Latest CVE Feed
-
7.8
HIGHCVE-2017-15383
Nero 7.10.1.0 has an unquoted BINARY_PATH_NAME for NBService, exploitable via a Trojan horse Nero.exe file in the %PROGRAMFILES(x86)%\Nero directory.... Read more
Affected Products : nero- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16880
The dump function in Util/TemplateHelper.php in filp whoops before 2.1.13 has XSS.... Read more
Affected Products : whoops- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9885
An issue was discovered in Pivotal GemFire for PCF 1.6.x versions prior to 1.6.5 and 1.7.x versions prior to 1.7.1. The gfsh (Geode Shell) endpoint, used by operators and application developers to connect to their cluster, is unauthenticated and publicly ... Read more
Affected Products : gemfire_for_pivotal_cloud_foundry- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-9868
An issue was discovered in EMC ScaleIO versions before 2.0.1.1. A low-privileged local attacker may cause a denial-of-service by generating a kernel panic in the SCINI driver using IOCTL calls which may render the ScaleIO Data Client (SDC) server unavaila... Read more
Affected Products : scaleio- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9072
Two CalendarXP products have XSS in common parts of HTML files. CalendarXP FlatCalendarXP through 9.9.290 has XSS in iflateng.htm and nflateng.htm. CalendarXP PopCalendarXP through 9.8.308 has XSS in ipopeng.htm and npopeng.htm.... Read more
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-16957
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the iface field of an admin/diagnostic command to cgi-bin/luci, related to the zone_get_effect_devices function in /... Read more
Affected Products : tl-wvr300_firmware tl-wvr302_firmware tl-wvr450_firmware tl-wvr450l_firmware tl-wvr450g_firmware tl-wvr458_firmware tl-wvr458l_firmware tl-wvr458p_firmware tl-wvr900g_firmware tl-wvr900l_firmware +98 more products- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1490
An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.... Read more
Affected Products : jazz_reporting_service- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-12947
classes\controller\admin\modals.php in the Easy Modal plugin before 2.1.0 for WordPress has SQL injection in an untrash action with the id, ids, or modal parameter to wp-admin/admin.php, exploitable by administrators.... Read more
Affected Products : easy_modal- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12922
wchar.c in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted fpx image.... Read more
Affected Products : libfpx- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12810
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.... Read more
Affected Products : phpjabbers_newsletter_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12731
A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The appli... Read more
- Published: Sep. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1269
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744... Read more
Affected Products : security_guardium- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12582
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveil... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12650
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.... Read more
Affected Products : loginizer- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1264
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.... Read more
Affected Products : security_guardium- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12591
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-12285
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected softwa... Read more
Affected Products : prime_network_analysis_module- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12268
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insuffic... Read more
Affected Products : anyconnect_secure_mobility_client- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12224
A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due ... Read more
Affected Products : meeting_server- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1195
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera... Read more
Affected Products : curam_social_program_management- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025