Latest CVE Feed
-
9.8
CRITICALCVE-2017-8120
The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated pri... Read more
Affected Products : uma- EPSS Score: %0.22
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8103
In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.... Read more
Affected Products : mybb- EPSS Score: %0.26
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-8099
There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.... Read more
- EPSS Score: %0.18
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8098
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.... Read more
Affected Products : e107- EPSS Score: %0.17
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8052
Craft CMS before 2.6.2974 allows XSS attacks.... Read more
Affected Products : craft_cms- EPSS Score: %0.35
- Published: Apr. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8007
In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnera... Read more
Affected Products : emc_m\&r emc_storage_monitoring_and_reporting emc_vipr_srm emc_vnx_monitoring_and_reporting- EPSS Score: %1.64
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7910
A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior. An attacker may be able to run arbitrary code by remotely exploiting an executable to perform a denial-of-service attack.... Read more
Affected Products : wind_analysis- EPSS Score: %0.66
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7905
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protect... Read more
Affected Products : multilin_sr_750_feeder_protection_relay_firmware multilin_sr_760_feeder_protection_relay_firmware multilin_sr_469_motor_protection_relay_firmware multilin_sr_489_generator_protection_relay_firmware multilin_sr_745_transformer_protection_relay_firmware multilin_sr_369_motor_protection_relay_firmware multilin_universal_relay_firmware multilin_urplus_d90_firmware multilin_urplus_c90_firmware multilin_urplus_b95_firmware +10 more products- EPSS Score: %0.20
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7888
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.16
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7877
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.... Read more
Affected Products : flatcore-cms- EPSS Score: %0.25
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7871
trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter).... Read more
Affected Products : tdm- EPSS Score: %0.24
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7720
Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password.... Read more
Affected Products : privatetunnel- EPSS Score: %0.05
- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7690
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.... Read more
Affected Products : proxifier- EPSS Score: %0.16
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7695
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.39
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1751
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7623
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.... Read more
- EPSS Score: %0.24
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7590
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.... Read more
Affected Products : openidm- EPSS Score: %0.27
- Published: Apr. 09, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-7563
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two b... Read more
- EPSS Score: %0.34
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-7566
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.... Read more
Affected Products : mybb- EPSS Score: %0.56
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2893
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker needs t... Read more
Affected Products : mongoose- EPSS Score: %5.26
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025