Latest CVE Feed
-
8.8
HIGHCVE-2017-5531
Deployments of TIBCO Managed File Transfer Command Center versions 8.0.0 and 8.0.1 and TIBCO Managed File Transfer Internet Server versions 8.0.0 and 8.0.1 that enable the Administrator Service may be affected by a vulnerability which may allow any authen... Read more
- EPSS Score: %0.55
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5519
SQL injection vulnerability in Posts.class.php in GeniXCMS through 0.0.8 allows remote attackers to execute arbitrary SQL commands via the id parameter.... Read more
Affected Products : genixcms- EPSS Score: %1.06
- Published: Jan. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5494
Multiple cross-site scripting (XSS) vulnerabilities in the file types table in b2evolution through 6.8.3 allow remote authenticated users to inject arbitrary web script or HTML via a .swf file in a (1) comment frame or (2) avatar frame.... Read more
Affected Products : b2evolution- EPSS Score: %0.22
- Published: Jan. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-1677
Technicolor TC7200 with firmware STD6.01.12 could allow remote attackers to obtain sensitive information.... Read more
- EPSS Score: %28.05
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-5346
SQL injection vulnerability in inc/lib/Control/Backend/posts.control.php in GeniXCMS 0.0.8 allows remote authenticated administrators to execute arbitrary SQL commands via the id parameter to gxadmin/index.php.... Read more
- EPSS Score: %1.08
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5264
Versions of Nexpose prior to 6.4.66 fail to adequately validate the source of HTTP requests intended for the Automated Actions administrative web application, and are susceptible to a cross-site request forgery (CSRF) attack.... Read more
Affected Products : nexpose- EPSS Score: %0.34
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5247
Biscom Secure File Transfer is vulnerable to cross-site scripting in the File Name field. An authenticated user with permissions to upload or send files can populate this field with a filename that contains standard HTML scripting tags. The resulting scri... Read more
Affected Products : secure_file_transfer- EPSS Score: %0.22
- Published: Jul. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5168
An issue was discovered in Hanwha Techwin Smart Security Manager Versions 1.5 and prior. Multiple Path Traversal vulnerabilities have been identified. The flaws exist within the ActiveMQ Broker service that is installed as part of the product. By issuing ... Read more
Affected Products : smart_security_manager- EPSS Score: %4.32
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-5217
Installing a zero-permission Android application on certain Samsung Android devices with KK(4.4), L(5.0/5.1), and M(6.0) software can continually crash the system_server process in the Android OS. The zero-permission app will create an active install sess... Read more
Affected Products : samsung_mobile- EPSS Score: %0.15
- Published: Jan. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5191
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.... Read more
Affected Products : access_manager- EPSS Score: %0.24
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12981
NexusPHP 1.5.beta5.20120707 has SQL Injection in forummanage.php via the sort parameter in an addforum action.... Read more
Affected Products : nexusphp- EPSS Score: %0.25
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-12977
The Web-Dorado "Photo Gallery by WD - Responsive Photo Gallery" plugin before 1.3.51 for WordPress has a SQL injection vulnerability related to bwg_edit_tag() in photo-gallery.php and edit_tag() in admin/controllers/BWGControllerTags_bwg.php. It is exploi... Read more
Affected Products : photo_gallery- EPSS Score: %0.51
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5178
An issue was discovered in Schneider Electric Tableau Server/Desktop Versions 7.0 to 10.1.3 in Wonderware Intelligence Versions 2014R3 and prior. These versions contain a system account that is installed by default. The default system account is difficult... Read more
- EPSS Score: %2.54
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5158
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specifie... Read more
Affected Products : wonderware_intouch_access_anywhere- EPSS Score: %1.02
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-3796
A vulnerability in Cisco WebEx Meetings Server could allow an authenticated, remote attacker to execute predetermined shell commands on other hosts. More Information: CSCuz03353. Known Affected Releases: 2.6.... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.93
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
8.9
HIGHCVE-2017-5149
An issue was discovered in St. Jude Medical Merlin@home, versions prior to Version 8.2.2 (RF models: EX1150; Inductive models: EX1100; and Inductive models: EX1100 with MerlinOnDemand capability). The identities of the endpoints for the communication chan... Read more
- EPSS Score: %0.32
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5155
An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenario... Read more
Affected Products : wonderware_historian- EPSS Score: %0.64
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-5143
An issue was discovered in Honeywell XL Web II controller XL1000C500 XLWebExe-2-01-00 and prior, and XLWeb 500 XLWebExe-1-02-08 and prior. A user without authenticating can make a directory traversal attack by accessing a specific URL.... Read more
- EPSS Score: %3.16
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-4991
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v260; UAA release 2.x versions prior to v2.7.4.16, 3.6.x versions prior to v3.6.10, 3.9.x versions prior to v3.9.12, and other versions prior to v3.17.0; and UAA bosh release... Read more
- EPSS Score: %0.28
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-4984
In EMC VNX2 versions prior to OE for File 8.1.9.211 and VNX1 versions prior to OE for File 7.1.80.8, an unauthenticated remote attacker may be able to elevate their permissions to root through a command injection. This may potentially be exploited by an a... Read more
- EPSS Score: %3.51
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025