Latest CVE Feed
-
10.0
HIGHCVE-2016-10387
In all Qualcomm products with Android releases from CAF using the Linux kernel, an assertion was potentially reachable in a handover scenario.... Read more
Affected Products : android- EPSS Score: %0.25
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1553
IBM Infosphere BigInsights 4.2.0 and 4.2.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure withi... Read more
Affected Products : infosphere_biginsights- EPSS Score: %0.27
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10184
An issue was discovered on the D-Link DWR-932B router. qmiweb allows file reading with ..%2f traversal.... Read more
- EPSS Score: %28.77
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10180
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.... Read more
- EPSS Score: %10.92
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10137
An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of com.adups.fota.sysoper allows any app on the device to read, write, and de... Read more
Affected Products : adups_fota- EPSS Score: %0.05
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10135
An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5.0, and BLU R1 HD devices. The MTKLogger app with a package name of com.mediatek.mtklogger has application... Read more
Affected Products : lg_mobile- EPSS Score: %0.30
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15375
Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, ... Read more
Affected Products : wpjobboard- EPSS Score: %0.20
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10123
Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.... Read more
Affected Products : firejail- EPSS Score: %0.04
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15368
The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers a... Read more
Affected Products : radare2- EPSS Score: %0.24
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-15366
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to g... Read more
Affected Products : ndoc- EPSS Score: %0.28
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10091
Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function.... Read more
Affected Products : unrtf- EPSS Score: %2.61
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15304
/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin passwo... Read more
- EPSS Score: %0.34
- Published: Oct. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15205
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user.... Read more
Affected Products : kanboard- EPSS Score: %0.29
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15195
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.... Read more
Affected Products : kanboard- EPSS Score: %0.49
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14985
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.php.... Read more
Affected Products : eyesofnetwork- EPSS Score: %0.15
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-3639
phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file.... Read more
Affected Products : phpmybackuppro- EPSS Score: %1.37
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-3617
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.... Read more
Affected Products : fortimanager_firmware- EPSS Score: %0.16
- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1481
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.18
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-3421
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure atta... Read more
Affected Products : eshop- EPSS Score: %0.17
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-14705
DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication paramete... Read more
- EPSS Score: %4.64
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025