Latest CVE Feed
-
7.5
HIGHCVE-1999-0236
ScriptAlias directory in NCSA and Apache httpd allowed attackers to read CGI programs.... Read more
- EPSS Score: %9.16
- Published: Jan. 01, 1997
- Modified: Apr. 20, 2025
-
6.3
MEDIUMCVE-2017-14124
In eLux RP 5.x before 5.5.1000 LTSR and 5.6.x before 5.6.2 CR when classic desktop mode is used, it is possible to start applications other than defined, even if the user does not have permissions to change application definitions.... Read more
Affected Products : rp- EPSS Score: %0.04
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11324
An issue was discovered in Tilde CMS 1.0.1. Due to missing escaping of the backtick character, a SELECT query in class.SystemAction.php is vulnerable to SQL Injection. The vulnerability can be triggered via a POST request to /actionphp/action.input.php wi... Read more
Affected Products : tilde_cms- EPSS Score: %0.25
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0919
EMC RSA Web Threat Detection version 5.0, RSA Web Threat Detection version 5.1, RSA Web Threat Detection version 5.1.2 has a cross site scripting vulnerability that could potentially be exploited by malicious users to compromise the affected system.... Read more
Affected Products : web_threat_detection- EPSS Score: %0.46
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14050
In BlackCat CMS 1.2, backend/addons/install.php allows remote authenticated users to execute arbitrary PHP code via a ZIP archive that contains a .php file.... Read more
Affected Products : blackcat_cms- EPSS Score: %0.51
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14031
An Improper Access Control issue was discovered in Trihedral VTScada 11.3.03 and prior. A local, non-administrator user has privileges to read and write to the file system of the target machine.... Read more
Affected Products : vtscada- EPSS Score: %0.04
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-0781
The UAA OAuth approval pages in Cloud Foundry v208 to v231, Login-server v1.6 to v1.14, UAA v2.0.0 to v2.7.4.1, UAA v3.0.0 to v3.2.0, UAA-Release v2 to v7 and Pivotal Elastic Runtime 1.6.x versions prior to 1.6.20 are vulnerable to an XSS attack by specif... Read more
Affected Products : cloud_foundry_elastic_runtime cloud_foundry_uaa cloud_foundry_uaa_bosh cloud_foundry login-server- EPSS Score: %0.27
- Published: May. 25, 2017
- Modified: Apr. 20, 2025
-
8.3
HIGHCVE-2017-2798
An exploitable heap corruption vulnerability exists in the GetIndexArray functionality of Antenna House DMC HTMLFilter as used by MarkLogic 8.0-6. A specially crafted XLS file can cause a heap corruption resulting in arbitrary code execution. An attacker ... Read more
Affected Products : marklogic- EPSS Score: %0.61
- Published: May. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2779
An exploitable memory corruption vulnerability exists in the RSRC segment parsing functionality of LabVIEW 2017, LabVIEW 2016, LabVIEW 2015, and LabVIEW 2014. A specially crafted Virtual Instrument (VI) file can cause an attacker controlled looping condit... Read more
Affected Products : labview- EPSS Score: %0.62
- Published: Sep. 05, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-2731
The vibrator service in P9 Plus smart phones with software versions earlier before VIE-AL10C00B386 has DoS vulnerability. An attacker can tricks a user into installing a malicious application on the smart phone, and send given parameter to smart phone vib... Read more
- EPSS Score: %0.07
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-5051
OSRAM SYLVANIA Osram Lightify Home before 2016-07-26 stores a PSK in cleartext under /private/var/mobile/Containers/Data/Application.... Read more
Affected Products : lightify_home- EPSS Score: %0.49
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10222
runtime/JSONObject.cpp in JavaScriptCore in WebKit, as distributed in Safari Technology Preview Release 18, allows remote attackers to cause a denial of service (segmentation violation and application crash) via crafted JavaScript code that triggers a "ty... Read more
Affected Products : safari- EPSS Score: %0.46
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-1603
An information leak in the NetIQ IDM ServiceNow Driver before 1.0.0.1 could expose cryptographic attributes to logged-in users.... Read more
Affected Products : netiq_idm_servicenow_driver- EPSS Score: %0.60
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUM- EPSS Score: %0.30
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2016-9468
Nextcloud Server before 9.0.54 and 10.0.1 & ownCloud Server before 9.0.6 and 9.1.2 suffer from content spoofing in the dav app. The exception message displayed on the DAV endpoints contained partially user-controllable input leading to a potential misrepr... Read more
- EPSS Score: %0.30
- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-3740
Heap-based buffer overflow in the CreateFXPDFConvertor function in ConvertToPdf_x86.dll in Foxit Reader 7.3.4.311 allows remote attackers to execute arbitrary code via a large SamplesPerPixel value in a crafted TIFF image that is mishandled during PDF con... Read more
Affected Products : foxit_reader- EPSS Score: %1.30
- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-0885
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a error message disclosing existence of file in write-only share. Due to an error in the application logic an adversary with access to a write-only share may enumerate the names of existing files and ... Read more
Affected Products : nextcloud_server- EPSS Score: %0.63
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2015-2883
Philips In.Sight B120/37 has XSS, related to the Weaved cloud web service, as demonstrated by the name parameter to deviceSettings.php or shareDevice.php.... Read more
Affected Products : in.sight_b120\\37- EPSS Score: %0.21
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1369
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : rational_engineering_lifecycle_manager- EPSS Score: %0.27
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-0218
IBM Cognos Business Intelligence and IBM Cognos Analytics are vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A remote attacker could exploit this vulnerability using a specially-crafted URL to execute script in ... Read more
Affected Products : cognos_business_intelligence- EPSS Score: %0.16
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025