Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2017-11631

    dapur/app/app_user/controller/status.php in Fiyo CMS 2.0.7 has SQL injection via the id parameter.... Read more

    Affected Products : fiyo_cms
    • EPSS Score: %0.23
    • Published: Jul. 26, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-1183

    IBM Tivoli Monitoring Portal v6 could allow a local (network adjacent) attacker to modify SQL commands to the Portal Server, when default client-server communications, HTTP, are being used. IBM X-Force ID: 123494.... Read more

    Affected Products : tivoli_monitoring
    • EPSS Score: %0.91
    • Published: Jul. 17, 2017
    • Modified: Apr. 20, 2025
  • 7.6

    HIGH
    CVE-2017-11797

    ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2... Read more

    Affected Products : chakracore
    • EPSS Score: %26.10
    • Published: Oct. 13, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-11741

    HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) before 4.0.24 uses weak permissions for the sudo helper scripts, allows local users to execute arbitrary code with root privileges by overwriting one of the scripts.... Read more

    Affected Products : vagrant_vmware_fusion
    • EPSS Score: %0.31
    • Published: Aug. 08, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-11682

    Stored Cross-site scripting vulnerability in Hashtopussy 0.4.0 allows remote attackers to inject arbitrary web script or HTML via the (1) version, (2) url, or (3) rootdir parameter in hashcat.php.... Read more

    Affected Products : hashtopolis
    • EPSS Score: %0.22
    • Published: Jul. 27, 2017
    • Modified: Apr. 20, 2025
  • 8.1

    HIGH
    CVE-2017-11667

    OpenProject before 6.1.6 and 7.x before 7.0.3 mishandles session expiry, which allows remote attackers to perform APIv3 requests indefinitely by leveraging a hijacked session.... Read more

    Affected Products : openproject
    • EPSS Score: %0.82
    • Published: Jul. 26, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-11630

    dapur\apps\app_config\controller\backuper.php in Fiyo CMS 2.0.7 allows remote attackers to delete arbitrary files via directory traversal sequences in the file parameter in a type=database request, a different vulnerability than CVE-2017-8853.... Read more

    Affected Products : fiyo_cms
    • EPSS Score: %0.78
    • Published: Jul. 26, 2017
    • Modified: Apr. 20, 2025
  • 8.6

    HIGH
    CVE-2017-11615

    A sandbox escape in the Lua interface in Wube Factorio before 0.15.31 allows remote game servers or user-assisted attackers to execute arbitrary C code by including and loading a C library.... Read more

    Affected Products : factorio
    • EPSS Score: %0.20
    • Published: Jul. 26, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-11594

    Cross-site scripting (XSS) vulnerability in the Markdown parser in Loomio before 1.8.0 allows remote attackers to inject arbitrary web script or HTML via non-sanitized Markdown content in a new thread or a thread comment.... Read more

    Affected Products : loomio
    • EPSS Score: %0.23
    • Published: Jul. 24, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2015-0783

    The FileViewer class in Novell ZENworks Configuration Management (ZCM) allows remote authenticated users to read arbitrary files via the filename variable.... Read more

    Affected Products : zenworks_configuration_management
    • EPSS Score: %1.26
    • Published: Aug. 09, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-11416

    Fiyo CMS 2.0.7 has SQL injection in /apps/app_comment/controller/insert.php via the name parameter.... Read more

    Affected Products : fiyo_cms
    • EPSS Score: %0.23
    • Published: Jul. 18, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2015-0780

    SQL injection vulnerability in the GetReRequestData method of the GetStoredResult class in Novell ZENworks Configuration Management (ZCM) allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more

    Affected Products : zenworks_configuration_management
    • EPSS Score: %3.54
    • Published: Aug. 09, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-11585

    dayrui FineCms 5.0.9 has remote PHP code execution via the param parameter in an action=cache request to libraries/Template.php, aka Eval Injection.... Read more

    Affected Products : finecms
    • EPSS Score: %1.14
    • Published: Jul. 24, 2017
    • Modified: Apr. 20, 2025
  • 6.5

    MEDIUM
    CVE-2017-1154

    IBM Algorithmics One-Algo Risk Application 4.9.1, 5.0, and 5.1.0 could allow a user to gain access to files in the local environment which should not be viewed by application users. IBM Reference #: 1999892.... Read more

    Affected Products : algo_one
    • EPSS Score: %0.25
    • Published: Mar. 31, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-11480

    Packetbeat versions prior to 5.6.4 are affected by a denial of service flaw in the PostgreSQL protocol handler. If Packetbeat is listening for PostgreSQL traffic and a user is able to send arbitrary network traffic to the monitored port, the attacker coul... Read more

    Affected Products : packetbeat
    • EPSS Score: %0.54
    • Published: Dec. 08, 2017
    • Modified: Apr. 20, 2025
  • 7.5

    HIGH
    CVE-2017-11511

    The ManageEngine ServiceDesk 9.3.9328 is vulnerable to arbitrary file downloads due to improper restrictions of the pathname used in the filepath parameter for the download-file URL. An unauthenticated remote attacker can use this vulnerability to downloa... Read more

    Affected Products : servicedesk
    • EPSS Score: %4.10
    • Published: Nov. 08, 2017
    • Modified: Apr. 20, 2025
  • 9.8

    CRITICAL
    CVE-2017-11519

    passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.... Read more

    • EPSS Score: %13.24
    • Published: Jul. 21, 2017
    • Modified: Apr. 20, 2025
  • 8.8

    HIGH
    CVE-2017-11392

    Proxy command injection vulnerability in Trend Micro InterScan Messaging Virtual Appliance 9.0 and 9.1 allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the "T" parameter within mo... Read more

    • EPSS Score: %6.77
    • Published: Aug. 03, 2017
    • Modified: Apr. 20, 2025
  • 6.1

    MEDIUM
    CVE-2017-11460

    Cross-site scripting (XSS) vulnerability in the DataArchivingService servlet in SAP NetWeaver Portal 7.4 allows remote attackers to inject arbitrary web script or HTML via the responsecode parameter to shp/shp_result.jsp, aka SAP Security Note 2308535.... Read more

    Affected Products : netweaver netweaver_portal
    • EPSS Score: %0.23
    • Published: Jul. 25, 2017
    • Modified: Apr. 20, 2025
  • 5.4

    MEDIUM
    CVE-2017-1146

    IBM Content Navigator 2.0.3 and 3.0.0 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a ... Read more

    Affected Products : content_navigator
    • EPSS Score: %0.23
    • Published: Mar. 20, 2017
    • Modified: Apr. 20, 2025
Showing 20 of 291750 Results