Latest CVE Feed
-
7.5
HIGHCVE-2017-14766
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php only require knowing the student id number.... Read more
Affected Products : simple_student_result- Published: Sep. 27, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-14717
In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.... Read more
Affected Products : epesi- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14702
ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.... Read more
Affected Products : ers_data_system- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-3342
Vulnerability in the Oracle Marketing component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 12.2.5 and 12.2.6. Easily "exploitable" vulnerability allows unauth... Read more
Affected Products : marketing- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14412
An invalid memory write was discovered in copy_mp in interface.c in mpglibDBL, as used in MP3Gain version 1.5.2. The vulnerability causes a denial of service (segmentation fault and application crash) or possibly unspecified other impact.... Read more
Affected Products : mp3gain- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14345
SQL Injection exists in tianchoy/blog through 2017-09-12 via the id parameter to view.php.... Read more
- Published: Sep. 12, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-14330
Extreme EXOS 16.x, 21.x, and 22.x allows administrators to obtain a root shell via vectors involving a privileged process.... Read more
Affected Products : extremexos- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14282
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .jb2 file, related to a "Read Access Violation starting at jbig2dec+0x0000000000005862."... Read more
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1421
IBM iNotes is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session.... Read more
Affected Products : inotes- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14194
The out function in controllers/member/Login.php in dayrui FineCms 5.0.11 has XSS related to the Referer HTTP header with Internet Explorer.... Read more
Affected Products : finecms- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16763
An exploitable vulnerability exists in the YAML parsing functionality in config.py in Confire 0.2.0. Due to the user-specific configuration being loaded from "~/.confire.yaml" using the yaml.load function, a YAML parser can execute arbitrary Python comman... Read more
Affected Products : confire- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-5532
Multiple cross-site scripting (XSS) vulnerabilities in the Paid Memberships Pro (PMPro) plugin before 1.8.4.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s parameter to membershiplevels.php, (2) memberslist.php,... Read more
Affected Products : paid_memberships_pro- Published: Oct. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16586
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.2.25013. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2016-1161
Cross-site request forgery (CSRF) vulnerability in ManageEngine Password Manager Pro before 8.5 (Build 8500).... Read more
Affected Products : password_manager_pro- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-5152
Foreman after 1.1 and before 1.9.0-RC1 does not redirect HTTP requests to HTTPS when the require_ssl setting is set to true, which allows remote attackers to obtain user credentials via a man-in-the-middle attack.... Read more
Affected Products : foreman- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15974
tPanel 2009 allows SQL injection for Authentication Bypass via 'or 1=1 or ''=' to login.php.... Read more
Affected Products : tpanel- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15918
Sera 1.2 stores the user's login password in plain text in their home directory. This makes privilege escalation trivial and also exposes the user and system keychains to local attacks.... Read more
Affected Products : sera- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15867
Multiple cross-site scripting (XSS) vulnerabilities in the user-login-history plugin through 1.5.2 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) date_from, (2) date_to, (3) user_id, (4) username, (5) country_name,... Read more
Affected Products : user-login-history- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15752
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to "Data from Faulting Address controls subsequent Write Address starting at BabaCAD4Imag... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025