Latest CVE Feed
-
6.1
MEDIUMCVE-2017-17955
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.... Read more
Affected Products : php_multivendor_ecommerce- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17906
PHP Scripts Mall Car Rental Script has SQL Injection via the admin/carlistedit.php carid parameter.... Read more
Affected Products : car_rental_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17905
PHP Scripts Mall Car Rental Script has CSRF via admin/sitesettings.php.... Read more
Affected Products : car_rental_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17872
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.... Read more
Affected Products : jextn_video_gallery- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2555
SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.... Read more
Affected Products : atutor- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17799
In TG Soft Vir.IT eXplorer Lite 8.5.65, the driver file (VIRAGTLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x82730068.... Read more
Affected Products : vir.it_explorer- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17779
Paid To Read Script 2.0.5 has SQL injection via the referrals.php id parameter.... Read more
Affected Products : paid_to_read_script- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17698
Zoho ManageEngine Password Manager Pro 9 before 9.4 (9400) has reflected XSS in SearchResult.ec and BulkAccessControlView.ec.... Read more
Affected Products : manageengine_password_manager_pro- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9893
XnView Classic for Windows Version 2.40 allows remote attackers to execute code via a crafted .fpx file, related to a "User Mode Write AV starting at Xfpx!gffGetFormatInfo+0x0000000000012548."... Read more
Affected Products : xnview- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9716
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the qbt1000 driver implements an alternative channel for usermode applications to talk to QSEE applications.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9829
'/cgi-bin/admin/downloadMedias.cgi' of the web service in most of the VIVOTEK Network Cameras is vulnerable, which allows remote attackers to read any file on the camera's Linux filesystem via a crafted HTTP request containing ".." sequences. This vulnera... Read more
- Published: Jun. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9730
SQL injection vulnerability in rdr.php in nuevoMailer version 6.0 and earlier allows remote attackers to execute arbitrary SQL commands via the "r" parameter.... Read more
Affected Products : nuevomailer- Published: Jun. 19, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9512
The mostActiveCommitters.do resource in Atlassian Fisheye and Crucible, before version 4.4.1 allows anonymous remote attackers to access sensitive information, for example email addresses of committers, as it lacked permission checks.... Read more
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-9661
An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to place a malicious DLL file within the s... Read more
Affected Products : scada- Published: Aug. 14, 2017
- Modified: Apr. 20, 2025
-
8.2
HIGHCVE-2017-9625
An Improper Authentication issue was discovered in Envitech EnviDAS Ultimate Versions prior to v1.0.0.5. The web application lacks proper authentication which could allow an attacker to view information and modify settings or execute code remotely.... Read more
Affected Products : envidas_ultimate- Published: Oct. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17597
Nearbuy Clone Script 3.2 has SQL Injection via the category_list.php search parameter.... Read more
Affected Products : nearbuy_clone_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17594
DomainSale PHP Script 1.0 has SQL Injection via the domain.php id parameter.... Read more
Affected Products : domainsale_php_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9557
register.ghp in EFS Software Easy Chat Server versions 2.0 to 3.1 allows remote attackers to discover passwords by sending the username parameter in conjunction with an empty password parameter, and reading the HTML source code of the response.... Read more
- Published: Jun. 12, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17587
FS Indiamart Clone 1.0 has SQL Injection via the catcompany.php token parameter, buyleads-details.php id parameter, or company/index.php c parameter.... Read more
Affected Products : indiamart_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9552
A design flaw in authentication in Synology Photo Station 6.0-2528 through 6.7.1-3419 allows local users to obtain credentials via cmdline. Synology Photo Station employs the synophoto_dsm_user program to authenticate username and password by "synophoto_d... Read more
Affected Products : photo_station- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025