Latest CVE Feed
-
8.1
HIGHCVE-2017-16870
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary... Read more
Affected Products : updraftplus- EPSS Score: %0.38
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16801
Cross-site scripting (XSS) vulnerability in Octopus Deploy 3.7.0-3.17.13 (fixed in 3.17.14) allows remote authenticated users to inject arbitrary web script or HTML via the Step Template Name parameter.... Read more
Affected Products : octopus_deploy- EPSS Score: %0.15
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1678
IBM DOORS Next Generation (DNG/RRC) 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials discl... Read more
Affected Products : rational_doors_next_generation- EPSS Score: %0.27
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16615
An exploitable vulnerability exists in the YAML parsing functionality in the parse_yaml_query method in parser.py in MLAlchemy before 0.2.2. When processing YAML-Based queries for data, a YAML parser can execute arbitrary Python commands resulting in comm... Read more
Affected Products : mlalchemy- EPSS Score: %0.90
- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-16659
The Gentoo mail-filter/assp package 1.9.8.13030 and earlier allows local users to gain privileges by leveraging access to the assp user account to install a Trojan horse /usr/share/assp/assp.pl script.... Read more
Affected Products : anti-spam_smtp_proxy- EPSS Score: %0.11
- Published: Nov. 08, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-16759
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.... Read more
Affected Products : librenms- EPSS Score: %0.01
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16723
A Cross-site Scripting issue was discovered in PHOENIX CONTACT FL COMSERVER BASIC 232/422/485, FL COMSERVER UNI 232/422/485, FL COMSERVER BAS 232/422/485-T, FL COMSERVER UNI 232/422/485-T, FL COM SERVER RS232, FL COM SERVER RS485, and PSI-MODEM/ETH (runni... Read more
Affected Products : fl_comserver_basic_232_firmware fl_comserver_uni_422_firmware fl_comserver_bas_485-t_firmware fl_com_server_rs232_firmware fl_com_server_rs485_firmware psi-modem\/eth_firmware fl_comserver_basic_422_firmware fl_comserver_basic_485_firmware fl_comserver_uni_485-t_firmware fl_comserver_uni_485_firmware +16 more products- EPSS Score: %0.42
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5543
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request.... Read more
Affected Products : subrion- EPSS Score: %1.76
- Published: Jan. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16711
The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) because of extractDefini... Read more
Affected Products : swftools- EPSS Score: %0.44
- Published: Nov. 09, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-5480
Directory traversal vulnerability in inc/files/files.ctrl.php in b2evolution through 6.8.3 allows remote authenticated users to read or delete arbitrary files by leveraging back-office access to provide a .. (dot dot) in the fm_selected array parameter.... Read more
Affected Products : b2evolution- EPSS Score: %0.32
- Published: Jan. 15, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5228
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter stdapi Dir.download() function. By using a specially-crafted build of Meterpreter, it is possible to write to an arbitrary ... Read more
Affected Products : metasploit- EPSS Score: %0.30
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-4987
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, a local authenticated user can load a maliciously crafted file in the search path which may potentially allow the attacker to execute arbitrary code on th... Read more
- EPSS Score: %0.07
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1613
IBM Connections 6.0 could allow an unauthenticated remote attacker to gain unauthenticated or unauthorized access to non-sensitive Engagement Center template data. IBM X-Force ID: 132954.... Read more
Affected Products : connections- EPSS Score: %0.32
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15959
Adult Script Pro 2.2.4 allows SQL Injection via the PATH_INFO to a /download URI, a different vulnerability than CVE-2007-6576.... Read more
Affected Products : adultscriptpro- EPSS Score: %2.34
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-15937
Artica Pandora FMS version 7.0 leaks a full installation pathname via GET data when intercepting the main page's graph requisition. This also implies that general OS information is leaked (e.g., a /var/www pathname typically means Linux or UNIX).... Read more
Affected Products : pandora_fms- EPSS Score: %0.31
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-15884
In HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 5.0.0, a local attacker or malware can silently subvert the plugin update process in order to escalate to root privileges.... Read more
Affected Products : vagrant_vmware_fusion- EPSS Score: %0.08
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15885
Reflected XSS in the web administration portal on the Axis 2100 Network Camera 2.03 allows an attacker to execute arbitrary JavaScript via the conf_Layout_OwnTitle parameter to view/view.shtml. NOTE: this might overlap CVE-2007-5214.... Read more
- EPSS Score: %0.22
- Published: Oct. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15813
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overflow can occur while reading firmware logs.... Read more
Affected Products : android- EPSS Score: %0.18
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15812
The Easy Appointments plugin before 1.12.0 for WordPress has XSS via a Settings values in the admin panel.... Read more
- EPSS Score: %0.20
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15811
The Pootle Button plugin before 1.2.0 for WordPress has XSS via the assets_url parameter in assets/dialog.php, exploitable via wp-admin/admin-ajax.php.... Read more
Affected Products : pootle_button- EPSS Score: %0.20
- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025