Latest CVE Feed
-
6.1
MEDIUMCVE-2017-10801
phpSocial (formerly phpDolphin) before 3.0.1 has XSS in the PATH_INFO to the search/tag/ URI.... Read more
Affected Products : phpsocial- Published: Jul. 19, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-7241
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) set... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-5156
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems o... Read more
Affected Products : wonderware_intouch_access_anywhere- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2014-8180
MongoDB on Red Hat Satellite 6 allows local users to bypass authentication by logging in with an empty password and delete information which can cause a Denial of Service.... Read more
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-9960
An information disclosure vulnerability exists in Schneider Electric's U.motion Builder software versions 1.2.1 and prior in which the system response to error provides more information than should be available to an unauthenticated user.... Read more
Affected Products : u.motion_builder- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9931
Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter to ajax.cgi.... Read more
- Published: Jul. 21, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9886
IrfanView version 4.44 (32bit) with FPX Plugin 4.46 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .fpx file, related to "Data from Faulting Address controls Branch Selection starting at ntdll_77df000... Read more
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9785
Csrf.cs in NancyFX Nancy before 1.4.4 and 2.x before 2.0-dangermouse has Remote Code Execution via Deserialization of JSON data in a CSRF Cookie.... Read more
Affected Products : nancy- Published: Jul. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9709
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, a privilege escalation vulnerability exists in telephony.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9613
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.... Read more
Affected Products : successfactors- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9574
The "KC Area Credit Union Mobile Banking" by K C Area Credit Union app 3.0.1 -- aka kc-area-credit-union-mobile-banking/id1097607736 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and... Read more
Affected Products : kc_area_credit_union_mobile_banking- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-9559
The MEA Financial vision-bank/id420406345 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : vision_bank- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8773
Quick Heal Internet Security 10.1.0.316, Quick Heal Total Security 10.1.0.316, and Quick Heal AntiVirus Pro 10.1.0.316 are vulnerable to Out of Bounds Write on a Heap Buffer due to improper validation of dwCompressionSize of Microsoft WIM Header WIMHEADER... Read more
- Published: May. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9510
The repository changelog resource in Atlassian Fisheye before version 4.4.1 allows remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability through the start date and end date parameters.... Read more
Affected Products : fisheye- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9442
BigTree CMS through 4.2.18 allows remote authenticated users to execute arbitrary code by uploading a crafted package containing a PHP web shell, related to extraction of a ZIP archive to filename patterns such as cache/package/xxx/yyy.php. This issue exi... Read more
Affected Products : bigtree_cms- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9295
XXE vulnerability in Hitachi Device Manager before 8.5.2-01 and Hitachi Replication Manager before 8.5.2-00 allows authenticated remote users to read arbitrary files.... Read more
Affected Products : device_manager- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9212
The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name.... Read more
Affected Products : bluetooth_stack- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9202
imagew-cmd.c:854:45 in libimageworsener.a in ImageWorsener 1.3.1 allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted image, related to imagew-api.c.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9134
An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. There is a page in the web interface that will show you the device's serial number, regardless of whether or not you have logged in. ... Read more
- Published: May. 21, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-9097
In Anti-Web through 3.8.7, as used on NetBiter FGW200 devices through 3.21.2, WS100 devices through 3.30.5, EC150 devices through 1.40.0, WS200 devices through 3.30.4, EC250 devices through 1.40.0, and other products, an LFI vulnerability allows a remote ... Read more
Affected Products : antiweb- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025