Latest CVE Feed
-
6.1
MEDIUMCVE-2014-8758
Cross-site scripting (XSS) vulnerability in Best Gallery Albums Plugin before 3.0.70for WordPress allows remote attackers to inject arbitrary web script or HTML via the order_id parameter in the gallery_album_sorting page to wp-admin/admin.php.... Read more
Affected Products : gallery_bank- EPSS Score: %0.18
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16797
In SWFTools 0.9.2, the png_load function in lib/png.c does not properly validate an alloclen_64 multiplication of width and height values, which allows remote attackers to cause a denial of service (integer overflow, heap-based buffer overflow, and applic... Read more
Affected Products : swftools- EPSS Score: %0.25
- Published: Nov. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11658
In the WP Rocket plugin 2.9.3 for WordPress, the Local File Inclusion mitigation technique is to trim traversal characters (..) -- however, this is insufficient to stop remote attacks and can be bypassed by using 0x00 bytes, as demonstrated by a .%00.../.... Read more
Affected Products : wp-rocket- EPSS Score: %3.03
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6497
main/java/org/apache/directory/groovyldap/LDAP.java in the Groovy LDAP API in Apache allows attackers to conduct LDAP entry poisoning attacks by leveraging setting returnObjFlag to true for all search methods.... Read more
- EPSS Score: %3.01
- Published: Jan. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6492
The MT6573FDVT_SetRegHW function in camera_fdvt.c in the MediaTek driver for Linux allows local users to gain privileges via a crafted application that makes an MT6573FDVTIOC_T_SET_FDCONF_CMD IOCTL call.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11465
The parser_yyerror function in the UTF-8 parser in Ruby 2.4.1 allows attackers to cause a denial of service (invalid write or read) or possibly have unspecified other impact via a crafted Ruby script, related to the parser_tokadd_utf8 function in parse.y.... Read more
Affected Products : ruby- EPSS Score: %0.38
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
4.0
MEDIUMCVE-2017-9843
SAP NetWeaver AS ABAP 7.40 allows remote authenticated users with certain privileges to cause a denial of service (process crash) via vectors involving disp+work.exe, aka SAP Security Note 2406841.... Read more
- EPSS Score: %0.27
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4905
SQL injection vulnerability in the WP-OliveCart versions prior to 3.1.3 and WP-OliveCartPro versions prior to 3.1.8 allows attackers with administrator rights to execute arbitrary SQL commands via unspecified vectors.... Read more
- EPSS Score: %1.73
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17105
Zivif PR115-204-P-RS V2.3.4.2103 and V4.7.4.2121 (and possibly in-between versions) web cameras are vulnerable to unauthenticated, blind remote command injection via CGI scripts used as part of the web interface, as demonstrated by a cgi-bin/iptest.cgi?cm... Read more
- EPSS Score: %91.75
- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2016-6037
IBM Rational Team Concert (RTC) is vulnerable to HTML injection. A remote attacker with project administrator privileges could send a project that contains malicious HTML code, which when the project is viewed, would be executed in the victim's Web browse... Read more
Affected Products : rational_collaborative_lifecycle_management rational_quality_manager rational_team_concert- EPSS Score: %0.15
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-9836
Cross-site scripting (XSS) vulnerability in Piwigo 2.9.1 allows remote authenticated administrators to inject arbitrary web script or HTML via the virtual_name parameter to /admin.php (i.e., creating a virtual album).... Read more
Affected Products : piwigo- EPSS Score: %0.16
- Published: Jun. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9816
Cross-site scripting (XSS) vulnerability in Paessler PRTG Network Monitor before 17.2.32.2279 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : prtg_network_monitor- EPSS Score: %0.25
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-10831
Untrusted search path vulnerability in The electronic authentication system based on the commercial registration system "The CRCA user's Software" Ver1.8 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : commercial_registration_electronic_authentication_software- EPSS Score: %0.18
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10795
Cross-site scripting (XSS) vulnerability in Subrion CMS 4.1.4 allows remote attackers to inject arbitrary web script or HTML via the body to blog/add/, a different vulnerability than CVE-2017-6069.... Read more
Affected Products : subrion- EPSS Score: %0.22
- Published: Jul. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9810
There are no Anti-CSRF tokens in any forms on the web interface in Kaspersky Anti-Virus for Linux File Server before Maintenance Pack 2 Critical Fix 4 (version 8.0.4.312). This would allow an attacker to submit authenticated requests when an authenticated... Read more
Affected Products : anti-virus_for_linux_server- EPSS Score: %1.08
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-7240
Cross-site scripting (XSS) vulnerability in the Easy Contact Form Solution plugin before 1.7 for WordPress allows remote attackers to inject arbitrary web script or HTML via the value parameter in a master_response action to wp-admin/admin-ajax.php.... Read more
Affected Products : easy_contact_form_solution- EPSS Score: %0.18
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9962
Schneider Electric's ClearSCADA versions released prior to August 2017 are susceptible to a memory allocation vulnerability, whereby malformed requests can be sent to ClearSCADA client applications to cause unexpected behavior. Client applications affecte... Read more
Affected Products : clearscada- EPSS Score: %0.57
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9922
IrfanView version 4.44 (32bit) with TOOLS Plugin 4.50 might allow attackers to cause a denial of service or execute arbitrary code via a crafted file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!LdrpCompareR... Read more
- EPSS Score: %0.03
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9904
XnView Classic for Windows Version 2.40 allows remote attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df0000!Rtl... Read more
Affected Products : xnview- EPSS Score: %0.28
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9882
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to execute arbitrary code or cause a denial of service via a crafted .fpx file, related to a "Read Access Violation on Block Data Move starting at FPX!FPX_GetScanDevicePropertyGroup+0x00... Read more
- EPSS Score: %0.21
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025