Latest CVE Feed
-
9.8
CRITICALCVE-2017-8076
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.... Read more
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7851
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-5183
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.... Read more
- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7731
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.... Read more
Affected Products : fortiportal- Published: May. 27, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-7569
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.... Read more
Affected Products : vbulletin- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7556
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.... Read more
Affected Products : hawtio- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7456
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.... Read more
Affected Products : mxview- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7450
AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot, or force a software update at an arbitrary time.... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.... Read more
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7366
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-18001
Trustwave Secure Web Gateway (SWG) through 11.8.0.27 allows remote attackers to append an arbitrary public key to the device's SSH Authorized Keys data, and consequently obtain remote root access, via the publicKey parameter to the /sendKey URI.... Read more
Affected Products : secure_web_gateway- Published: Dec. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-17995
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.... Read more
Affected Products : biometric_shift_employee_management_system- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17990
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.... Read more
Affected Products : biometric_shift_employee_management_system- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17985
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.... Read more
Affected Products : muslim_matrimonial_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17931
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.... Read more
Affected Products : resume_clone_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-6883
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vuln... Read more
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17875
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.... Read more
Affected Products : jextn_faq_pro- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.... Read more
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17731
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.... Read more
Affected Products : dedecms- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2017-6706
A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1.... Read more
Affected Products : prime_collaboration_provisioning- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025