Latest CVE Feed
-
9.3
HIGHCVE-2017-14263
Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can l... Read more
- EPSS Score: %24.42
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14242
SQL injection vulnerability in don/list.php in Dolibarr version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the statut parameter.... Read more
- EPSS Score: %0.34
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14238
SQL injection vulnerability in admin/menus/edit.php in Dolibarr ERP/CRM version 6.0.0 allows remote attackers to execute arbitrary SQL commands via the menuId parameter.... Read more
- EPSS Score: %0.34
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14081
Proxy command injection vulnerabilities in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allow remote attackers to execute arbitrary code on vulnerable installations.... Read more
Affected Products : mobile_security- EPSS Score: %13.34
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14070
Cross Site Scripting (XSS) exists in NexusPHP 1.5.beta5.20120707 via the PATH_INFO to ipsearch.php, related to PHP_SELF.... Read more
Affected Products : nexusphp- EPSS Score: %0.24
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14036
CrushFTP before 7.8.0 and 8.x before 8.2.0 has XSS.... Read more
Affected Products : crushftp- EPSS Score: %0.20
- Published: Aug. 30, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-14023
An Improper Input Validation issue was discovered in Siemens SIMATIC PCS 7 V8.1 prior to V8.1 SP1 with WinCC V7.3 Upd 13, and V8.2 all versions. The improper input validation vulnerability has been identified, which may allow an authenticated remote attac... Read more
- EPSS Score: %2.76
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12354
A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not suf... Read more
Affected Products : secure_access_control_system- EPSS Score: %0.50
- Published: Nov. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-2312
Sandstorm Cap'n Proto before 0.4.1.1 and 0.5.x before 0.5.1.1 allows remote peers to cause a denial of service (CPU and possibly general resource consumption) via a list with a large number of elements.... Read more
Affected Products : capnproto- EPSS Score: %0.62
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-13707
Privilege escalation in Replibit Backup Manager earlier than version 2017.08.04 allows attackers to gain root privileges via sudo command execution. The vi program can be accessed through sudo, in order to navigate the filesystem and modify a critical fil... Read more
Affected Products : replibit- EPSS Score: %0.57
- Published: Aug. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1371
Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions they do not have access to. IBM X-Force ID: 126864.... Read more
Affected Products : tririga_application_platform- EPSS Score: %0.46
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-13663
Encryption key exposure in firmware in iSmartAlarm CubeOne version 2.2.4.8 and earlier allows attackers to decrypt log files via an exposed key.... Read more
- EPSS Score: %0.08
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1354
IBM Atlas eDiscovery Process Management 6.0.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure wi... Read more
Affected Products : atlas_ediscovery_process_management- EPSS Score: %0.18
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9071
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscall.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9070
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer over-read vulnerability exists in a TrustZone syscall.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9060
In all Qualcomm products with Android releases from CAF using the Linux kernel, a pointer is not properly validated in a QTEE system call.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9052
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in LTE where an assertion can be reached while processing a downlink message.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-6882
MatrixSSL before 3.8.7, when the DHE_RSA based cipher suite is supported, makes it easier for remote attackers to obtain RSA private key information by conducting a Lenstra side-channel attack.... Read more
Affected Products : matrixssl- EPSS Score: %0.38
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-9049
In all Qualcomm products with Android releases from CAF using the Linux kernel, a vulnerability exists in the processing of certain responses from the USIM.... Read more
Affected Products : android- EPSS Score: %0.15
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2015-9006
In Resource Power Manager (RPM) in all Android releases from CAF using the Linux kernel, an Improper Access Control vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025