Latest CVE Feed
-
8.8
HIGHCVE-2017-11567
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to __mg_admin?save. NOTE: this issue can be leveraged to ... Read more
Affected Products : mongoose_embedded_web_server_library- EPSS Score: %0.36
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11467
OrientDB through 2.2.22 does not enforce privilege requirements during "where" or "fetchplan" or "order by" use, which allows remote attackers to execute arbitrary OS commands via a crafted request.... Read more
Affected Products : orientdb- EPSS Score: %74.86
- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11441
The WHM Upload Locale interface in cPanel before 56.0.51, 58.x before 58.0.52, 60.x before 60.0.45, 62.x before 62.0.27, 64.x before 64.0.33, and 66.x before 66.0.2 has XSS via a locale filename, aka SEC-297.... Read more
Affected Products : whm- EPSS Score: %0.29
- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1143
IBM Kenexa LCMS Premier on Cloud 9.x and 10.0 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive informat... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.14
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11381
A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can access the pre-configuration console.... Read more
Affected Products : deep_discovery_director- EPSS Score: %18.47
- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11379
Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.... Read more
Affected Products : deep_discovery_director- EPSS Score: %0.21
- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11347
Authenticated Code Execution Vulnerability in MetInfo 5.3.17 allows a remote authenticated attacker to generate a PHP script with the content of a malicious image, related to admin/include/common.inc.php and admin/app/physical/physical.php.... Read more
Affected Products : metinfo- EPSS Score: %1.49
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1128
IBM Rational DOORS Next Generation 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclo... Read more
- EPSS Score: %0.30
- Published: Feb. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11200
SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.... Read more
Affected Products : finecms- EPSS Score: %0.23
- Published: Jul. 13, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-11183
front/backup.php in GLPI before 9.1.5 allows remote authenticated administrators to delete arbitrary files via a crafted file parameter.... Read more
Affected Products : glpi- EPSS Score: %0.41
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11198
Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter.... Read more
Affected Products : finecms- EPSS Score: %0.22
- Published: Jul. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11153
Deserialization vulnerability in synophoto_csPhotoMisc.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to gain administrator privileges via a crafted serialized payload.... Read more
Affected Products : photo_station- EPSS Score: %15.08
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11128
Bolt CMS 3.2.14 allows stored XSS via text input, as demonstrated by the Title field of a New Entry.... Read more
- EPSS Score: %0.21
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-11105
The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation.... Read more
- EPSS Score: %0.56
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11090
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a buffer overread is observed in __wlan_hdd_cfg80211_set_pmksa when user space application sends PMKID of size less than WLAN_PMKID_LEN bytes.... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11041
In all Qualcomm products with Android releases from CAF using the Linux kernel, an output buffer is accessed in one thread and can be potentially freed in another.... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11015
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, currently, the value of SIR_MAC_AUTH_CHALLENGE_LENGTH is set to 128 which may result in buffer overflow since the frame parser allows challenge... Read more
Affected Products : android- EPSS Score: %0.11
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-10959
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious fil... Read more
- EPSS Score: %0.37
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10932
All versions prior to V12.17.20 of the ZTE Microwave NR8000 series products - NR8120, NR8120A, NR8120, NR8150, NR8250, NR8000 TR and NR8950 are the applications of C/S architecture using the Java RMI service in which the servers use the Apache Commons Col... Read more
Affected Products : nr8120_firmware nr8120a_firmware nr8150_firmware nr8250_firmware nr8000tr_firmware nr8950_firmware nr8120 nr8120a nr8150 nr8250 +2 more products- EPSS Score: %13.76
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-10903
Improper authentication issue in PTW-WMS1 firmware version 2.000.012 allows remote attackers to log in to the device with root privileges and conduct arbitrary operations via unspecified vectors.... Read more
- EPSS Score: %4.81
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025