Latest CVE Feed
-
7.5
HIGHCVE-2017-9484
The Comcast firmware on Cisco DPC3939 (firmware version dpc3939-P20-18-v303r20421733-160420a-CMCST) and DPC3939 (firmware version dpc3939-P20-18-v303r20421746-170221a-CMCST) devices allows remote attackers to discover a CM MAC address by sniffing Wi-Fi tr... Read more
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9419
Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9288
The Raygun4WP plugin 1.8.0 for WordPress is vulnerable to a reflected XSS in sendtesterror.php (backurl parameter).... Read more
Affected Products : raygun4wp- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9282
An integer overflow (CWE-190) led to an out-of-bounds write (CWE-787) on a heap-allocated area, leading to heap corruption in Micro Focus VisiBroker 8.5. The feasibility of leveraging this vulnerability for further attacks was not assessed.... Read more
Affected Products : visibroker- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-9135
An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the webpage; these are only accessible ... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-9067
In MODX Revolution before 2.5.7, when PHP 5.3.3 is used, an attacker is able to include and execute arbitrary files on the web server due to insufficient validation of the action parameter to setup/index.php, aka directory traversal.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0865
An elevation of privilege vulnerability in the MediaTek soc driver. Product: Android. Versions: Android kernel. Android ID: A-65025090. References: M-ALPS02973195.... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-8862
The webupgrade function on the Cohu 3960HD does not verify the firmware upgrade files or process, allowing an attacker to upload a specially crafted postinstall.sh file that will be executed with "root" privileges.... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8840
Debug information disclosure exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. A direct request to cgi-bin/HASync/hasync.cgi?debug=1 shows Master LAN Add... Read more
Affected Products : b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware balance_305 balance_380 balance_580 balance_710 +2 more products- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7683
Apache OpenMeetings 1.0.0 displays Tomcat version and detailed error stack trace, which is not secure.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8059
Acceptance of invalid/self-signed TLS certificates in "Foxit PDF - PDF reader, editor, form, signature" before 5.4 for iOS allows a man-in-the-middle and/or physically proximate attacker to silently intercept login information (username/password), in addi... Read more
Affected Products : foxit_pdf- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-3927
mrlg-lib.php in mrlg4php before 1.0.8 allows remote attackers to execute arbitrary shell code.... Read more
Affected Products : mrlg4php- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2016-8205
A Directory Traversal vulnerability in DashboardFileReceiveServlet in the Brocade Network Advisor versions released prior to and including 14.0.2 could allow remote attackers to upload a malicious file in a section of the file system where it can be execu... Read more
Affected Products : network_advisor- Published: Jan. 14, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-7229
PGP/MIME encrypted messages injected into a Vaultive O365 (before 4.5.21) frontend via IMAP or SMTP have their Content-Type changed from 'Content-Type: multipart/encrypted; protocol="application/pgp-encrypted"; boundary="abc123abc123"' to 'Content-Type: t... Read more
Affected Products : office_365_security- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9019
SQL injection vulnerability in the activate_address function in framework/modules/addressbook/controllers/addressController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the is_what parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6661
A vulnerability in the web-based management interface of Cisco Email Security Appliance (ESA) and Cisco Content Security Management Appliance (SMA) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a us... Read more
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2014-2903
CyaSSL does not check the key usage extension in leaf certificates, which allows remote attackers to spoof servers via a crafted server certificate not authorized for use in an SSL/TLS handshake.... Read more
Affected Products : wolfssl- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6551
Pexip Infinity before 14.2 allows remote attackers to cause a denial of service (service restart) or execute arbitrary code via vectors related to Conferencing Nodes.... Read more
Affected Products : pexip_infinity- Published: May. 02, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6541
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, time) passed to the webpagetest-master/www/benchmarks/viewtest.php URL. An attacker c... Read more
Affected Products : webpagetest- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7666
Apache OpenMeetings 1.0.0 is vulnerable to Cross-Site Request Forgery (CSRF) attacks, XSS attacks, click-jacking, and MIME based attacks.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025