Latest CVE Feed
-
9.8
CRITICALCVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.... Read more
Affected Products : consumer_complaints_clone_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.... Read more
Affected Products : entrepreneur_bus_booking_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17599
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.... Read more
Affected Products : advance_online_learning_management_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17588
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.... Read more
Affected Products : imdb_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17590
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.... Read more
Affected Products : stackoverflow-clone- EPSS Score: %0.59
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17584
FS Makemytrip Clone 1.0 has SQL Injection via the show-flight-result.php fl_orig or fl_dest parameter.... Read more
Affected Products : makemytrip_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17583
FS Shutterstock Clone 1.0 has SQL Injection via the /Category keywords parameter.... Read more
Affected Products : shutterstock_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17579
FS Freelancer Clone 1.0 has SQL Injection via the profile.php u parameter.... Read more
Affected Products : freelancer_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6574
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit_member.php with the GET Parameter: filter_list.... Read more
Affected Products : mail-masta- EPSS Score: %0.73
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6535
Multiple Cross-Site Scripting (XSS) issues were discovered in webpagetest 3.0. The vulnerabilities exist due to insufficient filtration of user-supplied data (benchmark, url) passed to the webpagetest-master/www/benchmarks/trendurl.php URL. An attacker co... Read more
Affected Products : webpagetest- EPSS Score: %0.22
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17533
default.tcl in Tkabber 1.1 does not validate strings before launching the program specified by the BROWSER environment variable, which might allow remote attackers to conduct argument-injection attacks via a crafted URL. NOTE: a third party has indicated ... Read more
Affected Products : tkabber- EPSS Score: %0.70
- Published: Dec. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6488
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (visible, tab, cid) passed to the EPESI-master/modules/Utils/RecordBrowser/Filters/save_filters.php... Read more
Affected Products : epesi- EPSS Score: %0.21
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6492
SQL Injection was discovered in adm_program/modules/dates/dates_function.php in Admidio 3.2.5. The POST parameter dat_cat_id is concatenated into a SQL query without any input validation/sanitization.... Read more
Affected Products : admidio- EPSS Score: %0.47
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6443
Cross-site scripting (XSS) vulnerability in EPSON TMNet WebConfig 1.00 allows remote attackers to inject arbitrary web script or HTML via the W_AD1 parameter to Forms/oadmin_1.... Read more
Affected Products : tmnet_webconfig- EPSS Score: %2.01
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-1746
IBM Jazz for Service Management (IBM Tivoli Components 1.1.3) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 135519.... Read more
Affected Products : jazz_for_service_management- EPSS Score: %0.11
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6396
An issue was discovered in WPO-Foundation WebPageTest 3.0. The vulnerability exists due to insufficient filtration of user-supplied data passed to the "webpagetest-master/www/compare-cf.php" URL. An attacker could execute arbitrary HTML and script code in... Read more
Affected Products : webpagetest- EPSS Score: %0.22
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6367
In Cerberus FTP Server 8.0.10.1, a crafted HTTP request causes the Windows service to crash. The attack methodology involves a long Host header and an invalid Content-Length header.... Read more
- EPSS Score: %52.82
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-6344
XML External Entity (XXE) vulnerability in Grails PDF Plugin 0.6 allows remote attackers to read arbitrary files via a crafted XML document.... Read more
Affected Products : pdf_plugin- EPSS Score: %0.33
- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6264
An elevation of privilege vulnerability exists in the NVIDIA GPU driver (gm20b_clk_throt_set_cdev_state), where an out of bound memory read is used as a function pointer could lead to code execution in the kernel.This issue is rated as high because it cou... Read more
- EPSS Score: %0.40
- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6205
D-Link DGS-1510-28XMP, DGS-1510-28X, DGS-1510-52X, DGS-1510-52, DGS-1510-28P, DGS-1510-28, and DGS-1510-20 Websmart devices with firmware before 1.31.B003 allow attackers to conduct Unauthenticated Command Bypass attacks via unspecified vectors.... Read more
- EPSS Score: %2.35
- Published: Feb. 23, 2017
- Modified: Apr. 20, 2025