Latest CVE Feed
-
10.0
HIGHCVE-2017-8862
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will be executed with "root" privileges.... Read more
- EPSS Score: %0.34
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Add... Read more
Affected Products : b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware balance_305 balance_380 balance_580 balance_710 +2 more products- EPSS Score: %3.84
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7683
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.... Read more
Affected Products : openmeetings- EPSS Score: %0.61
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8059
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addi... Read more
Affected Products : foxit_pdf- EPSS Score: %0.01
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-3927
mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code.... Read more
Affected Products : mrlg4php- EPSS Score: %0.88
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8205
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be execu... Read more
Affected Products : network_advisor- EPSS Score: %24.06
- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-7229
PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to 'Content-Type: t... Read more
Affected Products : office_365_security- EPSS Score: %0.24
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9019
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.... Read more
Affected Products : exponent_cms- EPSS Score: %0.66
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6661
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us... Read more
- EPSS Score: %0.30
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2014-2903
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.... Read more
Affected Products : wolfssl- EPSS Score: %0.21
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6551
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.... Read more
Affected Products : pexip_infinity- EPSS Score: %1.76
- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6541
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/viewtest.php URL. An attacker c... Read more
Affected Products : webpagetest- EPSS Score: %0.22
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7666
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.... Read more
Affected Products : openmeetings- EPSS Score: %0.17
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-7305
Riverbed RiOS through 9.6.0 does not require a bootloader password, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism via a crafted boot. NOTE: the vendor believes that this does not meet the definiti... Read more
Affected Products : rios- EPSS Score: %0.05
- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8457
An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.19
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8448
An elevation of privilege vulnerability in MediaTek components, including the thermal driver and video driver, could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it fi... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6479
FenixHosting/fenix-open-source before 2017-03-04 is vulnerable to a reflected XSS in forums/search.php (search-by-topic parameter).... Read more
Affected Products : fenix-open-source- EPSS Score: %0.30
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6356
Palo Alto Networks Terminal Services (aka TS) Agent 6.0, 7.0, and 8.0 before 8.0.1 uses weak permissions for unspecified resources, which allows attackers to obtain sensitive session information via unknown vectors.... Read more
Affected Products : terminal_services_agent- EPSS Score: %0.12
- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-8319
Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 12.0.1, 12.0.2,12.0.4,12.1.0 and 12.3.0. Easily exploitable vulnerability allows una... Read more
Affected Products : flexcube_investor_servicing- EPSS Score: %0.51
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6276
NVIDIA mediaserver contains a vulnerability where it is possible a use after free malfunction can occur due to an incorrect bounds check which could enable unauthorized code execution and possibly lead to elevation of privileges. This issue is rated as hi... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025