Latest CVE Feed
-
9.3
HIGHCVE-2017-10954
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Bitdefender Internet Security Internet Security 2018 prior to build 7.72918. User interaction is required to exploit this vulnerability in that the target ... Read more
Affected Products : internet_security_2018- EPSS Score: %6.34
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12881
Cross-site request forgery (CSRF) vulnerability in the Spring Batch Admin before 1.3.0 allows remote attackers to hijack the authentication of unspecified victims and submit arbitrary requests, such as exploiting the file upload vulnerability.... Read more
Affected Products : spring_batch_admin- EPSS Score: %0.16
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12818
Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service.... Read more
Affected Products : sentinel_ldk_rte_firmware- EPSS Score: %0.95
- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12679
SQL Injection exists in NexusPHP 1.5.beta5.20120707 via the delcheater parameter to cheaterbox.php.... Read more
Affected Products : nexusphp- EPSS Score: %0.29
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12639
Stack based buffer overflow in Ipswitch IMail server up to and including 12.5.5 allows remote attackers to execute arbitrary code via unspecified vectors in IMmailSrv, aka ETRE or ETCTERARED.... Read more
Affected Products : imail_server- EPSS Score: %0.19
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12579
An insecure suid wrapper binary in the HashiCorp Vagrant VMware Fusion plugin (aka vagrant-vmware-fusion) 4.0.24 and earlier allows a non-root user to obtain a root shell.... Read more
Affected Products : vagrant_vmware_fusion- EPSS Score: %0.33
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-8299
Buffer overflow in the Group messages monitor (Falcon) in KNX ETS 4.1.5 (Build 3246) allows remote attackers to execute arbitrary code via a crafted KNXnet/IP UDP packet.... Read more
Affected Products : ets- EPSS Score: %12.45
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-12480
Sandboxie installer 5071703 has a DLL Hijacking or Unsafe DLL Loading Vulnerability via a Trojan horse dwmapi.dll or profapi.dll file in an AppData\Local\Temp directory.... Read more
Affected Products : sandboxie_installer- EPSS Score: %0.19
- Published: Aug. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12304
A vulnerability in the IOS daemon (IOSd) web-based management interface of Cisco IOS and IOS XE Software could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface on... Read more
Affected Products : ios- EPSS Score: %0.17
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12290
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an ... Read more
Affected Products : email_encryption- EPSS Score: %0.16
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-7875
ctools 6.x-1.x before 6.x-1.14 and 7.x-1.x before 7.x-1.8 in Drupal does not verify the "edit" permission for the "content type" plugins that are used on Panels and similar systems to place content and functionality on a page.... Read more
Affected Products : ctools- EPSS Score: %0.27
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1227
IBM Tivoli Endpoint Manager could allow a unauthorized user to consume all resources and crash the system. IBM X-Force ID: 123906.... Read more
Affected Products : bigfix_platform- EPSS Score: %0.33
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-7740
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) via vectors involving an application that passes crafted input to the GPU driver.... Read more
- EPSS Score: %0.02
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7670
Multiple SQL injection vulnerabilities in includes/update.php in the Support Ticket System plugin before 1.2.1 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) user or (2) id parameter.... Read more
Affected Products : support_ticket_system- EPSS Score: %0.35
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
2.5
LOWCVE-2017-1211
IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0.2 could disclose sensitive information to a local user when logging is enabled. IBM X-Force ID: 123851.... Read more
Affected Products : daeja_viewone- EPSS Score: %0.04
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-12094
An exploitable vulnerability exists in the WiFi Channel parsing of Circle with Disney running firmware 2.0.1. A specially crafted SSID can cause the device to execute arbitrary sed commands. An attacker needs to setup an access point reachable by the devi... Read more
- EPSS Score: %0.32
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1180
The IBM TRIRIGA Document Manager contains a vulnerability that could allow an authenticated user to execute actions they did not have access to. IBM Reference #: 2001084.... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.19
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-11725
The share function in Thycotic Secret Server before 10.2.000019 mishandles the Back Button, leading to unintended redirections.... Read more
Affected Products : secret_server- EPSS Score: %0.16
- Published: Jul. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1161
IBM API Connect 5.0.6.0 could allow a remote attacker to execute arbitrary commands on the system, caused by improper validation of URLs for the Developer Portal. By crafting a malicious URL, an attacker could exploit this vulnerability to execute arbitra... Read more
Affected Products : api_connect- EPSS Score: %0.38
- Published: Apr. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11586
dayrui FineCms 5.0.9 has URL Redirector Abuse via the url parameter in a sync action, related to controllers/Weixin.php.... Read more
Affected Products : finecms- EPSS Score: %6.57
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025