Latest CVE Feed
-
7.5
HIGHCVE-2017-7688
Apache OpenMeetings 1.0.0 updates user password in insecure manner.... Read more
Affected Products : openmeetings- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6652
A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could expl... Read more
Affected Products : telepresence_ix5000- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7504
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote... Read more
Affected Products : jboss_enterprise_application_platform- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-4721
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.... Read more
Affected Products : concrete_cms- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7341
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system con... Read more
Affected Products : fortiwlc- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7188
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.... Read more
Affected Products : zurmo_crm- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6995
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-6973
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17986
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.... Read more
Affected Products : muslim_matrimonial_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17956
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.... Read more
Affected Products : php_multivendor_ecommerce- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6956
On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6813
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6782
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of paramet... Read more
Affected Products : prime_infrastructure- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17744
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.... Read more
Affected Products : custom_map- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17701
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.... Read more
Affected Products : antivirus- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0494
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data withou... Read more
Affected Products : android- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17695
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.... Read more
Affected Products : techno_-_portfolio_management_panel- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6623
A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an authenticated, local attacker to escalate their privilege level to root. The vulnerability is due to inco... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.... Read more
Affected Products : laundry_booking_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17599
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.... Read more
Affected Products : advance_online_learning_management_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025