Latest CVE Feed
-
9.0
HIGHCVE-2017-7283
An authenticated user of Unitrends Enterprise Backup before 9.1.2 can execute arbitrary OS commands by sending a specially crafted filename to the /api/restore/download-files endpoint, related to the downloadFiles function in api/includes/restore.php.... Read more
Affected Products : enterprise_backup- EPSS Score: %16.60
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7257
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_content parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- EPSS Score: %0.21
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17475
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82736068.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.03
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2863
An out-of-bounds write vulnerability exists in the PDF parsing functionality of Infix 7.1.5. A specially crafted PDF file can cause a vulnerability resulting in potential memory corruption. An attacker can send the victim a specific PDF file to trigger th... Read more
Affected Products : infix- EPSS Score: %0.25
- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17467
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730074.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.03
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-6916
CSRF exists in BigTree CMS 4.1.18 with the nav-social[#] parameter to the admin/settings/update/ page. The Navigation Social can be changed.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.12
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6907
An issue was discovered in Open.GL before 2017-03-13. The vulnerability exists due to insufficient filtration of user-supplied data (content) passed to the "Open.GL-master/index.php" URL. An attacker could execute arbitrary HTML and script code in a brows... Read more
Affected Products : open.gl- EPSS Score: %0.22
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6878
Cross-site scripting (XSS) vulnerability in MetInfo 5.3.15 allows remote authenticated users to inject arbitrary web script or HTML via the name_2 parameter to admin/column/delete.php.... Read more
Affected Products : metinfo- EPSS Score: %0.29
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-6792
A vulnerability in the batch provisioning feature in Cisco Prime Collaboration Provisioning Tool could allow an authenticated, remote attacker to overwrite system files as root. The vulnerability is due to lack of input validation of the parameters in Bat... Read more
Affected Products : prime_collaboration_provisioning- EPSS Score: %0.40
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6724
A vulnerability in the web framework code of Cisco Prime Infrastructure could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. More Information: CSCuw65843.... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.35
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6698
A vulnerability in the Cisco Prime Infrastructure (PI) and Evolved Programmable Network Manager (EPNM) SQL database interface could allow an authenticated, remote attacker to impact the confidentiality and integrity of the application by executing arbitra... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.20
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-6695
A vulnerability in the ConfD server in Cisco Ultra Services Platform could allow an authenticated, local attacker to view sensitive information. More Information: CSCvd29398. Known Affected Releases: 21.0.v0.65839.... Read more
Affected Products : ultra_services_platform- EPSS Score: %0.07
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6682
A vulnerability in the ConfD CLI of Cisco Elastic Services Controllers could allow an authenticated, remote attacker to run arbitrary commands as the Linux tomcat user on an affected system. More Information: CSCvc76620. Known Affected Releases: 2.2(9.76)... Read more
- EPSS Score: %0.95
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-6613
A vulnerability in the DNS input packet processor for Cisco Prime Network Registrar could allow an unauthenticated, remote attacker to cause the DNS process to momentarily restart, which could lead to a partial denial of service (DoS) condition on the aff... Read more
Affected Products : prime_network_registrar- EPSS Score: %0.29
- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6250
NVIDIA GeForce Experience contains a vulnerability in NVIDIA Web Helper.exe, where untrusted script execution may lead to violation of application execution policy and local code execution.... Read more
Affected Products : geforce_experience- EPSS Score: %0.06
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6537
A Cross-Site Scripting (XSS) issue was discovered in webpagetest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data (bgcolor) passed to the webpagetest-master/www/video/view.php URL. An attacker could execute arbitrary HTML... Read more
Affected Products : webpagetest- EPSS Score: %0.22
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6445
The auto-update feature of Open Embedded Linux Entertainment Center (OpenELEC) 6.0.3, 7.0.1, and 8.0.4 uses neither encrypted connections nor signed updates. A man-in-the-middle attacker could manipulate the update packages to gain root access remotely.... Read more
Affected Products : openelec- EPSS Score: %0.28
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6190
Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" request.... Read more
- EPSS Score: %64.65
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6102
Persistent XSS in wordpress plugin rockhoist-badges v1.2.2.... Read more
Affected Products : rockhoist_badges_plugin- EPSS Score: %0.24
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6071
CMS Made Simple version 1.x Form Builder before version 0.8.1.6 allows remote attackers to conduct information-disclosure attacks via exportxml.... Read more
- EPSS Score: %0.31
- Published: Feb. 21, 2017
- Modified: Apr. 20, 2025