Latest CVE Feed
-
7.2
HIGHCVE-2017-8206
HONOR 7 Lite mobile phones with software of versions earlier than NEM-L21C432B352 have an App Lock bypass vulnerability. An attacker could perform specific operations to bypass the App Lock to use apps on a target mobile phone temporarily.... Read more
- EPSS Score: %0.02
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-8163
AR120-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C30,AR1200 with software V200R006C10, V200R006C13, V200R007C00, V200R007C01, V200R007C02, V200R008C20, V200R008C30,AR1200-S with software V200R006C10, V200R007C00, V200R008C20, V200R008C... Read more
Affected Products : ar1200_firmware ar200_firmware ar3200_firmware ar120-s_firmware ar1200-s_firmware ar150_firmware ar150-s_firmware ar160_firmware ar200-s_firmware ar2200_firmware +24 more products- EPSS Score: %0.18
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-8115
Directory traversal in setup/processors/url_search.php (aka the search page of an unused processor) in MODX Revolution 2.5.7 might allow remote attackers to obtain system directory information.... Read more
Affected Products : modx_revolution- EPSS Score: %0.14
- Published: Apr. 25, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8075
On the TP-Link TL-SG108E 1.0, a remote attacker could retrieve credentials from "Switch Info" log lines where passwords are in cleartext. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.... Read more
- EPSS Score: %1.90
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8045
In Pivotal Spring AMQP versions prior to 1.7.4, 1.6.11, and 1.5.7, an org.springframework.amqp.core.Message may be unsafely deserialized when being converted into a string. A malicious payload could be crafted to exploit this and enable a remote code exec... Read more
Affected Products : spring_advanced_message_queuing_protocol- EPSS Score: %2.83
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8004
The EMC RSA Identity Governance and Lifecycle, RSA Via Lifecycle and Governance and RSA IMG products (RSA Identity Governance and Lifecycle versions 7.0.1, 7.0.2, all patch levels; RSA Via Lifecycle and Governance version 7.0, all patch levels; RSA Identi... Read more
- EPSS Score: %0.89
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-7964
Zyxel WRE6505 devices have a default TELNET password of 1234 for the root and admin accounts, which makes it easier for remote attackers to conduct DNS hijacking attacks by reconfiguring the built-in dnshijacker process.... Read more
Affected Products : wre6505_firmware- EPSS Score: %2.71
- Published: Apr. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7896
Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 before CP 1644 has XSS.... Read more
Affected Products : interscan_messaging_security_virtual_appliance- EPSS Score: %0.35
- Published: Apr. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7721
IrfanView version 4.44 (32bit) with FPX Plugin before 4.45 has an Access Violation and crash in processing a FlashPix (.FPX) file.... Read more
- EPSS Score: %0.12
- Published: Apr. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7717
SQL injection vulnerability in the getUserUddiElements method in the ES UDDI component in SAP NetWeaver AS Java 7.4 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors, aka SAP Security Note 2356504.... Read more
- EPSS Score: %0.84
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7688
Apache OpenMeetings 1.0.0 updates user password in insecure manner.... Read more
Affected Products : openmeetings- EPSS Score: %1.11
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6652
A vulnerability in the web framework of the Cisco TelePresence IX5000 Series could allow an unauthenticated, remote attacker to access arbitrary files on an affected device. The vulnerability is due to insufficient input validation. An attacker could expl... Read more
Affected Products : telepresence_ix5000- EPSS Score: %3.01
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7504
HTTPServerILServlet.java in JMS over HTTP Invocation Layer of the JbossMQ implementation, which is enabled by default in Red Hat Jboss Application Server <= Jboss 4.X does not restrict the classes for which it performs deserialization, which allows remote... Read more
Affected Products : jboss_enterprise_application_platform- EPSS Score: %89.66
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-4721
Multiple cross-site scripting (XSS) vulnerabilities in Concrete5 5.7.3.1.... Read more
Affected Products : concrete_cms- EPSS Score: %0.22
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7341
An OS Command Injection vulnerability in Fortinet FortiWLC 6.1-2 through 6.1-5, 7.0-7 through 7.0-10, 8.0 through 8.2, and 8.3.0 through 8.3.2 file management AP script download webUI page allows an authenticated admin user to execute arbitrary system con... Read more
Affected Products : fortiwlc- EPSS Score: %2.53
- Published: Oct. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7231
pngdefry through 2017-03-22 is prone to a heap-based buffer-overflow vulnerability because it fails to properly process a specially crafted png file. This issue affects the 'process()' function of the 'pngdefry.c' source file.... Read more
Affected Products : pngdefry- EPSS Score: %0.19
- Published: Mar. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7188
Zurmo 3.1.1 Stable allows a Cross-Site Scripting (XSS) attack with a base64-encoded SCRIPT element within a data: URL in the returnUrl parameter to default/toggleCollapse.... Read more
Affected Products : zurmo_crm- EPSS Score: %0.93
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6995
An issue was discovered in certain Apple products. iOS before 10.3.2 is affected. tvOS before 10.2.1 is affected. watchOS before 3.2.2 is affected. The issue involves the "AVEVideoEncoder" component. It allows attackers to execute arbitrary code in a priv... Read more
- EPSS Score: %0.68
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-6973
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.... Read more
Affected Products : mantisbt- EPSS Score: %0.62
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-17989
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.... Read more
Affected Products : biometric_shift_employee_management_system- EPSS Score: %0.21
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025