Latest CVE Feed
-
9.0
HIGHCVE-2017-17384
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.... Read more
Affected Products : ispconfig- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6223
Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerabilities in the ping functionality that could allow local authenticated users to execute arbitrary privileg... Read more
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6187
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.... Read more
Affected Products : disksavvy_enterprise- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-6005
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially allow an authorized but non-privileged local user to exe... Read more
Affected Products : maxxaudio- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.... Read more
Affected Products : posty_readymade_classifieds- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5892
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5831
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.... Read more
Affected Products : revive_adserver- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-16960
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/li... Read more
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16936
Directory Traversal vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_... Read more
- Published: Nov. 24, 2017
- Modified: Apr. 20, 2025
-
8.4
HIGHCVE-2017-5700
Insufficient protection of password storage in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows local attackers to bypass Administrator and User passwords via access to password storage.... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-16871
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: t... Read more
Affected Products : updraftplus- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16866
dayrui FineCms 5.2.0 before 2017.11.16 has Cross Site Scripting (XSS) in core/M_Controller.php via the DR_URI field.... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5622
With OxygenOS before 4.0.3, when a charger is connected to a powered-off OnePlus 3 or 3T device, the platform starts with adbd enabled. Therefore, a malicious charger or a physical attacker can open up, without authorization, an ADB session with the devic... Read more
- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5605
An incorrect implementation of "XEP-0280: Message Carbons" in multiple XMPP clients allows a remote attacker to impersonate any user, including contacts, in the vulnerable application's display. This allows for various kinds of social engineering attacks.... Read more
Affected Products : movim- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5538
The kbase_dispatch function in arm/t7xx/r5p0/mali_kbase_core_linux.c in the GPU driver on Samsung devices with M(6.0) and N(7.0) software and Exynos AP chipsets allows attackers to have unspecified impact via unknown vectors, which trigger an out-of-bound... Read more
Affected Products : samsung_mobile- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-5238
Due to a lack of bounds checking, several input configuration fields for the Eview EV-07S GPS Tracker will overflow data stored in one variable to another, overwriting the data of another field.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16241
Incorrect access control in AMAG Symmetry Door Edge Network Controllers (EN-1DBC Boot App 23611 03.60 and STD App 23603 03.60; EN-2DBC Boot App 24451 01.00 and STD App 2461 01.00) enables remote attackers to execute door controller commands (e.g., lock, u... Read more
- Published: Dec. 10, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-4994
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v263; UAA release 2.x versions prior to v2.7.4.18, 3.6.x versions prior to v3.6.12, 3.9.x versions prior to v3.9.14, and other versions prior to v4.3.0; and UAA bosh release ... Read more
Affected Products : cloud_foundry_uaa user_account_and_authentication cloud_foundry_uaa_bosh cloud_foundry_cf- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9964
In all Android releases from CAF using the Linux kernel, an integer overflow vulnerability exists in debug functionality.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15946
In the com_tag component 1.7.6 for Joomla!, a SQL injection vulnerability is located in the `tag` parameter to index.php. The request method to execute is GET.... Read more
Affected Products : tag_meta- Published: Oct. 28, 2017
- Modified: Apr. 20, 2025