Latest CVE Feed
-
7.8
HIGHCVE-2017-0746
A elevation of privilege vulnerability in the Qualcomm ipa driver. Product: Android. Versions: Android kernel. Android ID: A-35467471. References: QC-CR#2029392.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-6133
Cross-site scripting (XSS) vulnerability in Ektron Content Management System before 9.1.0.184SP3(9.1.0.184.3.127) allows remote attackers to inject arbitrary web script or HTML via the rptStatus parameter in a Report action to WorkArea/SelectUserGroup.asp... Read more
Affected Products : ektron_content_management_system- EPSS Score: %0.22
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-7845
GigaCC OFFICE ver.2.3 and earlier allows remote attackers to upload arbitrary files as a user profile image, which may be exploited for unauthorized file sharing.... Read more
Affected Products : gigacc_office- EPSS Score: %0.46
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
4.6
MEDIUMCVE-2017-10168
Vulnerability in the Hospitality Hotel Mobile component of Oracle Hospitality Applications (subcomponent: Suite 8/Windows). The supported version that is affected is 1.1. Difficult to exploit vulnerability allows physical access to compromise Hospitality ... Read more
Affected Products : hospitality_hotel_mobile- EPSS Score: %0.17
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10257
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: Browse Folder Hierarchy). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attac... Read more
Affected Products : peoplesoft_enterprise_prtl_interaction_hub- EPSS Score: %0.46
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0725
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37627194.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-10811
Buffalo WCR-1166DS devices with firmware 1.30 and earlier allow an attacker to execute arbitrary OS commands via unspecified vectors.... Read more
- EPSS Score: %0.18
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-7737
An information disclosure vulnerability in Fortinet FortiWeb 5.8.2 and below versions allows logged-in admin user to view SNMPv3 user password in cleartext in webui via the HTML source code.... Read more
Affected Products : fortiweb- EPSS Score: %0.29
- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-2959
IBM Sametime Meeting Server 8.5.2 and 9.0 could allow a meeting room manager to remove the primary managers privileges. IBM X-Force ID: 113804.... Read more
Affected Products : sametime- EPSS Score: %0.24
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9344
An issue was discovered in Moxa MiiNePort E1 versions prior to 1.8, E2 versions prior to 1.4, and E3 versions prior to 1.1. An attacker may be able to brute force an active session cookie to be able to download configuration files.... Read more
Affected Products : miineport_e1_firmware miineport_e3_firmware miineport_e2_firmware miineport_e3 miineport_e1 miineport_e2- EPSS Score: %0.32
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12655
Cross-Site Scripting (XSS) exists in NexusPHP version v1.5 via the query parameter to log.php in a dailylog action.... Read more
Affected Products : nexusphp- EPSS Score: %0.24
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-9102
Multiple cross-site scripting (XSS) vulnerabilities in Synology Photo Station 6.0 before 6.0-2638 and 6.3 before 6.3-2962 allow remote authenticated attackers to inject arbitrary web script or HTML via the (1) album name, (2) file name of uploaded photos,... Read more
Affected Products : photo_station- EPSS Score: %0.33
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12585
SLiMS 8 Akasia through 8.3.1 has SQL injection in admin/AJAX_lookup_handler.php (tableName and tableFields parameters), admin/AJAX_check_id.php, and admin/AJAX_vocabolary_control.php. It can be exploited by remote authenticated librarian users.... Read more
Affected Products : akasia- EPSS Score: %0.43
- Published: Aug. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9044
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached due to an improper bound on the size of a frequency list.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9029
In all Android releases from CAF using the Linux kernel, a vulnerability exists in the access control settings of modem memory.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9028
In all Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in a cryptographic routine.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8965
Rogue Wave JViews before 8.8 patch 21 and 8.9 before patch 1 allows remote attackers to execute arbitrary Java code that exists in the classpath, such as test code or administration code. The issue exists because the ilog.views.faces.IlvFacesController se... Read more
- EPSS Score: %1.38
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2015-2145
Multiple cross-site scripting (XSS) vulnerabilities in Issuetracker phpBugTracker before 1.7.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : phpbugtracker- EPSS Score: %0.28
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2015-7842
Huawei FusionServer rack servers RH2288 V3 with software before V100R003C00SPC603, RH2288H V3 with software before V100R003C00SPC503, XH628 V3 with software before V100R003C00SPC602, RH1288 V3 with software before V100R003C00SPC602, RH2288A V2 with softwa... Read more
Affected Products : rh2288_v3_firmware rh2288h_v3_firmware xh628_v3_firmware rh1288_v3_firmware rh2288a_v2_firmware rh1288a_v2_firmware rh8100_v3_firmware ch222_v3_firmware ch220_v3_firmware ch121_v3_firmware +10 more products- EPSS Score: %0.24
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-8832
Multiple incomplete blacklist vulnerabilities in inc/core/class.dc.core.php in Dotclear before 2.8.2 allow remote authenticated users with "manage their own media items" and "manage their own entries and comments" permissions to execute arbitrary PHP code... Read more
Affected Products : dotclear- EPSS Score: %1.12
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025