Latest CVE Feed
-
7.5
HIGHCVE-2017-1002007
Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.... Read more
Affected Products : dtracker- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-10007
Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent: Miscellaneous). Supported versions that are affected are 2.0.0, 2.0.1, 2.2.0 and 12.0.1. Easily exploitable vulnerability allows low pr... Read more
Affected Products : flexcube_private_banking- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000238
InvoicePlane version 1.4.10 is vulnerable to a Arbitrary File Upload resulting in an authenticated user can upload a malicious file to the webserver. It is possible for an attacker to upload a script which is able to compromise the webserver.... Read more
Affected Products : invoiceplane- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1000227
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can... Read more
Affected Products : salutation- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000237
I, Librarian version <=4.6 & 4.7 is vulnerable to Server-Side Request Forgery in the ajaxsupplement.php resulting in the attacker being able to reset any user's password.... Read more
Affected Products : i_librarian- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000163
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering attacks.... Read more
Affected Products : phoenix- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-8688
An issue was discovered in Telegram Messenger 2.6 for iOS and 1.8.2 for Android. Secret chat messages are available in cleartext in process memory and a .db file.... Read more
Affected Products : messenger- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1000110
Blue Ocean allows the creation of GitHub organization folders that are set up to scan a GitHub organization for repositories and branches containing a Jenkinsfile, and create corresponding pipelines in Jenkins. It did not properly check the current user's... Read more
Affected Products : blue_ocean- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1000069
CSRF in Bitly oauth2_proxy 2.1 during authentication flow... Read more
Affected Products : oauth2_proxy- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0643
A remote denial of service vulnerability in Mediaserver could enable an attacker to use a specially crafted file to cause a device hang or reboot. This issue is rated as High severity due to the possibility of remote denial of service. Product: Android. V... Read more
Affected Products : android- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000038
WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site... Read more
Affected Products : relevanssi- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1000006
Plotly, Inc. plotly.js versions prior to 1.16.0 are vulnerable to an XSS issue.... Read more
Affected Products : plotly.js- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-10000
Vulnerability in the Oracle Hospitality Reporting and Analytics component of Oracle Hospitality Applications (subcomponent: Reporting). Supported versions that are affected are 8.5.1 and 9.0.0. Easily exploitable vulnerability allows low privileged attack... Read more
Affected Products : hospitality_reporting_and_analytics- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-8701
Wonder CMS 2014 allows remote attackers to obtain sensitive information by viewing /files/password, which reveals the unsalted MD5 hashed password.... Read more
Affected Products : wondercms- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-0845
A denial of service vulnerability in the Android framework (syncstorageengine). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-35028827.... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0835
A remote code execution vulnerability in the Android media framework (libmpeg2). Product: Android. Versions: 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63316832.... Read more
Affected Products : android- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-0828
An elevation of privilege vulnerability in the Huawei bootloader. Product: Android. Versions: Android kernel. Android ID: A-34622855.... Read more
Affected Products : android- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-0808
An information disclosure vulnerability in the Android framework (file system). Product: Android. Versions: 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-62301183.... Read more
Affected Products : android- Published: Oct. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-0784
A elevation of privilege vulnerability in the Android system (nfc). Product: Android. Versions: 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37287958.... Read more
Affected Products : android- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-0771
A denial of service vulnerability in the Android media framework (libskia). Product: Android. Versions: 7.0, 7.1.1, 7.1.2. Android ID: A-37624243.... Read more
Affected Products : android- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025