Latest CVE Feed
-
8.8
HIGHCVE-2017-14050
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.... Read more
Affected Products : blackcat_cms- EPSS Score: %0.51
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14031
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the target machine.... Read more
Affected Products : vtscada- EPSS Score: %0.04
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0781
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specif... Read more
Affected Products : cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_uaa_bosh cloud_foundry login-server- EPSS Score: %0.27
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2798
An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker ... Read more
Affected Products : marklogic- EPSS Score: %0.61
- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2779
An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping condit... Read more
Affected Products : labview- EPSS Score: %0.62
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-2731
The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone vib... Read more
- EPSS Score: %0.07
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5051
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.... Read more
Affected Products : lightify_home- EPSS Score: %0.49
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10222
runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "ty... Read more
Affected Products : safari- EPSS Score: %0.46
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1603
An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.... Read more
Affected Products : netiq_idm_servicenow_driver- EPSS Score: %0.60
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- EPSS Score: %0.30
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9468
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepr... Read more
- EPSS Score: %0.30
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-3740
Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value in a crafted TIFF image that is mishandled during PDF con... Read more
Affected Products : foxit_reader- EPSS Score: %1.30
- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-0885
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and ... Read more
Affected Products : nextcloud_server- EPSS Score: %0.63
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-2883
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.... Read more
Affected Products : in.sight_b120\\37- EPSS Score: %0.21
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1369
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.27
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-0218
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in ... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.16
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2333
A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authenticated attacker to consume enough system resources to cause a persistent d... Read more
Affected Products : northstar_controller- EPSS Score: %0.43
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-2183
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings.... Read more
- EPSS Score: %0.54
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2147
Cross-site scripting vulnerability in WP Statistics version 12.0.4 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.34
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12964
There is a stack consumption issue in LibSass 3.4.5 that is triggered in the function Sass::Eval::operator() in eval.cpp. It will lead to a remote denial of service attack.... Read more
Affected Products : libsass- EPSS Score: %0.60
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025