Latest CVE Feed
-
5.7
MEDIUMCVE-2016-4315
Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp.... Read more
Affected Products : carbon- Published: Feb. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-3112
client/consumer/cli.py in Pulp before 2.8.3 writes consumer private keys to etc/pki/pulp/consumer/consumer-cert.pem as world-readable, which allows remote authenticated users to obtain the consumer private keys and escalate privileges by reading /etc/pki/... Read more
Affected Products : pulp- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-2161
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspeci... Read more
Affected Products : flashair- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2131
Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allow an attacker to bypass access restrictions to view the configuration menu via unspecified vectors.... Read more
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-8141
The Touch Panel (TP) driver in P10 Plus smart phones with software versions earlier than VKY-AL00C00B153 has a memory double free vulnerability. An attacker with the root privilege of the Android system tricks a user into installing a malicious applicatio... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2101
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.0 and earlier allows remote attackers to bypass authentication to perform arbitrary operations via unspecified vectors.... Read more
Affected Products : appgoat- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-8216
Warsaw Huawei Smart phones with software of versions earlier than Warsaw-AL00C00B180, versions earlier than Warsaw-TL10C01B180 have a permission control vulnerability. Due to improper authorization on specific processes, an attacker with the root privileg... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-8186
The Bastet of some Huawei mobile phones with software of earlier than MHA-AL00BC00B231 versions has a DOS vulnerability due to the lack of parameter validation. An attacker may trick a user into installing a malicious APP. The APP can modify specific para... Read more
Affected Products : mha-al00a- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-8166
Huawei mobile phones Honor V9 with the software versions before Duke-AL20C00B195 have an App Lock bypass vulnerability. An attacker could perform specific operations to bypass the App Lock to use apps on a target mobile phone.... Read more
- Published: Nov. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-8101
There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.... Read more
Affected Products : serendipity- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-8076
On the TP-Link TL-SG108E 1.0, admin network communications are RC4 encoded, even though RC4 is deprecated. This affects the 1.1.2 Build 20141017 Rel.50749 firmware.... Read more
- Published: Apr. 23, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7851
D-Link DCS-936L devices with firmware before 1.05.07 have an inadequate CSRF protection mechanism that requires the device's IP address to be a substring of the HTTP Referer header.... Read more
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-5183
Console: HTTPOnly and Secure attributes not set on cookies in Red Hat AMQ.... Read more
- Published: Sep. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7731
A weak password recovery vulnerability in Fortinet FortiPortal versions 4.0.0 and below allows attacker to carry out information disclosure via the Forgotten Password feature.... Read more
Affected Products : fortiportal- Published: May. 27, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-7569
In vBulletin before 5.3.0, remote attackers can bypass the CVE-2016-6483 patch and conduct SSRF attacks by leveraging the behavior of the PHP parse_url function, aka VBV-17037.... Read more
Affected Products : vbulletin- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7556
Hawtio versions up to and including 1.5.3 are vulnerable to CSRF vulnerability allowing remote attackers to trick the user to visit their website containing a malicious script which can be submitted to hawtio server on behalf of the user.... Read more
Affected Products : hawtio- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7456
Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.... Read more
Affected Products : mxview- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7450
AIRTAME HDMI dongle with firmware before 2.2.0 allows unauthenticated access to a big part of the management interface. It is possible to extract all information including the Wi-Fi password, reboot, or force a software update at an arbitrary time.... Read more
- Published: Apr. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7402
Pixie 1.0.4 allows remote authenticated users to upload and execute arbitrary PHP code via the POST data in an admin/index.php?s=publish&x=filemanager request for a filename with a double extension, such as a .jpg.php file with Content-Type of image/jpeg.... Read more
- Published: Apr. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7366
In all Android releases from CAF using the Linux kernel, a KGSL ioctl was not validating all of its parameters.... Read more
Affected Products : android- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025