Latest CVE Feed
-
4.3
MEDIUMCVE-2017-6916
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.12
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6907
An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the "Open.GL-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a brows... Read more
Affected Products : open.gl- EPSS Score: %0.22
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6878
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.... Read more
Affected Products : metinfo- EPSS Score: %0.29
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-6792
A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in Bat... Read more
Affected Products : prime_collaboration_provisioning- EPSS Score: %0.40
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6724
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCuw65843.... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.35
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6698
A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitra... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.20
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6695
A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More Information: CSCvd29398. Known Affected Releases: 21.0.v0.65839.... Read more
Affected Products : ultra_services_platform- EPSS Score: %0.07
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6682
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76)... Read more
- EPSS Score: %0.95
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-6613
A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the aff... Read more
Affected Products : prime_network_registrar- EPSS Score: %0.29
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6250
NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.... Read more
Affected Products : geforce_experience- EPSS Score: %0.06
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6537
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (bgcolor) passed to the webpagetest-master/www/video/view.php URL. An attacker could execute arbitrary HTML... Read more
Affected Products : webpagetest- EPSS Score: %0.22
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6445
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.... Read more
Affected Products : openelec- EPSS Score: %0.28
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6190
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.... Read more
- EPSS Score: %64.65
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6102
Persistent XSS in wordpress plugin rockhoist-badges v1.2.2.... Read more
Affected Products : rockhoist_badges_plugin- EPSS Score: %0.24
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6071
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.... Read more
- EPSS Score: %0.31
- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-5707
Multiple buffer overflows in kernel in Intel Trusted Execution Engine Firmware 3.0 allow attacker with local access to the system to execute arbitrary code.... Read more
Affected Products : trusted_execution_engine_firmware- EPSS Score: %0.12
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5905
The Dollar Bank Mobile app 2.6.3 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : dollar_bank_mobile- EPSS Score: %0.12
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5832
Cross-site scripting (XSS) vulnerability in Revive Adserver before 4.0.1 allows remote authenticated users to inject arbitrary web script or HTML via the user's email address.... Read more
Affected Products : revive_adserver- EPSS Score: %0.23
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5876
XSS was discovered in dotCMS 3.7.0, with an unauthenticated attack against the /news-events/events date parameter.... Read more
Affected Products : dotcms- EPSS Score: %0.47
- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5673
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, cryp... Read more
Affected Products : kunena- EPSS Score: %0.24
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025