Latest CVE Feed
-
5.4
MEDIUMCVE-2017-17745
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.... Read more
- EPSS Score: %0.16
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17699
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.... Read more
Affected Products : antivirus- EPSS Score: %0.35
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-17693
Techno - Portfolio Management Panel through 2017-11-16 does not check authorization for panel/portfolio.php?action=delete requests that remove feedback.... Read more
Affected Products : techno_-_portfolio_management_panel- EPSS Score: %0.15
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17671
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is bloc... Read more
- EPSS Score: %1.29
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17665
In Octopus Deploy before 4.1.3, the machine update process doesn't check that the user has access to all environments. This allows an access-control bypass because the set of environments to which a machine is scoped may include environments in which the ... Read more
Affected Products : octopus_deploy- EPSS Score: %0.27
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17613
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.... Read more
Affected Products : freelance_website_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17611
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.... Read more
Affected Products : doctor_search_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9980
In Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, the "PING" (aka tag_ipPing) feature within the web interface allows performing command injection, via the "pip" parameter.... Read more
- EPSS Score: %4.40
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9979
On the OSNEXUS QuantaStor v4 virtual appliance before 4.3.1, if the REST call invoked does not exist, an error will be triggered containing the invalid method previously invoked. The response sent to the user isn't sanitized in this case. An attacker can ... Read more
Affected Products : quantastor- EPSS Score: %2.40
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9977
AVG AntiVirus for MacOS with scan engine before 4668 might allow remote attackers to bypass malware detection by leveraging failure to scan inside disk image (aka DMG) files.... Read more
- EPSS Score: %0.41
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9945
In the Siemens 7KM PAC Switched Ethernet PROFINET expansion module (All versions < V2.1.3), a Denial-of-Service condition could be induced by a specially crafted PROFINET DCP packet sent as a local Ethernet (Layer 2) broadcast. The affected component requ... Read more
- EPSS Score: %0.14
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9924
In SWFTools 2013-04-09-1007 on Windows, png2swf allows remote attackers to execute arbitrary code or cause a denial of service via a crafted file, related to a "User Mode Write AV starting at image00000000_00400000+0x000000000001b72a."... Read more
- EPSS Score: %0.94
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9901
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls subsequent Write Address starting at Xfpx!gffGetFormatInfo+0x000000000002bfd5."... Read more
Affected Products : xnview- EPSS Score: %0.68
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9900
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to "Data from Faulting Address controls Code Flow starting at Xfpx!gffGetFormatInfo+0x000000000002e385."... Read more
Affected Products : xnview- EPSS Score: %0.68
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9896
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "Read Access Violation on Control Flow starting at Xfpx!gffGetFormatInfo+0x0000000000013e8a."... Read more
Affected Products : xnview- EPSS Score: %0.68
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9811
The kluser is able to interact with the kav4fs-control binary in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). By abusing the quarantine read and write operations, it is possible to elevate the pr... Read more
Affected Products : anti-virus_for_linux_server- EPSS Score: %24.67
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9797
When an Apache Geode cluster before v1.2.1 is operating in secure mode, an unauthenticated client can enter multi-user authentication mode and send metadata messages. These metadata operations could leak information about application data types. In additi... Read more
Affected Products : geode- EPSS Score: %0.34
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-9769
A specially crafted IOCTL can be issued to the rzpnk.sys driver in Razer Synapse 2.20.15.1104 that is forwarded to ZwOpenProcess allowing a handle to be opened to an arbitrary process.... Read more
Affected Products : synapse- EPSS Score: %77.70
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9365
CSRF exists in BigTree CMS through 4.2.18 with the force parameter to /admin/pages/revisions.php - for example: /admin/pages/revisions/1/?force=false. A page with id=1 can be unlocked.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.11
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-9718
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a race condition in a multimedia driver can potentially lead to a buffer overwrite.... Read more
Affected Products : android- EPSS Score: %0.01
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025