Latest CVE Feed
-
9.8
CRITICALCVE-2017-14738
FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).... Read more
Affected Products : filerun- EPSS Score: %6.27
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12439
SocuSoft Flash Slideshow Maker Professional through v5.20, when the advanced configuration is used, has an xml_path HTTP parameter that trusts user-supplied input, in conjunction with an unsafe XML configuration file. This has resultant content forgery, c... Read more
Affected Products : flash_slideshow_maker- EPSS Score: %0.17
- Published: Aug. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12364
A SQL Injection vulnerability in the web framework of Cisco Prime Service Catalog could allow an unauthenticated, remote attacker to execute unauthorized Structured Query Language (SQL) queries. The vulnerability is due to a failure to validate user-suppl... Read more
Affected Products : prime_service_catalog- EPSS Score: %0.32
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2017-12361
A vulnerability in Cisco Jabber for Windows could allow an unauthenticated, local attacker to access sensitive communications made by the Jabber client. An attacker could exploit this vulnerability to gain information to conduct additional attacks. The vu... Read more
Affected Products : jabber- EPSS Score: %0.07
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17635
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.... Read more
Affected Products : mlm_forex_market_plan_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
6.0
MEDIUMCVE-2017-12315
A vulnerability in system logging when replication is being configured with the Cisco HyperFlex System could allow an authenticated, local attacker to view sensitive information that should be restricted in the system log files. The attacker would have to... Read more
Affected Products : hyperflex_hx_data_platform- EPSS Score: %0.06
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17626
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.... Read more
Affected Products : readymade_php_classified_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17628
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.... Read more
Affected Products : responsive_realestate_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-8332
Huawei Video Content Management (VCM) before V100R001C10SPC001 does not properly "authenticate online user identities and privileges," which allows remote authenticated users to gain privileges and perform a case operation as another user via a crafted me... Read more
- EPSS Score: %0.24
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12216
A vulnerability in the web-based user interface of Cisco SocialMiner could allow an unauthenticated, remote attacker to have read and write access to information stored in the affected system. The vulnerability is due to improper handling of XML External ... Read more
Affected Products : socialminer- EPSS Score: %1.57
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-12476
The AP4_AvccAtom::InspectFields function in Core/Ap4AvccAtom.cpp in Bento4 mp4dump before 1.5.0-616 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted mp4 file.... Read more
Affected Products : bento4- EPSS Score: %0.26
- Published: Sep. 06, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-8805
Debian ftpsync before 20171017 does not use the rsync --safe-links option, which allows remote attackers to conduct directory traversal attacks via a crafted upstream mirror.... Read more
Affected Products : ftpsync- EPSS Score: %0.30
- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-8280
In all Qualcomm products with Android releases from CAF using the Linux kernel, during the wlan calibration data store and retrieve operation, there are some potential race conditions which lead to a memory leak and a buffer overflow during the context sw... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7570
PivotX 2.3.11 allows remote authenticated Advanced users to execute arbitrary PHP code by performing an upload with a safe file extension (such as .jpg) and then invoking the duplicate function to change to the .php extension.... Read more
Affected Products : pivotx- EPSS Score: %0.83
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-7980
Cross-site scripting (XSS) vulnerability in the Compass Rose module 6.x-1.x before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors, related to "embedding a JavaScript library from an external sourc... Read more
Affected Products : compass_rose- EPSS Score: %0.70
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6127
Multiple cross-site request forgery (CSRF) vulnerabilities in the access portal on the DIGISOL DG-HR1400 Wireless Router with firmware 1.00.02 allow remote attackers to hijack the authentication of administrators for requests that (1) change the SSID, (2)... Read more
- EPSS Score: %0.17
- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5537
The password reset form in Weblate before 2.10.1 provides different error messages depending on whether the email address is associated with an account, which allows remote attackers to enumerate user accounts via a series of requests.... Read more
Affected Products : weblate- EPSS Score: %0.54
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-5530
The tibbr web server components of tibbr Community, and tibbr Enterprise contain SAML protocol handling errors which may allow authorized users to impersonate other users, and therefore escalate their access privileges. Affected releases are tibbr Communi... Read more
Affected Products : tibbr- EPSS Score: %0.29
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-5518
The media-file upload feature in GeniXCMS through 0.0.8 allows remote attackers to conduct SSRF attacks via a URL, as demonstrated by a URL with an intranet IP address.... Read more
Affected Products : genixcms- EPSS Score: %0.40
- Published: Jan. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5219
An issue was discovered in SageCRM 7.x before 7.3 SP3. The Component Manager functionality, provided by SageCRM, permits additional components to be added to the application to enhance provided functionality. This functionality allows a zip file to be upl... Read more
Affected Products : sagecrm- EPSS Score: %4.03
- Published: Feb. 02, 2017
- Modified: Apr. 20, 2025