Latest CVE Feed
-
9.8
CRITICALCVE-2017-7919
An Improper Authentication issue was discovered in Newport XPS-Cx and XPS-Qx. An attacker may bypass authentication by accessing a specific uniform resource locator (URL).... Read more
- EPSS Score: %1.25
- Published: Jul. 03, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7915
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Moxa OnCell G3110-HSPA Version 1.3 build 15082117 and previous versions, OnCell G3110-HSDPA Version 1.2 Build 09123015 and previous versions, OnCell G3150-HSDPA Version 1... Read more
- EPSS Score: %0.31
- Published: May. 29, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7911
A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified, which may allow remote code execution.... Read more
Affected Products : kaa_iot_platform- EPSS Score: %7.01
- Published: May. 06, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7879
SQL Injection vulnerability in flatCore version 1.4.6 allows an attacker to read the content database.... Read more
Affected Products : flatcore-cms- EPSS Score: %0.23
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-7669
In Apache Hadoop 2.8.0, 3.0.0-alpha1, and 3.0.0-alpha2, the LinuxContainerExecutor runs docker commands as root with insufficient input validation. When the docker feature is enabled, authenticated users can run commands as root.... Read more
Affected Products : hadoop- EPSS Score: %0.30
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7643
Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.... Read more
Affected Products : proxifier- EPSS Score: %0.27
- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7442
Nitro Pro 11.0.3.173 allows remote attackers to execute arbitrary code via saveAs and launchURL calls with directory traversal sequences.... Read more
- EPSS Score: %68.98
- Published: Aug. 03, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7430
Novell iManager 2.7.x before 2.7 SP7 Patch 10 HF1 and NetIQ iManager 3.x before 3.0.3.1 have a persistent XSS vulnerability in Framework.... Read more
- EPSS Score: %0.66
- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-7424
A Path Traversal (CWE-22) vulnerability in esfadmingui in Micro Focus Enterprise Developer and Enterprise Server 2.3, 2.3 Update 1 before Hotfix 8, and 2.3 Update 2 before Hotfix 9 allows remote authenticated users to download arbitrary files from a syste... Read more
- EPSS Score: %0.34
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7421
Reflected and stored Cross-Site Scripting (XSS, CWE-79) vulnerabilities in Directory Server (aka Enterprise Server Administration web UI) and ESMAC (aka Enterprise Server Monitor and Control) in Micro Focus Enterprise Developer and Enterprise Server 2.3 a... Read more
Affected Products : enterprise_developer enterprise_server directory_server enterprise_server_monitor_and_control- EPSS Score: %0.17
- Published: Aug. 21, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-9304
Multiple buffer overflows in the Autodesk FBX-SDK before 2017.1 can allow attackers to execute arbitrary code when reading or converting malformed DFX format files.... Read more
Affected Products : fbx_software_development_kit- EPSS Score: %1.45
- Published: Jan. 25, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7361
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.... Read more
- EPSS Score: %0.23
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-7323
The (1) update and (2) package-installation features in MODX Revolution 2.5.4-pl and earlier use http://rest.modx.com by default, which allows man-in-the-middle attackers to spoof servers and trigger the execution of arbitrary code by leveraging the lack ... Read more
Affected Products : modx_revolution- EPSS Score: %1.20
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7258
HTTP Exploit in eMLi Portal in AuroMeera Technometrix Pvt. Ltd. eMLi allows an Attacker to View Restricted Information or (even more seriously) execute powerful commands on the web server which can lead to a full compromise of the system via Directory Pat... Read more
Affected Products : emli- EPSS Score: %2.68
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7243
Eclipse tinydtls 0.8.2 for Eclipse IoT allows remote attackers to cause a denial of service (DTLS peer crash) by sending a "Change cipher spec" packet without pre-handshake.... Read more
Affected Products : tinydtls- EPSS Score: %0.76
- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2016-2567
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by th... Read more
- EPSS Score: %0.08
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2016-2565
Samsung SecEmailSync on SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to read sent e-mail messages, aka SVE-2015-5081.... Read more
- EPSS Score: %0.08
- Published: Apr. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2014-3498
The user module in ansible before 1.6.6 allows remote authenticated users to execute arbitrary commands.... Read more
Affected Products : ansible- EPSS Score: %0.55
- Published: Jun. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2336
Type confusion exists in two methods of Ruby's WIN32OLE class, ole_invoke and ole_query_interface. Attacker passing different type of object than this assumed by developers can cause arbitrary code execution.... Read more
Affected Products : ruby- EPSS Score: %1.46
- Published: Jan. 06, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-6873
A vulnerability was discovered in Siemens OZW672 (all versions) and OZW772 (all versions) that could allow an attacker to read and manipulate data in TLS sessions while performing a man-in-the-middle (MITM) attack on the integrated web server on port 443/... Read more
- EPSS Score: %0.19
- Published: Aug. 08, 2017
- Modified: Apr. 20, 2025