Latest CVE Feed
-
7.5
HIGHCVE-2017-2704
Smarthome 1.0.2.364 and earlier versions,HiAPP 7.3.0.303 and earlier versions,HwParentControl 2.0.0 and earlier versions,HwParentControlParent 5.1.0.12 and earlier versions,Crowdtest 1.5.3 and earlier versions,HiWallet 8.0.0.301 and earlier versions,Huawe... Read more
Affected Products : smarthome hiapp hwparentcontrol hwparentcontrolparent crowdtest hiwallet huawei_pay skytone hwclouddrive\(emui6.0\) hwphonefinder\(emui6.0\) +4 more products- EPSS Score: %0.08
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8831
Cross-site scripting (XSS) vulnerability in admin/comments.php in Dotclear before 2.8.2 allows remote attackers to inject arbitrary web script or HTML via the author name in a comment.... Read more
Affected Products : dotclear- EPSS Score: %0.93
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-8814
Umbraco before 7.4.0 allows remote attackers to bypass anti-forgery security measures and conduct cross-site request forgery (CSRF) attacks as demonstrated by editing user account information in the templates.asmx.cs file.... Read more
- EPSS Score: %0.11
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4547
Samsung devices with Android KK(4.4), L(5.0/5.1), or M(6.0) allow attackers to cause a denial of service (system crash) via a crafted system call to TvoutService_C.... Read more
Affected Products : samsung_mobile- EPSS Score: %0.56
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2213
Untrusted search path vulnerability in SemiDynaEXE (SemiDynaEXE2008.EXE) ver. 1.0.2 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : semidynaexe- EPSS Score: %0.14
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8667
Cross-site scripting (XSS) vulnerability in Reset Your Password module in Exponent CMS before 2.3.5 allows remote attackers to inject arbitrary web script or HTML via the Username/Email.... Read more
Affected Products : exponent_cms- EPSS Score: %0.23
- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4460
Apache Pony Mail 0.6c through 0.8b allows remote attackers to bypass authentication.... Read more
Affected Products : pony_mail- EPSS Score: %0.09
- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-8593
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in 1x call processing.... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2325
A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.... Read more
Affected Products : northstar_controller- EPSS Score: %0.49
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-4312
XML external entity (XXE) vulnerability in the XACML flow feature in WSO2 Identity Server 5.1.0 before WSO2-CARBON-PATCH-4.4.0-0231 allows remote authenticated users with access to XACML features to read arbitrary files, cause a denial of service, conduct... Read more
Affected Products : identity_server- EPSS Score: %5.42
- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2253
Untrusted search path vulnerability in Installer of Yahoo! Toolbar (for Internet explorer) v8.0.0.6 and earlier, with its timestamp prior to June 13, 2017, 18:18:55 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : toolbar- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12907
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the url path to usersearch.php.... Read more
Affected Products : nexusphp- EPSS Score: %0.24
- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2167
Untrusted search path vulnerability in Installer for PrimeDrive Desktop Application version 1.4.4 and earlier allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : primedrive_desktop_application- EPSS Score: %0.66
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-2142
Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
- EPSS Score: %2.79
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-2141
WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors.... Read more
- EPSS Score: %0.48
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-2126
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors.... Read more
- EPSS Score: %13.46
- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-2103
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : lala_call- EPSS Score: %0.29
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2090
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.... Read more
- EPSS Score: %3.37
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-7893
SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.... Read more
Affected Products : galaxy_s6- EPSS Score: %13.65
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-3403
Multiple cross-site request forgery (CSRF) vulnerabilities in the Admin Console in Zimbra Collaboration before 8.6.0 Patch 8 allow remote attackers to hijack the authentication of administrators for requests that (1) add, (2) modify, or (3) remove account... Read more
Affected Products : zimbra_collaboration_suite- EPSS Score: %2.57
- Published: May. 17, 2017
- Modified: Apr. 20, 2025