Latest CVE Feed
-
6.1
MEDIUMCVE-2017-12413
AXIS 2100 devices 2.43 have XSS via the URI, possibly related to admin/admin.shtml.... Read more
- EPSS Score: %0.21
- Published: Aug. 04, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-8621
SQL injection vulnerability in the Store Locator plugin 2.3 through 3.11 for WordPress allows remote attackers to execute arbitrary SQL commands via the sl_custom_field parameter to sl-xml.php.... Read more
Affected Products : store_locator- EPSS Score: %2.55
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10838
Cross-site scripting vulnerability in SEO Panel prior to version 3.11.0 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : seo_panel- EPSS Score: %0.21
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12271
A vulnerability in Cisco SPA300 and SPA500 Series IP Phones could allow an unauthenticated, remote attacker to execute unwanted actions on an affected device. The vulnerability is due to a lack of cross-site request forgery (CSRF) protection. An attacker ... Read more
- EPSS Score: %0.28
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-9310
Cross-site scripting (XSS) vulnerability in the WordPress Backup to Dropbox plugin before 4.1 for WordPress.... Read more
Affected Products : wordpress_backup_to_dropbox- EPSS Score: %0.40
- Published: Jun. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2016-6783
An elevation of privilege vulnerability in the MediaTek driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High because it first requires compromising a privileged process. ... Read more
Affected Products : android- EPSS Score: %0.05
- Published: Jan. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-8903
IBM Curam Social Program Management 6.0 SP2 before EP26, 6.0.4 before 6.0.4.5iFix10 and 6.0.5 before 6.0.5.6 allows remote authenticated users to load arbitrary Java classes via unspecified vectors.... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.85
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-8731
PHPMemcachedAdmin 1.2.2 and earlier allows remote attackers to execute arbitrary PHP code via vectors related "serialized data and the last part of the concatenated filename," which creates a file in webroot.... Read more
Affected Products : phpmemcachedadmin- EPSS Score: %47.14
- Published: Mar. 23, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16796
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a denial of service (invalid write and application crash) or possibly have unspecified other impact via vectors... Read more
Affected Products : swftools- EPSS Score: %0.23
- Published: Nov. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUM- EPSS Score: %0.27
- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-0276
Cross-site request forgery (CSRF) vulnerability in Kallithea before 0.2.... Read more
Affected Products : kallithea- EPSS Score: %0.26
- Published: Sep. 21, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2015-0107
IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, ... Read more
Affected Products : maximo_asset_management maximo_for_life_sciences maximo_for_nuclear_power maximo_for_oil_and_gas maximo_for_transportation maximo_for_utilities change_and_configuration_management_database maximo_asset_management_essentials maximo_for_government tivoli_asset_management_for_it +1 more products- EPSS Score: %7.17
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2014-8492
Multiple cross-site scripting (XSS) vulnerabilities in assets/misc/fallback-page.php in the Profile Builder plugin before 2.0.3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) site_name, (2) message, or (3) site_url... Read more
Affected Products : profile_builder- EPSS Score: %0.15
- Published: Oct. 06, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2014-7857
D-Link DNS-320L firmware before 1.04b12, DNS-327L before 1.03b04 Build0119, DNR-326 1.40b03, DNS-320B 1.02b01, DNS-345 1.03b06, DNS-325 1.05b03, and DNS-322L 2.00b07 allow remote attackers to bypass authentication and log in with administrator permissions... Read more
Affected Products : dns-322l_firmware dns-325_firmware dns-345_firmware dns-320b_firmware dnr-326_firmware dns-327l_firmware dns-320l_firmware dns-320l dns-325 dns-327l +4 more products- EPSS Score: %1.48
- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2014-7851
oVirt 3.2.2 through 3.5.0 does not invalidate the restapi session after logout from the webadmin, which allows remote authenticated users with knowledge of another user's session data to gain that user's privileges by replacing their session token with th... Read more
- EPSS Score: %0.39
- Published: Oct. 16, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11161
Multiple SQL injection vulnerabilities in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allow remote attackers to execute arbitrary SQL commands via the (1) article_id parameter to label.php; or (2) type parameter to synotheme.php.... Read more
Affected Products : photo_station- EPSS Score: %0.58
- Published: Sep. 08, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-15581
In the "Diary with lock" (aka WriteDiary) application 4.72 for Android, neither HTTPS nor other encryption is used for transmitting data, despite the documentation that the product is intended for "a personal journal of ... secrets and feelings," which al... Read more
Affected Products : diary_with_lock- EPSS Score: %0.75
- Published: Oct. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11155
An information exposure vulnerability in index.php in Synology Photo Station before 6.7.3-3432 and 6.3-2967 allows remote attackers to obtain sensitive system information via unspecified vectors.... Read more
Affected Products : photo_station- EPSS Score: %35.18
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-11073
In android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, the qcacld pktlog allows mapping memory via /proc/ath_pktlog/cld to user space.... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2016-5858
In an ioctl handler in all Qualcomm products with Android for MSM, Firefox OS for MSM, or QRD Android, if a user supplies a value too large, then an out-of-bounds read occurs.... Read more
Affected Products : android- EPSS Score: %0.14
- Published: Aug. 16, 2017
- Modified: Apr. 20, 2025