Latest CVE Feed
-
9.3
HIGHCVE-2016-8430
An elevation of privilege vulnerability in the NVIDIA GPU driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device comp... Read more
- EPSS Score: %0.26
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2016-8415
An elevation of privilege vulnerability in the Qualcomm Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged pro... Read more
- EPSS Score: %0.20
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-8413
An information disclosure vulnerability in the Qualcomm camera driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. ... Read more
- EPSS Score: %0.28
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
4.4
MEDIUMCVE-2017-1339
IBM Spectrum Protect 7.1 and 8.1 (formerly Tivoli Storage Manager) Server uses weak encryption for the password. A database administrator may be able to decrypt the IBM Spectrum protect client or administrator password which can result in information disc... Read more
- EPSS Score: %0.02
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2015-0576
In all Qualcomm products with Android releases from CAF using the Linux kernel, a buffer overflow vulnerability exists in HSDPA.... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12949
lib\modules\contributors\contributor_list_table.php in the Podlove Podcast Publisher plugin 2.5.3 and earlier for WordPress has SQL injection in the orderby parameter to wp-admin/admin.php, exploitable through CSRF.... Read more
Affected Products : podlove_podcast_publisher- EPSS Score: %0.72
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-7803
SQL injection vulnerability in the Cybozu Garoon 3.0.0 to 4.2.2 allows remote authenticated attackers to execute arbitrary SQL commands via "MultiReport" function.... Read more
Affected Products : garoon- EPSS Score: %1.21
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12925
Double free vulnerability in DfFromLB in docfile.cxx in libfpx 1.3.1_p6 allows remote attackers to cause a denial of service via a crafted fpx image.... Read more
Affected Products : libfpx- EPSS Score: %0.48
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16884
Cross-site scripting (XSS) vulnerability in MistServer before 2.13 allows remote attackers to inject arbitrary web script or HTML via vectors related to failed authentication requests alerts.... Read more
Affected Products : mistserver- EPSS Score: %8.04
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12776
SQL injection vulnerability in reports.php in NexusPHP 1.5 allows remote attackers to execute arbitrary SQL commands via the delreport parameter.... Read more
Affected Products : nexusphp- EPSS Score: %0.49
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2014-9937
In TrustZone a buffer overflow vulnerability can potentially occur in a DRM routine in all Android releases from CAF using the Linux kernel.... Read more
Affected Products : android- EPSS Score: %0.06
- Published: May. 16, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2014-9941
In the Embedded File System in all Android releases from CAF using the Linux kernel, a Time-of-Check Time-of-Use Race Condition vulnerability could potentially exist.... Read more
Affected Products : android- EPSS Score: %0.03
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12623
An authorized user could upload a template which contained malicious code and accessed sensitive files via an XML External Entity (XXE) attack. The fix to properly handle XML External Entities was applied on the Apache NiFi 1.4.0 release. Users running a ... Read more
Affected Products : nifi- EPSS Score: %0.51
- Published: Oct. 10, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-1261
IBM Security Guardium 10.0 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 124736.... Read more
Affected Products : security_guardium- EPSS Score: %0.05
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-9696
The Hyper Module Management (HMM) software of Huawei Tecal E9000 Chassis V100R001C00SPC160 and earlier versions allows the operator to modify the user configuration of iMana through privilege escalation.... Read more
- EPSS Score: %0.22
- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2014-9686
The Googlemaps plugin 3.2 and earlier for Joomla! allows remote attackers with control of a sub-domain belonging to a victim domain to cause a denial of service via the 'url' parameter to plugin_googlemap3_kmlprxy.php. NOTE: this vulnerability exists bec... Read more
Affected Products : googlemaps- EPSS Score: %0.86
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12413
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.... Read more
- EPSS Score: %0.21
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-8621
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.... Read more
Affected Products : store_locator- EPSS Score: %2.55
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10838
Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : seo_panel- EPSS Score: %0.21
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12271
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker ... Read more
- EPSS Score: %0.28
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025