Latest CVE Feed
-
6.8
MEDIUMCVE-2017-10181
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Forgot Password). Supported versions that are affected are 12.0.2 and 12.0.3. Easily exploitable vulnerability allows low privileged att... Read more
Affected Products : flexcube_direct_banking- EPSS Score: %0.28
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10189
Vulnerability in the Hospitality Suite8 component of Oracle Hospitality Applications (subcomponent: Leisure). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructur... Read more
Affected Products : hospitality_suite8- EPSS Score: %0.12
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10172
Vulnerability in the Oracle Retail Open Commerce Platform component of Oracle Retail Applications (subcomponent: Framework). Supported versions that are affected are 5.0, 5.1, 5.2, 5.3, 6.0, 6.1, 15.0 and 15.1. Easily exploitable vulnerability allows unau... Read more
Affected Products : retail_open_commerce_platform_cloud_service- EPSS Score: %0.46
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-10134
Vulnerability in the PeopleSoft Enterprise FSCM component of Oracle PeopleSoft Products (subcomponent: eProcurement). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HT... Read more
Affected Products : peoplesoft_enterprise_scm_eprocurement- EPSS Score: %0.21
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-10119
Vulnerability in the Oracle Service Bus component of Oracle Fusion Middleware (subcomponent: OSB Web Console Design, Admin). The supported version that is affected is 11.1.1.9.0. Easily exploitable vulnerability allows low privileged attacker with network... Read more
Affected Products : service_bus- EPSS Score: %0.48
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10047
Vulnerability in the MICROS BellaVita component of Oracle Hospitality Applications (subcomponent: Interface). The supported version that is affected is 2.7.x. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to... Read more
Affected Products : micros_bellavita- EPSS Score: %0.40
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-9483
Emacs 24.4 allows remote attackers to bypass security restrictions.... Read more
Affected Products : emacs- EPSS Score: %0.23
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1002007
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.... Read more
Affected Products : dtracker- EPSS Score: %4.62
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-10007
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low pr... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.22
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000238
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.... Read more
Affected Products : invoiceplane- EPSS Score: %0.57
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000227
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can... Read more
Affected Products : salutation- EPSS Score: %0.18
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000237
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.... Read more
Affected Products : i_librarian- EPSS Score: %0.46
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000163
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.... Read more
Affected Products : phoenix- EPSS Score: %1.79
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-8688
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file.... Read more
Affected Products : messenger- EPSS Score: %0.30
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1000110
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. It did not properly check the current user's... Read more
Affected Products : blue_ocean- EPSS Score: %0.04
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000069
CSRF in Bitly oauth2_proxy 2.1 during authentication flow... Read more
Affected Products : oauth2_proxy- EPSS Score: %0.10
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0643
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. V... Read more
Affected Products : android- EPSS Score: %0.20
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000038
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site... Read more
Affected Products : relevanssi- EPSS Score: %1.04
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000006
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.... Read more
Affected Products : plotly.js- EPSS Score: %0.64
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-10000
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attack... Read more
Affected Products : hospitality_reporting_and_analytics- EPSS Score: %0.37
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025