Latest CVE Feed
-
7.5
HIGHCVE-2016-1502
NetApp SnapCenter Server 1.0 and 1.0P1 allows remote attackers to partially bypass authentication and then list and delete backups via unspecified vectors.... Read more
Affected Products : snapcenter_server- EPSS Score: %0.13
- Published: Feb. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-2880
IBM QRadar 7.2 stores the encryption key used to encrypt the service account password which can be obtained by a local user. IBM Reference #: 1997340.... Read more
Affected Products : qradar_security_information_and_event_manager- EPSS Score: %0.02
- Published: Mar. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6558
iball Baton 150M iB-WRA150N v1 00000001 1.2.6 build 110401 Rel.47776n devices are prone to an authentication bypass vulnerability that allows remote attackers to view and modify administrative router settings by reading the HTML source code of the passwor... Read more
- EPSS Score: %34.77
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6758
An elevation of privilege vulnerability in Qualcomm media codecs could enable a local malicious application to execute arbitrary code within the context of a privileged process. This issue is rated as High because it could be used to gain local access to ... Read more
- EPSS Score: %0.15
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-10104
Information Disclosure can occur in sshProfiles.jsd in Hitek Software's Automize because of the Read attribute being set for Users. This allows an attacker to recover encrypted passwords for SSH/SFTP profiles. Verified in all 10.x versions up to and inclu... Read more
Affected Products : automize- EPSS Score: %0.27
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-4010
Magento CE and EE before 2.0.6 allows remote attackers to conduct PHP objection injection attacks and execute arbitrary PHP code via crafted serialized shopping cart data.... Read more
Affected Products : magento- EPSS Score: %86.18
- Published: Jan. 23, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1002002
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/... Read more
Affected Products : webapp-builder- EPSS Score: %51.16
- Published: Sep. 14, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2015-3637
SQL injection vulnerability in phpMyBackupPro when run in multi-user mode before 2.5 allows remote attackers to execute arbitrary SQL commands via the username and password parameters.... Read more
Affected Products : phpmybackuppro- EPSS Score: %0.85
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16524
Web Viewer 1.0.0.193 on Samsung SRN-1670D devices suffers from an Unrestricted file upload vulnerability: 'network_ssl_upload.php' allows remote authenticated attackers to upload and execute arbitrary PHP code via a filename with a .php extension, which i... Read more
- EPSS Score: %76.72
- Published: Nov. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-16523
MitraStar GPT-2541GNAC (HGU) 1.00(VNJ0)b1 and DSL-100HN-T1 ES_113WJY0b16 devices have a zyad1234 password for the zyad1234 account, which is equivalent to root and undocumented.... Read more
- EPSS Score: %2.91
- Published: Nov. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000358
Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.... Read more
Affected Products : opendaylight- EPSS Score: %0.37
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1000075
Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the memcmp function... Read more
Affected Products : gravity- EPSS Score: %0.85
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000064
kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS... Read more
Affected Products : kitto- EPSS Score: %0.40
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
9.0
CRITICALCVE-2017-17055
Artica Web Proxy before 3.06.112911 allows remote attackers to execute arbitrary code as root by conducting a cross-site scripting (XSS) attack involving the username-form-id parameter to freeradius.users.php.... Read more
Affected Products : artica_proxy- EPSS Score: %4.57
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-3254
The client libraries in Apache Thrift before 0.9.3 might allow remote authenticated users to cause a denial of service (infinite recursion) via vectors involving the skip function.... Read more
Affected Products : thrift- EPSS Score: %2.69
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15998
In the "NQ Contacts Backup & Restore" application 1.1 for Android, DES encryption with a static key is used to secure transmitted contact data. This makes it easier for remote attackers to obtain cleartext information by sniffing the network.... Read more
Affected Products : contacts_backup_\&_restore- EPSS Score: %0.08
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0805
A elevation of privilege vulnerability in the Android media framework (libstagefright). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2. Android ID: A-37237701.... Read more
Affected Products : android- EPSS Score: %0.09
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-0802
A elevation of privilege vulnerability in the MediaTek kernel. Product: Android. Versions: Android kernel. Android ID: A-36232120. References: M-ALPS03384818.... Read more
Affected Products : android- EPSS Score: %0.08
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-15878
A cross-site scripting (XSS) vulnerability exists in fields/types/markdown/MarkdownType.js in KeystoneJS before 4.0.0-beta.7 via the Contact Us feature.... Read more
Affected Products : keystone- EPSS Score: %3.60
- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-5695
Designate 2015.1.0 through 1.0.0.0b1 as packaged in OpenStack Kilo does not enforce RecordSets per domain, and Records per RecordSet quotas when processing an internal zone file transfer, which might allow remote attackers to cause a denial of service (in... Read more
Affected Products : designate- EPSS Score: %2.43
- Published: Aug. 31, 2017
- Modified: Apr. 20, 2025