Latest CVE Feed
-
5.4
MEDIUMCVE-2017-17989
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.... Read more
Affected Products : biometric_shift_employee_management_system- EPSS Score: %0.21
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17986
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.... Read more
Affected Products : muslim_matrimonial_script- EPSS Score: %0.22
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17958
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.... Read more
Affected Products : php_multivendor_ecommerce- EPSS Score: %0.24
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17956
PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.... Read more
Affected Products : php_multivendor_ecommerce- EPSS Score: %0.24
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-17924
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.... Read more
Affected Products : professional_service_script- EPSS Score: %0.25
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6956
On the Broadcom Wi-Fi HardMAC SoC with fbt firmware, a stack buffer overflow occurs when handling an 802.11r (FT) authentication response, leading to remote code execution via a crafted access point that sends a long R0KH-ID field in a Fast BSS Transition... Read more
- EPSS Score: %0.43
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6813
A service provided by Zimbra Collaboration Suite (ZCS) before 8.7.6 fails to require needed privileges before performing a few requested operations.... Read more
- EPSS Score: %1.74
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6782
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of paramet... Read more
Affected Products : prime_infrastructure- EPSS Score: %0.24
- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17744
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.... Read more
Affected Products : custom_map- EPSS Score: %0.21
- Published: Dec. 19, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17701
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025c8 DeviceIoControl request.... Read more
Affected Products : antivirus- EPSS Score: %0.35
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-0494
An information disclosure vulnerability in AOSP Messaging could enable a remote attacker using a special crafted file to access data outside of its permission levels. This issue is rated as Moderate because it could be used to access sensitive data withou... Read more
Affected Products : android- EPSS Score: %0.20
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17695
Techno - Portfolio Management Panel through 2017-11-16 allows SQL Injection via the panel/search.php s parameter.... Read more
Affected Products : techno_-_portfolio_management_panel- EPSS Score: %0.23
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17633
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.... Read more
Affected Products : multiplex_movie_theater_booking_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6623
A vulnerability in a script file that is installed as part of the Cisco Policy Suite (CPS) Software distribution for the CPS appliance could allow an authenticated, local attacker to escalate their privilege level to root. The vulnerability is due to inco... Read more
- EPSS Score: %0.03
- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17619
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.... Read more
Affected Products : laundry_booking_script- EPSS Score: %4.15
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17605
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.... Read more
Affected Products : consumer_complaints_clone_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17604
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.... Read more
Affected Products : entrepreneur_bus_booking_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17599
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.... Read more
Affected Products : advance_online_learning_management_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17588
FS IMDB Clone 1.0 has SQL Injection via the movie.php f parameter, tvshow.php s parameter, or show_misc_video.php id parameter.... Read more
Affected Products : imdb_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17590
FS Stackoverflow Clone 1.0 has SQL Injection via the /question keywords parameter.... Read more
Affected Products : stackoverflow-clone- EPSS Score: %0.59
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025