS Score: %1.37
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3841
A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Information: CSCvc04854. Known Affected Releases: 5.8(2.5).... Read more
Affected Products : secure_access_control_system- EPSS Score: %0.44
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3839
An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Informa... Read more
Affected Products : secure_access_control_system- EPSS Score: %0.40
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3828
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of a... Read more
Affected Products : unified_communications_manager- EPSS Score: %0.32
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-3759
The Lenovo Service Framework Android application accepts some responses from the server without proper validation. This exposes the application to man-in-the-middle attacks leading to possible remote code execution.... Read more
Affected Products : service_framework- EPSS Score: %1.42
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3756
A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path.... Read more
Affected Products : windows_10 windows_7 windows_8.1 thinkpad_x1_carbon thinkpad_x1_tablet thinkpad_x1_yoga thinkpad_10_ella_2_bios thinkpad_11e_beema_bios thinkpad_11e_braswell_bios thinkpad_11e_broadwell_bios +141 more products- EPSS Score: %0.06
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-3752
An industry-wide vulnerability has been identified in the implementation of the Open Shortest Path First (OSPF) routing protocol used on some Lenovo switches. Exploitation of these implementation flaws may result in attackers being able to erase or alter ... Read more
Affected Products : bladecenter 1g_l2-7_slb 1\ layer_2\/3_copper_firmware virtual_fabric_10gb en2092_1gb_firmware fabric_cn4093_10gb_firmware fabric_en4093\/en4093r_10gb_firmware g8052_firmware g8124_firmware +20 more products- EPSS Score: %0.15
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3744
In the IMM2 firmware of Lenovo System x servers, remote commands issued by LXCA or other utilities may be captured in the First Failure Data Capture (FFDC) service log if the service log is generated when that remote command is running. Captured command d... Read more
Affected Products : system_x3100_m4 system_x3250_m4 system_x3300_m4 system_x3500_m4 system_x3530_m4 system_x3550_m4 system_x3630_m4 system_x3650_m4 system_x3650_m4_hd system_x3750_m4 +37 more products- EPSS Score: %0.26
- Published: Jun. 20, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-3569
Vulnerability in the Oracle Hospitality OPERA 5 Property Services component of Oracle Hospitality Applications (subcomponent: OPERA Business Events). Supported versions that are affected are 5.4.0.x, 5.4.1.x, 5.4.2.x, 5.4.3.x, 5.5.0.x and 5.5.1.x. Easily ... Read more
Affected Products : hospitality_opera_5_property_services- EPSS Score: %0.19
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025