Latest CVE Feed
-
7.5
HIGHCVE-2017-9134
An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. There is a page in the web interface that will show you the device's serial number, regardless of whether or not you have logged in. ... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-9097
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote ... Read more
Affected Products : antiweb- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14244
An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /p... Read more
- Published: Sep. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8893
AeroAdmin 4.1 uses a function to copy data between two pointers where the size of the data copied is taken directly from a network packet. This can cause a buffer overflow and denial of service.... Read more
Affected Products : aeroadmin- Published: Jul. 02, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-8827
forgotpassword.php in GeniXCMS 1.0.2 lacks a rate limit, which might allow remote attackers to cause a denial of service (login inability) or possibly conduct Arbitrary User Password Reset attacks via a series of requests.... Read more
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0543
A remote code execution vulnerability in libavc in Mediaserver could enable an attacker using a specially crafted file to cause memory corruption during media file and data processing. This issue is rated as Critical due to the possibility of remote code ... Read more
Affected Products : android- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8204
The Bastet driver of Honor 9 Huawei smart phones with software of versions earlier than Stanford-AL10C00B175 has a buffer overflow vulnerability due to the lack of parameter validation. An attacker tricks a user into installing a malicious APP which has t... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-8143
Wi-Fi driver of Honor 5C and P9 Lite Huawei smart phones with software versions earlier than NEM-L21C432B351 and versions earlier than VNS-L21C10B381 has a DoS vulnerability. An attacker may trick a user into installing a malicious application and the app... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-8174
Huawei USG6300 V100R001C30SPC300 and USG6600 with software of V100R001C30SPC500,V100R001C30SPC600,V100R001C30SPC700,V100R001C30SPC800 have a weak algorithm vulnerability. Attackers may exploit the weak algorithm vulnerability to crack the cipher text and ... Read more
Affected Products : secospace_usg6600_firmware secospace_usg6300_firmware secospace_usg6300 secospace_usg6600- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.6
MEDIUMCVE-2017-8032
In Cloud Foundry cf-release versions prior to v264; UAA release all versions of UAA v2.x.x, 3.6.x versions prior to v3.6.13, 3.9.x versions prior to v3.9.15, 3.20.x versions prior to v3.20.0, and other versions prior to v4.4.0; and UAA bosh release (uaa-r... Read more
Affected Products : cloud_foundry_uaa user_account_and_authentication cloud_foundry_uaa_bosh cloud_foundry_cf- Published: Jul. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7897
A cross-site scripting (XSS) vulnerability in the MantisBT (2.3.x before 2.3.2) Timeline include page, used in My View (my_view_page.php) and User Information (view_user_page.php) pages, allows remote attackers to inject arbitrary code (if CSP settings pe... Read more
Affected Products : mantisbt- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7919
An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform resource locator (URL).... Read more
- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7915
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1... Read more
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7879
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.... Read more
Affected Products : flatcore-cms- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7643
Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.... Read more
Affected Products : proxifier- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2016-2567
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by th... Read more
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2336
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.... Read more
Affected Products : ruby- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6823
Fiyo CMS 2.0.6.1 allows remote authenticated users to gain privileges via a modified level parameter to dapur/ in an app=user&act=edit action.... Read more
Affected Products : fiyo_cms- Published: Mar. 12, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6781
A vulnerability in the management of shell user accounts for Cisco Policy Suite (CPS) Software for CPS appliances could allow an authenticated, local attacker to gain elevated privileges on an affected system. The affected privilege level is not at the ro... Read more
Affected Products : policy_suite- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6643
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Virtual Directory information on an affected system. The vulnerability exists because the affected soft... Read more
Affected Products : remote_expert_manager- Published: May. 22, 2017
- Modified: Apr. 20, 2025