Latest CVE Feed
-
7.1
HIGHCVE-2017-5229
All editions of Rapid7 Metasploit prior to version 4.13.0-2017020701 contain a directory traversal vulnerability in the Meterpreter extapi Clipboard.parse_dump() function. By using a specially-crafted build of Meterpreter, it is possible to write to an ar... Read more
Affected Products : metasploit- EPSS Score: %0.30
- Published: Mar. 02, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-4995
An issue was discovered in Pivotal Spring Security 4.2.0.RELEASE through 4.2.2.RELEASE, and Spring Security 5.0.0.M1. When configured to enable default typing, Jackson contained a deserialization vulnerability that could lead to arbitrary code execution. ... Read more
Affected Products : spring_security- EPSS Score: %0.83
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10370
An issue was discovered on OnePlus devices such as the 3T. The OnePlus OTA Updater pushes the signed-OTA image over HTTP without TLS. While it does not allow for installation of arbitrary OTAs (due to the digital signature), it unnecessarily increases the... Read more
- EPSS Score: %0.22
- Published: May. 11, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-4976
EMC ESRS Policy Manager prior to 6.8 contains an undocumented account (OpenDS admin) with a default password. A remote attacker with the knowledge of the default password may login to the system and gain administrator privileges to the local LDAP director... Read more
Affected Products : esrs_policy_manager- EPSS Score: %1.31
- Published: Jul. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4959
An issue was discovered in Pivotal PCF Elastic Runtime 1.8.x versions prior to 1.8.29 and 1.9.x versions prior to 1.9.7. Pivotal Cloud Foundry deployments using the Pivotal Account application are vulnerable to a flaw which allows an authorized user to ta... Read more
Affected Products : cloud_foundry_elastic_runtime- EPSS Score: %0.53
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2016-5940
IBM Kenexa LMS on Cloud is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session... Read more
- EPSS Score: %0.23
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-5952
IBM Kenexa LCMS Premier on Cloud is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database.... Read more
Affected Products : kenexa_lcms_premier- EPSS Score: %0.54
- Published: Feb. 01, 2017
- Modified: Apr. 20, 2025
-
4.5
MEDIUMCVE-2017-4015
Clickjacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to inject arbitrary web script or HTML via HTTP response header.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.22
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
8.0
HIGHCVE-2017-4014
Session Side jacking vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote authenticated users to view, add, and remove users via modification of the HTTP request.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %0.40
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-4011
Embedding Script (XSS) in HTTP Headers vulnerability in the server in McAfee Network Data Loss Prevention (NDLP) 9.3.x allows remote attackers to get session/cookie information via modification of the HTTP request.... Read more
Affected Products : network_data_loss_prevention- EPSS Score: %10.89
- Published: May. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14760
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.php.... Read more
Affected Products : event_espresso_lite- EPSS Score: %0.52
- Published: Sep. 27, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-1468
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-force ID: 128467.... Read more
- EPSS Score: %0.06
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-1467
A network layer security vulnerability in InfoSphere Information Server 9.1, 11.3, and 11.5 can lead to privilege escalation or unauthorized access. IBM X-Force ID: 128466.... Read more
- EPSS Score: %0.56
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14554
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to a "Possible Stack Corruption starting at STDUDjVuFile!DllUnregisterServer+0x000000000000d908."... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2015-1878
Thales nShield Connect hardware models 500, 1500, 6000, 500+, 1500+, and 6000+ before 11.72 allows physically proximate attackers to sign arbitrary data with previously loaded signing keys, extract the device identification key [KNETI] and impersonate the... Read more
- EPSS Score: %0.07
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-14487
The OhMiBod Remote app for Android and iOS allows remote attackers to impersonate users by sniffing network traffic for search responses from the OhMiBod API server and then editing the username, user_id, and token fields in data/data/com.ohmibod.remote2/... Read more
Affected Products : ohmibod_remote- EPSS Score: %0.25
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2015-1835
Apache Cordova Android before 3.7.2 and 4.x before 4.0.2, when an application does not set explicit values in config.xml, allows remote attackers to modify undefined secondary configuration variables (preferences) via a crafted intent: URL.... Read more
Affected Products : cordova- EPSS Score: %0.62
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-1786
Cross-site request forgery (CSRF) vulnerability in Zend/Validator/Csrf in Zend Framework 2.3.x before 2.3.6 via null or malformed token identifiers.... Read more
Affected Products : zend_framework- EPSS Score: %0.11
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15738
IrfanView 4.50 - 64bit with CADImage plugin version 12.0.0.5 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to a "Read Access Violation starting at CADIMAGE+0x00000000003d22d8."... Read more
- EPSS Score: %0.10
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-1600
Information disclosure vulnerability in Netatmo Indoor Module firmware 100 and earlier.... Read more
- EPSS Score: %1.00
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025