Latest CVE Feed
-
5.9
MEDIUMCVE-2014-9686
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists bec... Read more
Affected Products : googlemaps- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12413
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.... Read more
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-8621
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.... Read more
Affected Products : store_locator- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10838
Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : seo_panel- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12271
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker ... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-9310
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.... Read more
Affected Products : wordpress_backup_to_dropbox- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-8903
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.... Read more
Affected Products : curam_social_program_management- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUM- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-7851
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with th... Read more
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11161
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.... Read more
Affected Products : photo_station- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15581
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which al... Read more
Affected Products : diary_with_lock- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11155
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.... Read more
Affected Products : photo_station- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10801
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.... Read more
Affected Products : phpsocial- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-7241
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) set... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5156
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems o... Read more
Affected Products : wonderware_intouch_access_anywhere- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-8180
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.... Read more
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9960
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.... Read more
Affected Products : u.motion_builder- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9931
Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter to ajax.cgi.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9886
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df000... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9785
Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.... Read more
Affected Products : nancy- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025