Latest CVE Feed
-
9.8
CRITICALCVE-2017-17871
The "JEXTN Question And Answer" extension 3.1.0 for Joomla! has SQL Injection via the an parameter in a view=tags action, or the ques-srch parameter.... Read more
Affected Products : jextn_question_and_answer- EPSS Score: %1.41
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-10369
Vulnerability in the Oracle Virtual Directory component of Oracle Fusion Middleware (subcomponent: Virtual Directory Server). Supported versions that are affected are 11.1.1.7.0 and 11.1.1.9.0. Difficult to exploit vulnerability allows low privileged atta... Read more
Affected Products : virtual_directory- EPSS Score: %0.60
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1000155
Mahara 15.04 before 15.04.8 and 15.10 before 15.10.4 and 16.04 before 16.04.2 are vulnerable to profile pictures being accessed without any access control checks consequently allowing any of a user's uploaded profile pictures to be viewable by anyone, whe... Read more
Affected Products : mahara- EPSS Score: %0.17
- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12303
A vulnerability in the Advanced Malware Protection (AMP) file filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured AMP file filtering rule. The file types... Read more
- EPSS Score: %0.40
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0847
An elevation of privilege vulnerability in the Android media framework (mediaanalytics). Product: Android. Versions: 8.0. Android ID: A-65540999.... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
2.4
LOWCVE-2017-2705
Huawei P9 smartphones with software versions earlier before EVA-AL10C00B365, versions earlier before EVA-AL00C00B365, versions earlier before EVA-CL00C92B365, versions earlier before EVA-DL00C17B365, versions earlier before EVA-TL00C01B365 have a phone ac... Read more
- EPSS Score: %0.05
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-2826
WordPress Simple Ads Manager plugin 2.5.94 and 2.5.96 allows remote attackers to obtain sensitive information.... Read more
Affected Products : simple_ads_manager- EPSS Score: %43.16
- Published: Sep. 20, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12363
A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could explo... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.88
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11394
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-... Read more
Affected Products : officescan- EPSS Score: %78.47
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11383
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.... Read more
Affected Products : control_manager- EPSS Score: %7.24
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-5187
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.... Read more
Affected Products : candlepin- EPSS Score: %0.34
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11165
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.... Read more
- EPSS Score: %92.04
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11149
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.... Read more
Affected Products : download_station- EPSS Score: %0.28
- Published: Aug. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11048
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a display driver function, a Use After Free condition can occur.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-11045
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a camera driver function, a race condition exists which can lead to a Use After Free condition.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10899
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : a-reserve- EPSS Score: %0.22
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2015-2692
AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.... Read more
Affected Products : adblock- EPSS Score: %0.62
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10747
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa."... Read more
- EPSS Score: %0.06
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17988
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.... Read more
Affected Products : muslim_matrimonial_script- EPSS Score: %0.22
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-13162
An elevation of privilege vulnerability in the kernel binder. Product: Android. Versions: Android kernel. Android ID A-64216036.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025