Latest CVE Feed
-
9.8
CRITICALCVE-2017-8790
An issue was discovered on Accellion FTA devices before FTA_9_12_180. The home/seos/courier/ldaptest.html POST parameter "filter" can be used for LDAP Injection.... Read more
Affected Products : file_transfer_appliance- EPSS Score: %0.49
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8774
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file.... Read more
- EPSS Score: %0.53
- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2173
Cross-site scripting vulnerability in Empirical Project Monitor - eXtended all versions allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : empirical_project_monitor_-_extended- EPSS Score: %0.24
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2273
Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
- EPSS Score: %0.14
- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2211
Untrusted search path vulnerability in PatchJGD (Hyoko) (PatchJGDh101.EXE) ver. 1.0.1 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : patchjgd- EPSS Score: %0.14
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2185
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI.... Read more
- EPSS Score: %0.91
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2135
Cross-site scripting vulnerability in WP Statistics version 12.0.1 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.32
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2134
Cross-site scripting vulnerability in ASSETBASE 8.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : assetbase- EPSS Score: %0.30
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8259
In the service locator in all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow can occur as the variable set for determining the size of the buffer is not used to indicate the size of the buffer.... Read more
Affected Products : android- EPSS Score: %0.08
- Published: Aug. 11, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8217
TP-Link C2 and C20i devices through firmware 0.9.1 4.2 v0032.0 Build 160706 Rel.37961n have too permissive iptables rules, e.g., SNMP is not blocked on any interface.... Read more
- EPSS Score: %0.25
- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8206
HONOR 7 Lite mobile phones with software of versions earlier than NEM-L21C432B352 have an App Lock bypass vulnerability. An attacker could perform specific operations to bypass the App Lock to use apps on a target mobile phone temporarily.... Read more
- EPSS Score: %0.02
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-8163
AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C... Read more
Affected Products : ar1200_firmware ar200_firmware ar3200_firmware ar120-s_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200-s_firmware ar2200_firmware +24 more products- EPSS Score: %0.18
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8115
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.... Read more
Affected Products : modx_revolution- EPSS Score: %0.14
- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8045
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code exec... Read more
Affected Products : spring_advanced_message_queuing_protocol- EPSS Score: %2.83
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8004
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identi... Read more
- EPSS Score: %0.89
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-7964
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.... Read more
Affected Products : wre6505_firmware- EPSS Score: %2.71
- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7896
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.... Read more
Affected Products : interscan_messaging_security_virtual_appliance- EPSS Score: %0.35
- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7721
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.... Read more
- EPSS Score: %0.12
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7688
Apache OpenMeetings 1.0.0 updates user password in insecure manner.... Read more
Affected Products : openmeetings- EPSS Score: %1.11
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6652
A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could expl... Read more
Affected Products : telepresence_ix5000- EPSS Score: %3.01
- Published: May. 18, 2017
- Modified: Apr. 20, 2025