Latest CVE Feed
-
6.1
MEDIUMCVE-2017-1000042
Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name.... Read more
Affected Products : mapbox- EPSS Score: %0.16
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000137
Mahara 1.10 before 1.10.0 and 15.04 before 15.04.0 are vulnerable to possible cross site scripting when adding a text block to a page via the keyboard (rather than drag and drop).... Read more
Affected Products : mahara- EPSS Score: %0.19
- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-0895
Nextcloud Server before 10.0.4 and 11.0.2 are vulnerable to disclosure of calendar and addressbook names to other logged-in users. Note that no actual content of the calendar and addressbook has been disclosed.... Read more
Affected Products : nextcloud_server- EPSS Score: %0.13
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-0890
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.... Read more
Affected Products : nextcloud_server- EPSS Score: %0.67
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0842
An elevation of privilege vulnerability in the Android system (bluetooth). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-37502513.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9576
The "Middleton Community Bank Mobile Banking" by Middleton Community Bank app 3.0.0 -- aka middleton-community-bank-mobile-banking/id721843238 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof s... Read more
Affected Products : middleton_community_bank_mobile- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-5699
The Switch Configuration Tools Backend (clcmd_server) in Cumulus Linux 2.5.3 and earlier allows local users to execute arbitrary commands via shell metacharacters in a cl-rctl command label.... Read more
Affected Products : cumulus_linux- EPSS Score: %0.06
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2015-5666
ANA App for Android 3.1.1 and earlier, and ANA App for iOS 3.3.6 and earlier does not verify SSL certificates.... Read more
Affected Products : all_nippon_airways- EPSS Score: %0.58
- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0684
A elevation of privilege vulnerability in the Android media framework. Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35421151.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0675
A remote code execution vulnerability in the Android media framework. Product: Android. Versions: 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34779227.... Read more
Affected Products : android- EPSS Score: %0.21
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0604
An elevation of privilege vulnerability in the kernel Qualcomm power driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent ... Read more
Affected Products : android- EPSS Score: %0.04
- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0581
An elevation of privilege vulnerability in the Synaptics Touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privile... Read more
- EPSS Score: %0.25
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-0535
An information disclosure vulnerability in the HTC sound codec driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. ... Read more
- EPSS Score: %0.26
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0458
An elevation of privilege vulnerability in the Qualcomm camera driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- EPSS Score: %0.24
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15609
Octopus before 3.17.7 allows attackers to obtain sensitive cleartext information by reading a variable JSON file in certain situations involving Offline Drop Targets.... Read more
Affected Products : octopus_deploy- EPSS Score: %0.12
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-15538
Stored XSS vulnerability in the Media Objects component of ILIAS before 5.1.21 and 5.2.x before 5.2.9 allows an authenticated user to inject JavaScript to gain administrator privileges, related to the setParameter function in Services/MediaObjects/classes... Read more
Affected Products : ilias- EPSS Score: %0.43
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-8769
Facebook WhatsApp Messenger before 2.16.323 for Android uses the SD card for cleartext storage of files (Audio, Documents, Images, Video, and Voice Notes) associated with a chat, even after that chat is deleted. There may be users who expect file deletion... Read more
Affected Products : whatsapp- EPSS Score: %0.02
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15251
IrfanView version 4.44 (32bit) with PDF plugin version 4.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .pdf file, related to "Data from Faulting Address controls Code Flow starting at PDF!xmlParserInputRead+0x000... Read more
- EPSS Score: %0.19
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-2690
Multiple cross-site scripting (XSS) vulnerabilities in views/add-license-form.php in the Digium Addons module (digiumaddoninstaller) before 2.11.0.7 for FreePBX allow remote attackers to inject arbitrary web script or HTML via the (1) add_license_key, (2)... Read more
Affected Products : addons_module- EPSS Score: %0.17
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9405
Cross-site scripting (XSS) vulnerability in member validation in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.61
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025