Latest CVE Feed
-
5.3
MEDIUMCVE-2017-10342
Vulnerability in the Java Advanced Management Console component of Oracle Java SE (subcomponent: Server). The supported version that is affected is Java Advanced Management Console: 2.7. Easily exploitable vulnerability allows unauthenticated attacker wit... Read more
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-15783
XnView Classic for Windows Version 2.43 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .dwg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x0000000000285c... Read more
- Published: Oct. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-6942
Cross-site scripting (XSS) vulnerability in Coremail XT3.0 allows remote attackers to inject arbitrary web script or HTML via a hyperlink in a document attachment.... Read more
Affected Products : coremail_xt- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-14905
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing a specially crafted cfg80211 vendor command, a buffer over-read can occur.... Read more
Affected Products : android- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11388
SQL Injection in Trend Micro Control Manager 6.0 causes Remote Code Execution when RestfulServiceUtility.NET.dll doesn't properly validate user provided strings before constructing SQL queries. Formerly ZDI-CAN-4639 and ZDI-CAN-4638.... Read more
Affected Products : control_manager- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-11344
Global buffer overflow in networkmap in Asuswrt-Merlin firmware for ASUS devices and ASUS firmware for ASUS RT-AC5300, RT_AC1900P, RT-AC68U, RT-AC68P, RT-AC88U, RT-AC66U, RT-AC66U_B1, RT-AC58U, RT-AC56U, RT-AC55U, RT-AC52U, RT-AC51U, RT-N18U, RT-N66U, RT-... Read more
Affected Products : rt-ac5300_firmware rt_ac1900p_firmware rt-ac68u_firmware rt-ac68p_firmware rt-ac88u_firmware rt-ac66u_firmware rt-ac66u_b1_firmware rt-ac58u_firmware rt-ac56u_firmware rt-ac55u_firmware +46 more products- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-1557
Netgear WNAP320, WNDAP350, and WNDAP360 before 3.5.5.0 reveal wireless passwords and administrative usernames and passwords over SNMP.... Read more
- Published: Apr. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11167
FineCMS 2.1.0 allows remote attackers to execute arbitrary PHP code by using a URL Manager "Add Site" action to enter this code after a ', sequence in a domain name, as demonstrated by the ',phpinfo() input value.... Read more
Affected Products : finecms- Published: Jul. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11152
Directory traversal vulnerability in PixlrEditorHandler.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to write arbitrary files via the path parameter.... Read more
Affected Products : photo_station- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11135
An issue was discovered in heinekingmedia StashCat through 1.7.5 for Android, through 0.0.80w for Web, and through 0.0.86 for Desktop. The logout mechanism does not check for authorization. Therefore, an attacker only needs to know the device ID. This cau... Read more
Affected Products : heinekingmedia- Published: Aug. 01, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11116
The ExifImageFile::readDQT function in ExifImageFileRead.cpp in OpenExif 2.1.4 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted jpg file.... Read more
Affected Products : openexif- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2015-5057
Cross-site scripting (XSS) vulnerability exists in the Wordpress admin panel when the Broken Link Checker plugin before 1.10.9 is installed.... Read more
Affected Products : broken_link_checker- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-8877
ASUS RT-AC* and RT-N* devices with firmware through 3.0.0.4.380.7378 allow JSONP Information Disclosure such as the SSID.... Read more
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-9421
Cross-site scripting (XSS) vulnerability in the Users module in the Admin control panel in MyBB (aka MyBulletinBoard) before 1.8.8 and MyBB Merge System before 1.8.8 might allow remote attackers to inject arbitrary web script or HTML via unspecified vecto... Read more
- Published: Jan. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3109
An issue was discovered in Adobe Experience Manager 6.3, 6.2, 6.1, 6.0. Adobe Experience Manager has a reflected cross-site scripting vulnerability in the HtmlRendererServlet.... Read more
Affected Products : experience_manager- Published: Dec. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-10870
Memory corruption vulnerability in Rakuraku Hagaki (Rakuraku Hagaki 2018, Rakuraku Hagaki 2017, Rakuraku Hagaki 2016) and Rakuraku Hagaki Select for Ichitaro (Ichitaro 2017, Ichitaro 2016, Ichitaro 2015, Ichitaro Pro3, Ichitaro Pro2, Ichitaro Pro, Ichitar... Read more
Affected Products : easy_postcard_2016 easy_postcard_2017 easy_postcard_2018 ichitaro_2016 ichitaro_2017 ichitaro_2017_trial_version ichitaro_2018 ichitaro_government_6 ichitaro_government_7 ichitaro_government_8 +4 more products- Published: Nov. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGH- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-10669
Signature Wrapping exists in OSCI-Transport 1.2 as used in OSCI Transport Library 1.6.1 (Java) and OSCI Transport Library 1.6 (.NET). An attacker with access to unencrypted OSCI protocol messages must send crafted protocol messages with duplicate IDs.... Read more
Affected Products : osci_transport_library- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-17932
A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port ... Read more
Affected Products : allmediaserver- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17103
Fiyo CMS 2.0.7 has SQL injection in /apps/app_user/sys_user.php via $_POST[name] or $_POST[email]. This vulnerability can lead to escalation from normal user privileges to administrator privileges.... Read more
Affected Products : fiyo_cms- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025