Latest CVE Feed
-
7.5
HIGHCVE-2016-10180
An issue was discovered on the D-Link DWR-932B router. WPS PIN generation is based on srand(time(0)) seeding.... Read more
- EPSS Score: %10.92
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10137
An issue was discovered on BLU R1 HD devices with Shanghai Adups software. The content provider named com.adups.fota.sysoper.provider.InfoProvider in the app with a package name of com.adups.fota.sysoper allows any app on the device to read, write, and de... Read more
Affected Products : adups_fota- EPSS Score: %0.05
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10135
An issue was discovered on LG devices using the MTK chipset with L(5.0/5.1), M(6.0/6.0.1), and N(7.0) software, and RCA Voyager Tablet, BLU Advance 5.0, and BLU R1 HD devices. The MTKLogger app with a package name of com.mediatek.mtklogger has application... Read more
Affected Products : lg_mobile- EPSS Score: %0.30
- Published: Jan. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15375
Multiple client-side cross site scripting vulnerabilities have been discovered in the WpJobBoard v4.5.1 web-application for WordPress. The vulnerabilities are located in the `query` and `id` parameters of the `wpjb-email`, `wpjb-job`, `wpjb-application`, ... Read more
Affected Products : wpjobboard- EPSS Score: %0.20
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10123
Firejail allows --chroot when seccomp is not supported, which might allow local users to gain privileges.... Read more
Affected Products : firejail- EPSS Score: %0.04
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15368
The wasm_dis function in libr/asm/arch/wasm/wasm.c in radare2 2.0.0 allows remote attackers to cause a denial of service (stack-based buffer over-read and application crash) or possibly have unspecified other impact via a crafted WASM file that triggers a... Read more
Affected Products : radare2- EPSS Score: %0.24
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-15366
Before Thornberry NDoc version 8.0, laptop clients and the server have default database (Cache) users set up with a single password. This password is left behind in a cleartext log file during client installation on laptops. This password can be used to g... Read more
Affected Products : ndoc- EPSS Score: %0.28
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10091
Multiple stack-based buffer overflows in unrtf 0.21.9 allow remote attackers to cause a denial-of-service by writing a negative integer to the (1) cmd_expand function, (2) cmd_emboss function, or (3) cmd_engrave function.... Read more
Affected Products : unrtf- EPSS Score: %2.61
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15304
/bin/login.php in the Web Panel on the Airtame HDMI dongle with firmware before 3.0 allows an attacker to set his own session id via a "Cookie: PHPSESSID=" header. This can be used to achieve persistent access to the admin panel even after an admin passwo... Read more
- EPSS Score: %0.34
- Published: Oct. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15205
In Kanboard before 1.0.47, by altering form data, an authenticated user can download attachments from a private project of another user.... Read more
Affected Products : kanboard- EPSS Score: %0.29
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15195
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit swimlanes of a private project of another user.... Read more
Affected Products : kanboard- EPSS Score: %0.49
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14985
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the url parameter to module/module_frame/index.php.... Read more
Affected Products : eyesofnetwork- EPSS Score: %0.15
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-3639
phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file.... Read more
Affected Products : phpmybackuppro- EPSS Score: %1.37
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-3617
Fortinet FortiManager 5.0 before 5.0.11 and 5.2 before 5.2.2 allow local users to gain privileges via crafted CLI commands.... Read more
Affected Products : fortimanager_firmware- EPSS Score: %0.16
- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1481
IBM Sterling B2B Integrator Standard Edition 5.2 allows a user to view sensitive information that belongs to another user. IBM X-Force ID: 128619.... Read more
Affected Products : sterling_b2b_integrator- EPSS Score: %0.18
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-3421
The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure atta... Read more
Affected Products : eshop- EPSS Score: %0.17
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-14705
DenyAll WAF before 6.4.1 allows unauthenticated remote command execution via TCP port 3001 because shell metacharacters can be inserted into the type parameter to the tailDateFile function in /webservices/stream/tail.php. An iToken authentication paramete... Read more
- EPSS Score: %4.64
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14563
STDU Viewer 1.6.375 allows attackers to execute arbitrary code or cause a denial of service via a crafted .xps file, related to a "Read Access Violation on Block Data Move starting at STDUXPSFile!DllUnregisterServer+0x0000000000005311."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.06
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1458
IBM QRadar Network Security 5.4 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 128377.... Read more
Affected Products : qradar_network_security- EPSS Score: %0.66
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-4988
EMC Isilon OneFS 8.0.1.0, 8.0.0 - 8.0.0.3, 7.2.0 - 7.2.1.4, 7.1.x is affected by a privilege escalation vulnerability that could potentially be exploited by attackers to compromise the affected system.... Read more
- EPSS Score: %0.50
- Published: Jun. 21, 2017
- Modified: Apr. 20, 2025