Latest CVE Feed
-
7.1
HIGHCVE-2017-5701
Insecure platform configuration in system firmware for Intel NUC7i3BNK, NUC7i3BNH, NUC7i5BNK, NUC7i5BNH, NUC7i7BNH versions BN0049 and below allows an attacker with physical presence to run arbitrary code via unauthorized firmware modification during BIOS... Read more
- Published: Oct. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1359
IBM RELM 4.0, 5.0, and 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted sess... Read more
Affected Products : rational_engineering_lifecycle_manager- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7433
An absolute path traversal vulnerability (CWE-36) in Micro Focus Vibe 4.0.2 and earlier allows a remote authenticated attacker to download arbitrary files from the server by submitting a specially crafted request to the viewFile endpoint. Note that the at... Read more
Affected Products : vibe- Published: May. 18, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7276
There is reflected XSS in TOPdesk before 5.7.6 and 6.x and 7.x before 7.03.019.... Read more
Affected Products : topdesk- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2014-3531
Multiple cross-site scripting (XSS) vulnerabilities in Foreman before 1.5.2 allow remote authenticated users to inject arbitrary web script or HTML via the operating system (1) name or (2) description.... Read more
Affected Products : foreman- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6637
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to delete any file from an affected system. The vulnerability exists because the affected softwar... Read more
Affected Products : prime_collaboration_provisioning- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6599
A vulnerability in Google-defined remote procedure call (gRPC) handling in Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause the Event Management Service daemon (emsd) to crash due to a system memory leak, resulting in a denia... Read more
Affected Products : ios_xr- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6573
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/edit-list.php with the GET Parameter: id.... Read more
Affected Products : mail-masta- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6550
Multiple SQL injection vulnerabilities in Kinsey Infor-Lawson (formerly ESBUS) allow remote attackers to execute arbitrary SQL commands via the (1) TABLE parameter to esbus/servlet/GetSQLData or (2) QUERY parameter to KK_LS9ReportingPortal/GetData.... Read more
Affected Products : infor-lawson- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8473
An information disclosure vulnerability in the STMicroelectronics driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged proces... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6485
A Cross-Site Scripting (XSS) issue was discovered in php-calendar before 2017-03-03. The vulnerability exists due to insufficient filtration of user-supplied data (errorMsg) passed to the "php-calendar-master/error.php" URL. An attacker could execute arbi... Read more
Affected Products : php-calendar- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8394
An elevation of privilege vulnerability in the Synaptics touchscreen driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privile... Read more
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8322
Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Core). Supported versions that are affected are 5.1.0, 5.2.0 and 11.5.0. Easily exploitable vulnerability allows low privileged attacker w... Read more
Affected Products : flexcube_core_banking- Published: Jan. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6178
The IofCallDriver function in USBPcap 1.1.0.0 allows local users to gain privileges via a crafted 0x00090028 IOCTL call, which triggers a NULL pointer dereference.... Read more
Affected Products : usbpcap- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2016-8217
EMC RSA BSAFE Crypto-J versions prior to 6.2.2 has a PKCS#12 Timing Attack Vulnerability. A possible timing attack could be carried out by modifying a PKCS#12 file that has an integrity MAC for which the password is not known. An attacker could then feed ... Read more
Affected Products : bsafe_crypto-j- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-6029
A Cross-Site Scripting issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. This may allow remote code execution.... Read more
Affected Products : atvise_scada- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6018
An open redirect issue was discovered in B. Braun Medical SpaceCom module, which is integrated into the SpaceStation docking station: SpaceStation with SpaceCom module (integrated as part number 8713142U), software versions prior to Version 012U000040, an... Read more
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-1520
The Grandstream Wave app 1.0.1.26 and earlier for Android does not use HTTPS when retrieving update information, which might allow man-in-the-middle attackers to execute arbitrary code via a crafted application.... Read more
Affected Products : wave- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5995
The NetApp ONTAP Select Deploy administration utility 2.0 through 2.2.1 might allow remote attackers to obtain sensitive information via unspecified vectors.... Read more
Affected Products : ontap_select_deploy_administration_utility- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5913
The TradeKing Forex for iPhone app 1.2.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : tradeking_forex- Published: May. 05, 2017
- Modified: Apr. 20, 2025