Latest CVE Feed
-
8.8
HIGHCVE-2017-9603
SQL injection vulnerability in the WP Jobs plugin before 1.5 for WordPress allows authenticated users to execute arbitrary SQL commands via the jobid parameter to wp-admin/edit.php.... Read more
Affected Products : wp_jobs- EPSS Score: %1.29
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9570
The mount-vernon-bank-trust-mobile-banking/id542706679 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : mount_vernon_bank_\&_trust_mobile_banking- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9562
The Freedom First freedom-1st-credit-union-mobile-banking/id1085229458 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certific... Read more
Affected Products : freedom_1st_credit_union_mobile_banking- EPSS Score: %0.12
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9548
admin.php in BigTree through 4.2.18 has a Cross-site Scripting (XSS) vulnerability, which allows remote authenticated users to inject arbitrary web script or HTML by launching a Home Template Edit Page action and entering the Navigation Title of a page th... Read more
Affected Products : bigtree_cms- EPSS Score: %0.14
- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9475
Comcast XFINITY WiFi Home Hotspot devices allow remote attackers to spoof the identities of Comcast customers via a forged MAC address.... Read more
Affected Products : xfinity_wifi_hotspot- EPSS Score: %0.55
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9435
Dolibarr ERP/CRM before 5.0.3 is vulnerable to a SQL injection in user/index.php (search_supervisor and search_statut parameters).... Read more
- EPSS Score: %0.33
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9368
An information disclosure vulnerability in the BlackBerry Workspaces Server could result in an attacker gaining access to source code for server-side applications by crafting a request for specific files.... Read more
- EPSS Score: %0.29
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9336
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.... Read more
Affected Products : wp_editor.md- EPSS Score: %0.24
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-2738
VCM5010 with software versions earlier before V100R002C50SPC100 has an authentication bypass vulnerability. This is due to improper implementation of authentication for accessing web pages. An unauthenticated attacker could bypass the authentication by se... Read more
- EPSS Score: %1.25
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-2714
The GaussDB in FusionSphere OpenStack V100R005C10SPC705 and earlier versions has a buffer overflow vulnerability. An authenticated attacker on the LAN can exploit this vulnerability to execute arbitrary code or cause a denial of service (DoS) condition in... Read more
Affected Products : fusionsphere_openstack- EPSS Score: %0.06
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9136
An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user. The attacker can download any file... Read more
- EPSS Score: %0.12
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-9133
An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hosts from the device and view the results. The user is al... Read more
- EPSS Score: %0.38
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2017-2684
Siemens SIMATIC Logon prior to V1.5 SP3 Update 2 could allow an attacker with knowledge of a valid user name, and physical or network access to the affected system, to bypass the application-level authentication.... Read more
Affected Products : simatic_logon- EPSS Score: %1.71
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8926
Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.... Read more
Affected Products : logview_pro- EPSS Score: %1.33
- Published: May. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8836
CSRF exists on Peplink Balance 305, 380, 580, 710, 1350, and 2500 devices with firmware before fw-b305hw2_380hw6_580hw2_710hw3_1350hw2_2500-7.0.1-build2093. The CGI scripts in the administrative interface are affected. This allows an attacker to execute c... Read more
Affected Products : b305hw2_firmware 380hw6_firmware 580hw2_firmware 710hw3_firmware 1350hw2_firmware 2500_firmware balance_305 balance_380 balance_580 balance_710 +2 more products- EPSS Score: %0.60
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8024
EMC Isilon OneFS (versions prior to 8.1.0.1, versions prior to 8.0.1.2, versions prior to 8.0.0.6, version 7.2.1.x) is impacted by a reflected cross-site scripting vulnerability that may potentially be exploited by malicious users to compromise the affect... Read more
- EPSS Score: %0.24
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8775
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Memory Corruption while parsing a malformed Mach-O file.... Read more
- EPSS Score: %0.53
- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-2283
WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device.... Read more
- EPSS Score: %0.22
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2272
Untrusted search path vulnerability in Self-extracting encrypted files created by AttacheCase ver.3.2.2.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : attachecase- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2267
Untrusted search path vulnerability in FileCapsule Deluxe Portable Ver.1.0.5.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : filecapsule_deluxe_portable- EPSS Score: %0.14
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025