Latest CVE Feed
-
7.5
HIGHCVE-2017-5359
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.... Read more
Affected Products : sql_iplug- EPSS Score: %37.44
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5240
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the ... Read more
Affected Products : appspider_pro- EPSS Score: %0.39
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5215
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechanism, leading to remote code execution.... Read more
Affected Products : b2j_contact- EPSS Score: %0.22
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5833
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : revive_adserver- EPSS Score: %0.31
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7544
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.... Read more
- EPSS Score: %2.82
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-10076
Vulnerability in the Oracle Hospitality Simphony First Edition Venue Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.9. Easily exploitable vulnerability allows low privileged attack... Read more
Affected Products : hospitality_simphony_first_edition_venue_management- EPSS Score: %0.20
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16681
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.... Read more
Affected Products : business_intelligence_promotion_management_application- EPSS Score: %0.42
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-10061
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.91
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9402
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
- EPSS Score: %3.69
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002023
Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php... Read more
Affected Products : easy_team_manager- EPSS Score: %10.33
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1002011
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript in... Read more
Affected Products : image-gallery-with-slideshow- EPSS Score: %0.89
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-3643
usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call c... Read more
- EPSS Score: %0.14
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000054
Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.... Read more
- EPSS Score: %0.21
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-17068
A cross-origin vulnerability has been discovered in the Auth0 auth0.js library affecting versions < 8.12. This vulnerability allows an attacker to acquire authenticated users' tokens and invoke services on a user's behalf if the target site or application... Read more
- EPSS Score: %0.28
- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000223
A stored web content injection vulnerability (WCI, a.k.a XSS) is present in MODX Revolution CMS version 2.5.6 and earlier. An authenticated user with permissions to edit users can save malicious JavaScript as a User Group name and potentially take control... Read more
Affected Products : modx_revolution- EPSS Score: %0.26
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000219
npm/KyleRoss windows-cpu all versions vulnerable to command injection resulting in code execution as Node.js user... Read more
Affected Products : windows-cpu- EPSS Score: %3.34
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-1000213
WBCE v1.1.11 is vulnerable to reflected XSS via the "begriff" POST parameter in /admin/admintools/tool.php?tool=user_search... Read more
Affected Products : wbce_cms- EPSS Score: %0.24
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-1000209
The Java WebSocket client nv-websocket-client does not verify that the server hostname matches a domain name in the subject's Common Name (CN) or subjectAltName field of the X.509 certificate, which allows man-in-the-middle attackers to spoof SSL/TLS serv... Read more
Affected Products : nv-websocket-client- EPSS Score: %0.12
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-6671
Open edX edx-platform before 2015-08-25 requires use of the database for storage of SAML SSO secrets, which makes it easier for context-dependent attackers to obtain sensitive information by leveraging access to a database backup.... Read more
Affected Products : edx-platform- EPSS Score: %0.26
- Published: Mar. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000193
October CMS build 412 is vulnerable to stored WCI (a.k.a XSS) in brand logo image name resulting in JavaScript code execution in the victim's browser.... Read more
Affected Products : october- EPSS Score: %0.40
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025