Latest CVE Feed
-
8.8
HIGHCVE-2017-8007
In EMC ViPR SRM, Storage M&R, VNX M&R, and M&R (Watch4Net) for SAS Solution Packs, the Webservice Gateway is affected by a directory traversal vulnerability. Attackers with knowledge of Webservice Gateway credentials could potentially exploit this vulnera... Read more
Affected Products : emc_m\&r emc_storage_monitoring_and_reporting emc_vipr_srm emc_vnx_monitoring_and_reporting- EPSS Score: %1.64
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7910
A Stack-Based Buffer Overflow issue was discovered in Digital Canal Structural Wind Analysis versions 9.1 and prior. An attacker may be able to run arbitrary code by remotely exploiting an executable to perform a denial-of-service attack.... Read more
Affected Products : wind_analysis- EPSS Score: %0.66
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7905
A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protect... Read more
Affected Products : multilin_sr_750_feeder_protection_relay_firmware multilin_sr_760_feeder_protection_relay_firmware multilin_sr_469_motor_protection_relay_firmware multilin_sr_489_generator_protection_relay_firmware multilin_sr_745_transformer_protection_relay_firmware multilin_sr_369_motor_protection_relay_firmware multilin_universal_relay_firmware multilin_urplus_d90_firmware multilin_urplus_c90_firmware multilin_urplus_b95_firmware +10 more products- EPSS Score: %0.20
- Published: Jun. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7888
Dolibarr ERP/CRM 4.0.4 stores passwords with the MD5 algorithm, which makes brute-force attacks easier.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.16
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7877
CSRF vulnerability in flatCore version 1.4.6 allows remote attackers to modify CMS configurations.... Read more
Affected Products : flatcore-cms- EPSS Score: %0.25
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7871
trollepierre/tdm before 2017-04-13 is vulnerable to a reflected XSS in tdm-master/webhook.php (challenge parameter).... Read more
Affected Products : tdm- EPSS Score: %0.24
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7720
Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password.... Read more
Affected Products : privatetunnel- EPSS Score: %0.05
- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7690
Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.... Read more
Affected Products : proxifier- EPSS Score: %0.16
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7695
Unrestricted File Upload exists in BigTree CMS before 4.2.17: if an attacker uploads an 'xxx.php[space]' file, they could bypass a safety check and execute any code.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.39
- Published: Apr. 11, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1751
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credenti... Read more
Affected Products : robotic_process_automation_with_automation_anywhere- EPSS Score: %0.25
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7623
The iwmiffr_convert_row32 function in imagew-miff.c in libimageworsener.a in ImageWorsener 1.3.0 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.... Read more
- EPSS Score: %0.24
- Published: Apr. 10, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7590
OpenIDM through 4.0.0 and 4.5.0 is vulnerable to persistent cross-site scripting (XSS) attacks within the Admin UI, as demonstrated by a crafted Managed Object Name.... Read more
Affected Products : openidm- EPSS Score: %0.27
- Published: Apr. 09, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-7563
In ARM Trusted Firmware 1.3, RO memory is always executable at AArch64 Secure EL1, allowing attackers to bypass the MT_EXECUTE_NEVER protection mechanism. This issue occurs because of inconsistency in the number of execute-never bits (one bit versus two b... Read more
- EPSS Score: %0.34
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
7.7
HIGHCVE-2017-7566
MyBB before 1.8.11 allows remote attackers to bypass an SSRF protection mechanism.... Read more
Affected Products : mybb- EPSS Score: %0.56
- Published: Apr. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-2893
An exploitable NULL pointer dereference vulnerability exists in the MQTT packet parsing functionality of Cesanta Mongoose 6.8. An MQTT SUBSCRIBE packet can cause a NULL pointer dereference leading to server crash and denial of service. An attacker needs t... Read more
Affected Products : mongoose- EPSS Score: %5.26
- Published: Nov. 07, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6771
A vulnerability in the AutoVNF automation tool of the Cisco Ultra Services Framework could allow an unauthenticated, remote attacker to acquire sensitive information. The vulnerability is due to insufficient protection of sensitive data. An attacker could... Read more
Affected Products : ultra_services_framework- EPSS Score: %0.41
- Published: Aug. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7390
A Cross-Site Scripting (XSS) was discovered in 'SocialNetwork v1.2.1'. The vulnerability exists due to insufficient filtration of user-supplied data (mail) passed to the 'SocialNetwork-andrea/app/template/pw_forgot.php' URL. An attacker could execute arbi... Read more
Affected Products : socialnetwork- EPSS Score: %0.22
- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7389
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An a... Read more
Affected Products : openeclass- EPSS Score: %0.23
- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7343
An open redirect vulnerability in Fortinet FortiPortal 4.0.0 and below allows attacker to execute unauthorized code or commands via the url parameter.... Read more
Affected Products : fortiportal- EPSS Score: %0.20
- Published: May. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.... Read more
- EPSS Score: %0.23
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025