Latest CVE Feed
-
3.8
LOWCVE-2017-4896
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16000
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.php.... Read more
Affected Products : eyesofnetwork- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15881
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.... Read more
Affected Products : keystone- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15787
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15780
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285dad."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15772
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15750
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15748
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADIMAGE+0x000000000000613a."... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15730
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.... Read more
Affected Products : phpmyfaq- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1569
IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779.... Read more
Affected Products : websphere_commerce- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
6.7
MEDIUMCVE-2017-15651
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.... Read more
Affected Products : prtg_network_monitor- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9148
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.... Read more
Affected Products : service_desk_manager- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15294
The Java administration console in SAP CRM has XSS. This is SAP Security Note 2478964.... Read more
Affected Products : customer_relationship_management- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15239
IrfanView 4.44 - 32bit with PDF plugin version 4.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .pdf file, related to "Data from Faulting Address may be used as a return value starting at PDF!xmlPa... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15188
A persistent (stored) XSS vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to inject arbitrary web script or HTML via the hosts array parameter to module/admin_device/index.php.... Read more
Affected Products : eyesofnetwork- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-15207
In Kanboard before 1.0.47, by altering form data, an authenticated user can edit tasks of a private project of another user.... Read more
Affected Products : kanboard- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15081
In PHPSUGAR PHP Melody CMS 2.6.1, SQL Injection exists via the playlist parameter to playlists.php.... Read more
Affected Products : php_melody- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-3870
A vulnerability in the URL filtering feature of Cisco AsyncOS Software for Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to bypass a configured URL filter rule. Affected Products: This vulnerability affects all release... Read more
Affected Products : web_security_appliance- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-3814
A vulnerability in Cisco Firepower System Software could allow an unauthenticated, remote attacker to maliciously bypass the appliance's ability to block certain web content, aka a URL Bypass. More Information: CSCvb93980. Known Affected Releases: 5.3.0 5... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3798
A cross-site scripting (XSS) filter bypass vulnerability in the web-based management interface of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to mount XSS attacks against a user of an affected device. More Informat... Read more
Affected Products : unified_communications_manager- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025