Latest CVE Feed
-
5.3
MEDIUMCVE-2017-8115
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.... Read more
Affected Products : modx_revolution- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8045
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code exec... Read more
Affected Products : spring_advanced_message_queuing_protocol- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8004
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identi... Read more
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-7964
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.... Read more
Affected Products : wre6505_firmware- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7896
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.... Read more
Affected Products : interscan_messaging_security_virtual_appliance- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7721
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.... Read more
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7688
Apache OpenMeetings 1.0.0 updates user password in insecure manner.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6652
A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could expl... Read more
Affected Products : telepresence_ix5000- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7504
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote... Read more
Affected Products : jboss_enterprise_application_platform- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-4721
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.... Read more
Affected Products : concrete_cms- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7341
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system con... Read more
Affected Products : fortiwlc- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7188
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.... Read more
Affected Products : zurmo_crm- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6995
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-6973
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17986
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.... Read more
Affected Products : muslim_matrimonial_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17956
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.... Read more
Affected Products : php_multivendor_ecommerce- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6956
On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6813
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6782
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of paramet... Read more
Affected Products : prime_infrastructure- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17744
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.... Read more
Affected Products : custom_map- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025