Latest CVE Feed
-
8.8
HIGHCVE-2017-1311
IBM Insights Foundation for Energy 2.0 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 12571... Read more
Affected Products : insights_foundation_for_energy- EPSS Score: %0.62
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-12213
A vulnerability in the dynamic access control list (ACL) feature of Cisco IOS XE Software running on Cisco Catalyst 4000 Series Switches could allow an unauthenticated, adjacent attacker to cause dynamic ACL assignment to fail and the port to fail open. T... Read more
- EPSS Score: %0.24
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12320
Multiple vulnerabilities in the web interface of the Cisco Registered Envelope Service (a cloud-based service) could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack or redirect a user of the affected service to an ... Read more
- EPSS Score: %0.16
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17645
Bus Booking Script 1.0 has SQL Injection via the txtname parameter to admin/index.php.... Read more
Affected Products : bus_booking_script- EPSS Score: %2.51
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-12300
A vulnerability in the SNORT detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass a file policy that is configured to block the Server Message Block Version 2 (SMB2) protocol. The vulnerability is d... Read more
Affected Products : firepower_management_center firepower_threat_defense secure_firewall_management_center- EPSS Score: %0.23
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12298
A vulnerability in Cisco WebEx Meeting Center could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of an affected system. The vulnerability is due to insufficient input validation of some parameters... Read more
Affected Products : webex_meeting_center- EPSS Score: %0.23
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12295
A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to access sensitive data about the application. An attacker could exploit this vulnerability to gain information to conduct additional reconnaissance attacks. T... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.36
- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17625
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.... Read more
Affected Products : on_demand_marketplace_script- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-8350
Multiple cross-site scripting (XSS) vulnerabilities in the Calls to Action plugin before 2.5.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) open-tab parameter in a wp_cta_global_settings action to wp-admin/edit.p... Read more
Affected Products : call_to_action- EPSS Score: %0.43
- Published: Sep. 11, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12096
An exploitable vulnerability exists in the WiFi management of Circle with Disney. A crafted Access Point with the same name as the legitimate one can be used to make Circle connect to an untrusted network. An attacker needs to setup an Access Point reacha... Read more
- EPSS Score: %0.10
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2015-8089
The GPU driver in Huawei P7 phones with software P7-L00 before P7-L00C17B851, P7-L05 before P7-L05C00B851, and P7-L09 before P7-L09C92B851 allows local users to read or write to arbitrary kernel memory locations and consequently cause a denial of service ... Read more
- EPSS Score: %0.02
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-12084
A backdoor vulnerability exists in remote control functionality of Circle with Disney running firmware 2.0.1. A specific set of network packets can remotely start an SSH server on the device, resulting in a persistent backdoor. An attacker can send an API... Read more
- EPSS Score: %0.39
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2015-7895
Samsung Gallery on the Samsung Galaxy S6 allows local users to cause a denial of service (process crash).... Read more
- EPSS Score: %0.29
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7214
An issue was discovered in exception_wrapper.py in OpenStack Nova 13.x through 13.1.3, 14.x through 14.0.4, and 15.x through 15.0.1. Legacy notification exception contexts appearing in ERROR level logs may include sensitive information such as account pas... Read more
Affected Products : nova- EPSS Score: %1.30
- Published: Mar. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6557
SQL injection vulnerability in ArrayOS before AG 9.4.0.135, when the portal bookmark function is enabled, allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : arrayos- EPSS Score: %0.37
- Published: May. 05, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3815
An API Privilege vulnerability in Cisco TelePresence Server Software could allow an unauthenticated, remote attacker to emulate Cisco TelePresence Server endpoints. Affected Products: This vulnerability affects Cisco TelePresence Server MSE 8710 Processor... Read more
Affected Products : telepresence_server_software- EPSS Score: %0.13
- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6039
A Use of Hard-Coded Password issue was discovered in Phoenix Broadband PowerAgent SC3 BMS, all versions prior to v6.87. Use of a hard-coded password may allow unauthorized access to the device.... Read more
- EPSS Score: %0.24
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2015-7891
Race condition in the ioctl implementation in the Samsung Graphics 2D driver (aka /dev/fimg2d) in Samsung devices with Android L(5.0/5.1) allows local users to trigger memory errors by leveraging definition of g2d_lock and g2d_unlock lock macros as no-ops... Read more
Affected Products : samsung_mobile- EPSS Score: %0.17
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2015-7880
The Entity Registration module 7.x-1.x before 7.x-1.5 for Drupal allows remote attackers to obtain sensitive event registration information by leveraging the "Register other accounts" permission and knowledge of usernames.... Read more
Affected Products : drupal- EPSS Score: %0.06
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2016-8751
Apache Ranger before 0.6.3 is vulnerable to a Stored Cross-Site Scripting in when entering custom policy conditions. Admin users can store some arbitrary javascript code to be executed when normal users login and access policies.... Read more
Affected Products : ranger- EPSS Score: %0.21
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025