Latest CVE Feed
-
9.8
CRITICALCVE-2017-7905
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protect... Read more
Affected Products : multilin_sr_750_feeder_protection_relay_firmware multilin_sr_760_feeder_protection_relay_firmware multilin_sr_469_motor_protection_relay_firmware multilin_sr_489_generator_protection_relay_firmware multilin_sr_745_transformer_protection_relay_firmware multilin_sr_369_motor_protection_relay_firmware multilin_universal_relay_firmware multilin_urplus_d90_firmware multilin_urplus_c90_firmware multilin_urplus_b95_firmware +10 more products- EPSS Score: %0.20
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7888
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.16
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7877
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.... Read more
Affected Products : flatcore-cms- EPSS Score: %0.25
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7871
trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter).... Read more
Affected Products : tdm- EPSS Score: %0.24
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7720
Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password.... Read more
Affected Products : privatetunnel- EPSS Score: %0.05
- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7690
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.... Read more
Affected Products : proxifier- EPSS Score: %0.16
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7695
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.39
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1751
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7623
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.... Read more
- EPSS Score: %0.24
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7590
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.... Read more
Affected Products : openidm- EPSS Score: %0.27
- Published: Apr. 09, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-7563
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two b... Read more
- EPSS Score: %0.34
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-7566
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.... Read more
Affected Products : mybb- EPSS Score: %0.56
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2893
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker needs t... Read more
Affected Products : mongoose- EPSS Score: %5.26
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6771
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could... Read more
Affected Products : ultra_services_framework- EPSS Score: %0.41
- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7390
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbi... Read more
Affected Products : socialnetwork- EPSS Score: %0.22
- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7389
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An a... Read more
Affected Products : openeclass- EPSS Score: %0.23
- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7343
An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.... Read more
Affected Products : fortiportal- EPSS Score: %0.20
- Published: May. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.... Read more
- EPSS Score: %0.23
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7314
An issue was discovered in Personify360 e-Business 7.5.2 through 7.6.1. When going to the /TabId/275 URI, while creating a new role, a list of database tables and their columns is available.... Read more
Affected Products : personify360_e-business- EPSS Score: %8.85
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7320
setup/controllers/language.php in MODX Revolution 2.5.4-pl and earlier does not properly constrain the language parameter, which allows remote attackers to conduct Cookie-Bombing attacks and cause a denial of service (cookie quota exhaustion), or conduct ... Read more
Affected Products : modx_revolution- EPSS Score: %0.31
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025