Latest CVE Feed
-
6.1
MEDIUMCVE-2017-5673
In the Kunena extension 5.0.2 through 5.0.4 for Joomla!, the forum message subject (aka topic subject) accepts JavaScript, leading to XSS. Six files are affected: crypsis/layouts/message/item/default.php, crypsis/layouts/message/item/top/default.php, cryp... Read more
Affected Products : kunena- EPSS Score: %0.24
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17411
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Linksys WVBR0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the web management portal. The issue lies in t... Read more
- EPSS Score: %92.16
- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5619
An issue was discovered in Zammad before 1.0.4, 1.1.x before 1.1.3, and 1.2.x before 1.2.1. Attackers can login with the hashed password itself (e.g., from the DB) instead of the valid password string.... Read more
Affected Products : zammad- EPSS Score: %0.44
- Published: Mar. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5602
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
Affected Products : jappix- EPSS Score: %0.24
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5598
An issue was discovered in eClinicalWorks healow@work 8.0 build 8. This is a blind SQL injection within the EmployeePortalServlet, which can be exploited by un-authenticated users via an HTTP POST request and which can be used to dump database data out to... Read more
Affected Products : patient_portal- EPSS Score: %0.29
- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5590
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
- EPSS Score: %0.38
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5553
Cross-site scripting (XSS) vulnerability in plugins/markdown_plugin/_markdown.plugin.php in b2evolution before 6.8.5 allows remote authenticated users to inject arbitrary web script or HTML via a javascript: URL.... Read more
Affected Products : b2evolution- EPSS Score: %0.22
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-5529
JasperReports library components contain an information disclosure vulnerability. This vulnerability includes the theoretical disclosure of any accessible information from the host file system. Affects TIBCO JasperReports Library Community Edition (versio... Read more
Affected Products : jasperreports_server jasperreports_library_community_edition jasperreports_library_for_activematrix_bpm jasperreports_professional jasperreports_server_community_edition jasperreports_server_for_activematrix_bpm jaspersoft_for_aws_with_multi-tenancy jaspersoft_reporting_and_analytics_for_aws jaspersoft_studio_for_activematrix_bpm- EPSS Score: %0.31
- Published: Jun. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5359
EasyCom SQL iPlug allows remote attackers to cause a denial of service via the D$EVAL parameter to the default URI.... Read more
Affected Products : sql_iplug- EPSS Score: %37.44
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5240
Editions of Rapid7 AppSpider Pro prior to version 6.14.060 contain a heap-based buffer overflow in the FLAnalyzer.exe component. A malicious or malformed Flash source file can cause a denial of service condition when parsed by this component, causing the ... Read more
Affected Products : appspider_pro- EPSS Score: %0.39
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5215
The Codextrous B2J Contact (aka b2j_contact) extension before 2.1.13 for Joomla! allows a rename attack that bypasses a "safe file extension" protection mechanism, leading to remote code execution.... Read more
Affected Products : b2j_contact- EPSS Score: %0.22
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5833
Cross-site scripting (XSS) vulnerability in the invocation code generation for interstitial zones in Revive Adserver before 4.0.1 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : revive_adserver- EPSS Score: %0.31
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-7544
Crypto++ 5.6.4 incorrectly uses Microsoft's stack-based _malloca and _freea functions. The library will request a block of memory to align a table in memory. If the table is later reallocated, then the wrong pointer could be freed.... Read more
- EPSS Score: %2.82
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-10076
Vulnerability in the Oracle Hospitality Simphony First Edition Venue Management component of Oracle Hospitality Applications (subcomponent: Core). The supported version that is affected is 3.9. Easily exploitable vulnerability allows low privileged attack... Read more
Affected Products : hospitality_simphony_first_edition_venue_management- EPSS Score: %0.20
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16681
Cross-Site Scripting (XSS) vulnerability in SAP Business Intelligence Promotion Management Application, Enterprise 4.10, 4.20, 4.30, as user controlled inputs are not sufficiently encoded.... Read more
Affected Products : business_intelligence_promotion_management_application- EPSS Score: %0.42
- Published: Dec. 12, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-10061
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Integration Broker). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.91
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9402
SQL injection vulnerability in the moderation tool in MyBB (aka MyBulletinBoard) before 1.8.7 and MyBB Merge System before 1.8.7 might allow remote attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
- EPSS Score: %3.69
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002023
Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php... Read more
Affected Products : easy_team_manager- EPSS Score: %10.33
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1002011
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript in... Read more
Affected Products : image-gallery-with-slideshow- EPSS Score: %0.89
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-3643
usb-creator before 0.2.38.3ubuntu0.1 on Ubuntu 12.04 LTS, before 0.2.56.3ubuntu0.1 on Ubuntu 14.04 LTS, before 0.2.62ubuntu0.3 on Ubuntu 14.10, and before 0.2.67ubuntu0.1 on Ubuntu 15.04 allows local users to gain privileges by leveraging a missing call c... Read more
- EPSS Score: %0.14
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025