Latest CVE Feed
-
8.8
HIGHCVE-2017-5345
SQL injection vulnerability in inc/lib/Control/Ajax/tags-ajax.control.php in GeniXCMS 0.0.8 allows remote authenticated editors to execute arbitrary SQL commands via the term parameter to the default URI.... Read more
Affected Products : genixcms- EPSS Score: %0.43
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-3817
A vulnerability in the role-based resource checking functionality of Cisco Unified Computing System (UCS) Director could allow an authenticated, remote attacker to view unauthorized information for any virtual machine in a UCS domain. More Information: CS... Read more
Affected Products : unified_computing_system_director- EPSS Score: %0.14
- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
3.8
LOWCVE-2017-4896
Airwatch Inbox for Android contains a vulnerability that may allow a rooted device to decrypt the local data used by the application. Successful exploitation of this issue may result in an unauthorized disclosure of confidential data.... Read more
- EPSS Score: %0.05
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-16000
SQL injection vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated administrators to execute arbitrary SQL commands via the graph parameter to module/capacity_per_label/index.php.... Read more
Affected Products : eyesofnetwork- EPSS Score: %0.44
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-15988
Nice PHP FAQ Script allows SQL Injection via the index.php nice_theme parameter, a different vulnerability than CVE-2008-6525.... Read more
Affected Products : nice_php_faq_script- EPSS Score: %1.41
- Published: Oct. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-15881
Cross-Site Scripting vulnerability in KeystoneJS before 4.0.0-beta.7 allows remote authenticated administrators to inject arbitrary web script or HTML via the "content brief" or "content extended" field, a different vulnerability than CVE-2017-15878.... Read more
Affected Products : keystone- EPSS Score: %0.47
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-14422
D-Link DIR-850L REV. A (with firmware through FW114WWb07_h2ab_beta1) and REV. B (with firmware through FW208WWb02) devices use the same hardcoded /etc/stunnel.key private key across different customers' installations, which allows remote attackers to defe... Read more
- EPSS Score: %0.42
- Published: Sep. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15787
XnView Classic for Windows Version 2.43 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at xnview+0x0000000000580063."... Read more
- EPSS Score: %0.36
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15780
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADImage+0x0000000000285dad."... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15772
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address may be used as a return value starting at CADImage+0x0000000000... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15759
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV near NULL starting at BabaCAD4Image!ShowPlugInOptions+0x00000000... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15750
IrfanView 4.50 - 64bit with BabaCAD4Image plugin version 1.3 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at BabaCAD4Image!ShowPlugInOptions+0... Read more
- EPSS Score: %0.10
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15748
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "User Mode Write AV starting at CADIMAGE+0x000000000000613a."... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15747
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to execute arbitrary code or cause a denial of service via a crafted .dwg file, related to a "Data Execution Prevention Violation starting at Unknown Symbol @ 0x0000700b00260112... Read more
- EPSS Score: %0.19
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15732
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/news.php.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.13
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-15730
In phpMyFAQ before 2.9.9, there is Cross-Site Request Forgery (CSRF) in admin/stat.ratings.php.... Read more
Affected Products : phpmyfaq- EPSS Score: %0.38
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1569
IBM WebSphere Commerce 7.0 and 8.0 contains an unspecified vulnerability in Marketing ESpot's that could cause a denial of service. IBM X-Force ID: 131779.... Read more
Affected Products : websphere_commerce- EPSS Score: %0.51
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
6.7
MEDIUMCVE-2017-15651
PRTG Network Monitor 17.3.33.2830 allows remote authenticated administrators to execute arbitrary code by uploading a .exe file and then proceeding in spite of the error message.... Read more
Affected Products : prtg_network_monitor- EPSS Score: %0.58
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9148
Cross-site scripting (XSS) vulnerability in CA Service Desk Manager (formerly CA Service Desk) 12.9 and 14.1 allows remote attackers to inject arbitrary web script or HTML via the QBE.EQ.REF_NUM parameter.... Read more
Affected Products : service_desk_manager- EPSS Score: %0.63
- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15297
SAP Hostcontrol does not require authentication for the SOAP SAPControl endpoint. This is SAP Security Note 2442993.... Read more
Affected Products : host_agent- EPSS Score: %2.63
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025