Latest CVE Feed
-
9.8
CRITICALCVE-2015-7224
puppetlabs-mysql 3.1.0 through 3.6.0 allow remote attackers to bypass authentication by leveraging creation of a database account without a password when a 'mysql_user' user parameter contains a host with a netmask.... Read more
Affected Products : puppetlabs-mysql- Published: Dec. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15317
AR120-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR1200 V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30; AR1200-S V200R006C10, V200R007C00, V200R008C20, V200R008C30; AR150 V200R006C10, V200R007C00, V200... Read more
Affected Products : ar1200_firmware ar200_firmware ar3200_firmware ar120-s_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200-s_firmware ar2200_firmware +20 more products- Published: Dec. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-4463
The file_manager component in eFront CMS before 3.6.15.5 allows remote authenticated users to bypass intended file-upload restrictions by appending a crafted parameter to the file URL.... Read more
Affected Products : efront- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-8105
Drivers for the Intel Ethernet Controller X710 and Intel Ethernet Controller XL710 families before version 22.0 are vulnerable to a denial of service in certain layer 2 network configurations.... Read more
- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17114
ntguard.sys and ntguard_x64.sys 0.18780.0.0 in IKARUS anti.virus 2.16.15 have a Memory Corruption vulnerability via a 0x83000084 DeviceIoControl request.... Read more
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-16958
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/bridge command to cgi-bin/luci, related to the get_device_byif function in /usr/lib/l... Read more
Affected Products : tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware tl-wvr900l_firmware +98 more products- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10216
Vulnerability in the Hospitality Property Interfaces component of Oracle Hospitality Applications (subcomponent: Parser). The supported version that is affected is 8.10.x. Easily exploitable vulnerability allows low privileged attacker with network access... Read more
Affected Products : hospitality_suite8_property_interfaces- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10215
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub component of Oracle PeopleSoft Products (subcomponent: EPPCM_DEFN_CATG). The supported version that is affected is 9.1.0. Easily exploitable vulnerability allows unauthenticated attacker with... Read more
Affected Products : peoplesoft_enterprise_prtl_interaction_hub- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-10166
Vulnerability in the Oracle Security Service component of Oracle Fusion Middleware (subcomponent: C Oracle SSL API). Supported versions that are affected are FMW: 11.1.1.9.0 and 12.1.3.0.0. Difficult to exploit vulnerability allows unauthenticated attacke... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-3998
Cross-site scripting (XSS) vulnerability in phpwhois 4.2.5, as used in the adsense-click-fraud-monitoring plugin 1.7.5 for WordPress, allows remote attackers to inject arbitrary web script or HTML via the query parameter to whois.php.... Read more
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-1894
NetApp OnCommand Workflow Automation before 3.1P2 allows remote attackers to bypass authentication via unspecified vectors.... Read more
Affected Products : oncommand_workflow_automation- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-8494
Insufficient verification of uploaded files allows attackers with webui administrators privileges to perform arbitrary code execution by uploading a new webui theme.... Read more
Affected Products : connect- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-10206
Cross-site request forgery (CSRF) vulnerability in Zoneminder 1.30 and earlier allows remote attackers to hijack the authentication of users for requests that change passwords and possibly have unspecified other impact as demonstrated by a crafted user ac... Read more
Affected Products : zoneminder- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9728
IBM Qradar 7.2 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, information in the back-end database. IBM Reference #: 1999543.... Read more
Affected Products : qradar_security_information_and_event_manager- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-6756
An information disclosure vulnerability in Qualcomm components including the camera driver and video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requir... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-0356
IBM Sametime Enterprise Meeting Server 8.5.2 and 9.0 could allow an authenticated user that has been invited to a Sametime meeting room, to cause the screen sharing to cease through the use of cross-site request forgery. IBM X-Force ID: 111895.... Read more
Affected Products : sametime- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1449
IBM Emptoris Sourcing 9.5 - 10.1.3 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL ... Read more
Affected Products : emptoris_sourcing- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14406
A NULL pointer dereference was discovered in sync_buffer in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a segmentation fault and application crash, which leads to remote denial of service.... Read more
Affected Products : mp3gain- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1431
IBM InfoSphere Streams 4.0, 4.1, and 4.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within ... Read more
Affected Products : infosphere_streams- Published: Aug. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-14263
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can l... Read more
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025