Latest CVE Feed
-
9.8
CRITICALCVE-2017-7462
Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.... Read more
- EPSS Score: %11.29
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-7428
NetIQ iManager 3.x before 3.0.3.1 has an issue in the renegotiation of connection parameters with Tomcat.... Read more
Affected Products : imanager- EPSS Score: %0.34
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7422
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allow remote authenticated attackers to by... Read more
- EPSS Score: %0.10
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-7372
In all Android releases from CAF using the Linux kernel, a race condition exists in a video driver potentially leading to buffer overflow or write to arbitrary pointer location.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7288
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.51
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7239
Ninka before 1.3.2 might allow remote attackers to obtain sensitive information, manipulate license compliance scan results, or cause a denial of service (process hang) via a crafted filename.... Read more
Affected Products : ninka- EPSS Score: %2.11
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7236
SQL injection vulnerability in NetApp OnCommand Unified Manager Core Package 5.x before 5.2.2P1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : oncommand_unified_manager_core_package- EPSS Score: %0.29
- Published: May. 26, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-7229
PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to 'Content-Type: t... Read more
Affected Products : office_365_security- EPSS Score: %0.24
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7183
The TFTP server in ExtraPuTTY 0.30 and earlier allows remote attackers to cause a denial of service (crash) via a large (1) read or (2) write TFTP protocol message.... Read more
Affected Products : extraputty- EPSS Score: %30.06
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-3526
Apache Wicket before 1.5.12, 6.x before 6.17.0, and 7.x before 7.0.0-M3 might allow remote attackers to obtain sensitive information via vectors involving identifiers for storing page markup for temporary user sessions.... Read more
Affected Products : wicket- EPSS Score: %0.50
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9019
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.... Read more
Affected Products : exponent_cms- EPSS Score: %0.66
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9012
CloudVision Portal (CVP) before 2016.1.2.1 allows remote authenticated users to gain access to the internal configuration mechanisms via the management plane, related to a request to /web/system/console/bundle.... Read more
Affected Products : cloudvision_portal- EPSS Score: %0.74
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2191
Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- EPSS Score: %0.14
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8912
IBM Kenexa LMS on Cloud 13.1 and 13.2 - 13.2.4 stores potentially sensitive information in in log files that could be read by an authenticated user.... Read more
Affected Products : kenexa_lms_on_cloud- EPSS Score: %0.16
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-6915
CSRF exists in BigTree CMS 4.1.18 with the colophon parameter to the admin/settings/update/ page. The Colophon can be changed.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.12
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6812
paintballrefjosh/MaNGOSWebV4 4.0.8 is vulnerable to a reflected XSS in inc/admin/template_files/admin.vote.php (id parameter).... Read more
Affected Products : mangoswebv4- EPSS Score: %0.22
- Published: Mar. 11, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2014-3150
Livebox 1.1 allows remote authenticated users to upload arbitrary configuration files, download the configuration file, or obtain sensitive information via crafted Javascript.... Read more
- EPSS Score: %0.62
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6661
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us... Read more
- EPSS Score: %0.30
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2014-2903
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.... Read more
Affected Products : wolfssl- EPSS Score: %0.21
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-6620
A vulnerability in the remote management access control list (ACL) feature of the Cisco CVR100W Wireless-N VPN Router could allow an unauthenticated, remote attacker to bypass the remote management ACL. The vulnerability is due to incorrect implementation... Read more
- EPSS Score: %0.16
- Published: May. 03, 2017
- Modified: Apr. 20, 2025