Latest CVE Feed
-
4.3
MEDIUMCVE-2017-10022
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privi... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.22
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002021
Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.... Read more
Affected Products : surveys- EPSS Score: %10.91
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002015
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.... Read more
Affected Products : image-gallery-with-slideshow- EPSS Score: %6.01
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002003
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.... Read more
Affected Products : wp2android-turn-wp-site-into-android-app- EPSS Score: %47.73
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002001
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.... Read more
Affected Products : mobile-app-builder-by-wappress- EPSS Score: %44.53
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10012
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Operations). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low privi... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.20
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-5729
The Soft Access Point (AP) feature in Samsung Smart TVs X10P, X12, X14H, X14J, and NT14U and Xpress M288OFW printers generate weak WPA2 PSK keys, which makes it easier for remote attackers to obtain sensitive information or bypass authentication via a bru... Read more
Affected Products : nt14u_firmware x14j_firmware x14h_firmware x12_firmware x10p_firmware m288ofw_firmware nt14u_us x14j_us x14h_cn x12_us +11 more products- EPSS Score: %1.35
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1000360
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.... Read more
Affected Products : opendaylight- EPSS Score: %0.39
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0740
A remote code execution vulnerability in the Broadcom networking driver. Product: Android. Versions: Android kernel. Android ID: A-37168488. References: B-RB#116402.... Read more
Affected Products : android- EPSS Score: %0.28
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1000243
Jenkins Favorite Plugin 2.1.4 and older does not perform permission checks when changing favorite status, allowing any user to set any other user's favorites... Read more
Affected Products : favorite_plugin- EPSS Score: %0.03
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000107
Script Security Plugin did not apply sandboxing restrictions to constructor invocations via positional arguments list, super constructor invocations, method references, and type coercion expressions. This could be used to invoke arbitrary constructors and... Read more
Affected Products : script_security- EPSS Score: %0.27
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000095
The default whitelist included the following unsafe entries: DefaultGroovyMethods.putAt(Object, String, Object); DefaultGroovyMethods.getAt(Object, String). These allowed circumventing many of the access restrictions implemented in the script sandbox by u... Read more
Affected Products : script_security- EPSS Score: %0.07
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000032
Cross-Site scripting (XSS) vulnerabilities in Cacti 0.8.8b allow remote attackers to inject arbitrary web script or HTML via the parent_id parameter to tree.php and drp_action parameter to data_sources.php.... Read more
Affected Products : cacti- EPSS Score: %0.20
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000012
MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user... Read more
Affected Products : mysqldumper- EPSS Score: %0.21
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000011
MyWebSQL version 3.6 is vulnerable to stored XSS in the database manager component resulting in account takeover or stealing of information... Read more
Affected Products : mywebsql- EPSS Score: %0.21
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-1000007
txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.... Read more
Affected Products : txaws- EPSS Score: %0.17
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000002
ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal and file extension check bypass in the Course component resulting in code execution. ATutor versions 2.2.1 and earlier are vulnerable to a directory traversal vulnerability in the C... Read more
Affected Products : atutor- EPSS Score: %2.12
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0909
The private_address_check ruby gem before 0.4.1 is vulnerable to a bypass due to an incomplete blacklist of common private/local network addresses used to prevent server-side request forgery.... Read more
Affected Products : private_address_check- EPSS Score: %0.34
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0905
The Recurly Client Ruby Library before 2.0.13, 2.1.11, 2.2.5, 2.3.10, 2.4.11, 2.5.4, 2.6.3, 2.7.8, 2.8.2, 2.9.2, 2.10.4, 2.11.3 is vulnerable to a Server-Side Request Forgery vulnerability in the "Resource#find" method that could result in compromise of A... Read more
Affected Products : recurly_client_ruby- EPSS Score: %0.52
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2014-8706
Pluck CMS 4.7.2 allows remote attackers to obtain sensitive information by (1) changing "PHPSESSID" to an array; (2) adding non-alphanumeric chars to "PHPSESSID"; (3) changing the image parameter to an array; or (4) changing the image parameter to a strin... Read more
Affected Products : pluck- EPSS Score: %0.24
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025