Latest CVE Feed
-
9.8
CRITICALCVE-2017-1002012
Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.... Read more
Affected Products : image-gallery-with-slideshow- EPSS Score: %10.33
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10017
Vulnerability in the PeopleSoft Enterprise PeopleTools component of Oracle PeopleSoft Products (subcomponent: Workcenter). Supported versions that are affected are 8.54 and 8.55. Easily exploitable vulnerability allows unauthenticated attacker with networ... Read more
Affected Products : peoplesoft_enterprise_peopletools- EPSS Score: %0.46
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1001001
PluXml version 5.6 is vulnerable to stored cross-site scripting vulnerability, within the article creation page, which can result in escalation of privileges.... Read more
Affected Products : pluxml- EPSS Score: %0.21
- Published: Nov. 01, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-10011
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low pr... Read more
Affected Products : flexcube_private_banking- EPSS Score: %0.12
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000372
A flaw exists in OpenBSD's implementation of the stack guard page that allows attackers to bypass it resulting in arbitrary code execution using setuid binaries such as /usr/bin/at. This affects OpenBSD 6.1 and possibly earlier versions.... Read more
- EPSS Score: %5.37
- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-1000235
I, Librarian version <=4.6 & 4.7 is vulnerable to OS Command Injection in batchimport.php resulting the web server being fully compromised.... Read more
Affected Products : i_librarian- EPSS Score: %11.63
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000153
Mahara 15.04 before 15.04.10 and 15.10 before 15.10.6 and 16.04 before 16.04.4 are vulnerable to incorrect access control after the password reset link is sent via email and then user changes default email, Mahara fails to invalidate old link.Consequently... Read more
Affected Products : mahara- EPSS Score: %0.38
- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1000114
The Datadog Plugin stores an API key to access the Datadog service in the global Jenkins configuration. While the API key is stored encrypted on disk, it was transmitted in plain text as part of the configuration form. This could result in exposure of the... Read more
Affected Products : datadog- EPSS Score: %0.03
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000072
Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations... Read more
Affected Products : gravity- EPSS Score: %0.83
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000021
LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.... Read more
Affected Products : logicaldoc- EPSS Score: %0.69
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000004
ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Soc... Read more
Affected Products : atutor- EPSS Score: %2.22
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-0894
Nextcloud Server before 11.0.3 is vulnerable to disclosure of valid share tokens for public calendars due to a logical error. Thus granting an attacker potentially access to publicly shared calendars without knowing the share token.... Read more
Affected Products : nextcloud_server- EPSS Score: %0.98
- Published: May. 08, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-0883
Nextcloud Server before 9.0.55 and 10.0.2 suffers from a permission increase on re-sharing via OCS API issue. A permission related issue within the OCS sharing API allowed an authenticated adversary to reshare shared files with an increasing permission se... Read more
Affected Products : nextcloud_server- EPSS Score: %0.09
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0697
A denial of service vulnerability in the Android media framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37239013.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0668
A information disclosure vulnerability in the Android framework. Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-22011579.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: Jul. 06, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0795
A elevation of privilege vulnerability in the MediaTek accessory detector driver. Product: Android. Versions: Android kernel. Android ID: A-36198473. References: M-ALPS03361480.... Read more
Affected Products : android- EPSS Score: %0.04
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0776
A information disclosure vulnerability in the Android media framework (n/a). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-38496660.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0756
A remote code execution vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-34621073.... Read more
Affected Products : android- EPSS Score: %0.16
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-0445
An elevation of privilege vulnerability in the HTC touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pr... Read more
- EPSS Score: %0.12
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0742
A elevation of privilege vulnerability in the MediaTek video driver. Product: Android. Versions: Android kernel. Android ID: A-36074857. References: M-ALPS03275524.... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Aug. 09, 2017
- Modified: Apr. 20, 2025