Latest CVE Feed
-
5.4
MEDIUMCVE-2017-17995
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.... Read more
Affected Products : biometric_shift_employee_management_system- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-17990
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.... Read more
Affected Products : biometric_shift_employee_management_system- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17985
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.... Read more
Affected Products : muslim_matrimonial_script- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17931
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.... Read more
Affected Products : resume_clone_script- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-6883
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vuln... Read more
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17875
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.... Read more
Affected Products : jextn_faq_pro- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.... Read more
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17731
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.... Read more
Affected Products : dedecms- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2017-6706
A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1.... Read more
Affected Products : prime_collaboration_provisioning- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6685
A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More... Read more
Affected Products : ultra_services_framework_staging_server- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-6679
The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily l... Read more
Affected Products : umbrella- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17627
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.... Read more
Affected Products : readymade_video_sharing_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6646
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Order information on an affected system. The vulnerability exists because the affected software does no... Read more
Affected Products : remote_expert_manager- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.... Read more
Affected Products : event_calendar_category_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.... Read more
Affected Products : chartered_accountant_booking_script- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17586
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.... Read more
Affected Products : olx_clone- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6572
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.... Read more
Affected Products : mail-masta- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6552
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting i... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6489
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (element, state, cat, id, cid) passed to the EPESI-master/modules/Utils/Watchdog/subscribe.php URL.... Read more
Affected Products : epesi- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-17384
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.... Read more
Affected Products : ispconfig- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025