Latest CVE Feed
-
5.3
MEDIUMCVE-2017-12363
A vulnerability in Cisco WebEx Meeting Server could allow an unauthenticated, remote attacker to modify the welcome message of a meeting on an affected system. The vulnerability is due to insufficient security settings on meetings. An attacker could explo... Read more
Affected Products : webex_meetings_server- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11394
Proxy command injection vulnerability in Trend Micro OfficeScan 11 and XG (12) allows remote attackers to execute arbitrary code on vulnerable installations. The specific flaw can be exploited by parsing the T parameter within Proxy.php. Formerly ZDI-CAN-... Read more
Affected Products : officescan- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11383
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when executing opcode 0x1b07 due to lack of proper user input validation in cmdHandlerTVCSCommander.dll. Formerly ZDI-CAN-4560.... Read more
Affected Products : control_manager- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-5187
Candlepin allows remote attackers to obtain sensitive information by obtaining Java exception statements as a result of excessive web traffic.... Read more
Affected Products : candlepin- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11165
dataTaker DT80 dEX 1.50.012 allows remote attackers to obtain sensitive credential and configuration information via a direct request for the /services/getFile.cmd?userfile=config.xml URI.... Read more
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-11149
Server-side request forgery (SSRF) vulnerability in Downloader in Synology Download Station 3.8.x before 3.8.5-3475 and 3.x before 3.5-2984 allows remote authenticated users to download arbitrary local files via crafted URI.... Read more
Affected Products : download_station- Published: Aug. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11048
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a display driver function, a Use After Free condition can occur.... Read more
Affected Products : android- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-11045
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in a camera driver function, a race condition exists which can lead to a Use After Free condition.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-10899
SQL injection vulnerability in the A-Reserve and A-Reserve for MT cloud versions 3.8.6 and earlier allows an attacker to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : a-reserve- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2015-2692
AdBlock before 2.21 allows remote attackers to block arbitrary resources on arbitrary websites and to disable arbitrary blocking filters.... Read more
Affected Products : adblock- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10747
XnView Classic for Windows Version 2.40 allows attackers to execute arbitrary code or cause a denial of service via a crafted .rle file, related to a "User Mode Write AV starting at xnview+0x000000000037a8aa."... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17988
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.... Read more
Affected Products : muslim_matrimonial_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-13162
An elevation of privilege vulnerability in the kernel binder. Product: Android. Versions: Android kernel. Android ID A-64216036.... Read more
Affected Products : android- Published: Dec. 06, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7224
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.... Read more
Affected Products : puppetlabs-mysql- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15317
AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200... Read more
Affected Products : ar1200_firmware ar200_firmware ar3200_firmware ar120-s_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200-s_firmware ar2200_firmware +20 more products- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-4463
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.... Read more
Affected Products : efront- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-8105
Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial of service in certain layer 2 network configurations.... Read more
- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17114
ntguard.sys and ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 have a Memory Corruption vulnerability via a 0x83000084 DeviceIoControl request.... Read more
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-16958
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/l... Read more
Affected Products : tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware tl-wvr900l_firmware +98 more products- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10216
Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access... Read more
Affected Products : hospitality_suite8_property_interfaces- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025