Latest CVE Feed
-
7.5
HIGHCVE-2017-15920
In Watchdog Anti-Malware 2.74.186.150 and Online Security Pro 2.74.186.150, the zam32.sys driver contains a NULL pointer dereference vulnerability that gets triggered when sending an operation to ioctl 0x80002054. This is due to the input buffer being NUL... Read more
- EPSS Score: %9.66
- Published: Oct. 30, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2006-5331
The altivec_unavailable_exception function in arch/powerpc/kernel/traps.c in the Linux kernel before 2.6.19 on 64-bit systems mishandles the case where CONFIG_ALTIVEC is defined and the CPU actually supports Altivec, but the Altivec support was not detect... Read more
Affected Products : linux_kernel- EPSS Score: %0.06
- Published: Oct. 29, 2017
- Modified: Apr. 20, 2025
-
7.4
HIGHCVE-2017-5729
Frame replay vulnerability in Wi-Fi subsystem in Intel Dual-Band and Tri-Band Wireless-AC Products allows remote attacker to replay frames via channel-based man-in-the-middle.... Read more
- EPSS Score: %0.68
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16819
A stored cross-site scripting vulnerability in the Icon Time Systems RTC-1000 v2.5.7458 and earlier time clock allows remote attackers to inject arbitrary JavaScript in the nameFirst (aka First Name) field for the employee details page (/employee.html) th... Read more
- EPSS Score: %1.09
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-4929
VMware NSX Edge (6.2.x before 6.2.9 and 6.3.x before 6.3.5) contains a moderate Cross-Site Scripting (XSS) issue which may lead to information disclosure.... Read more
Affected Products : nsx_edge- EPSS Score: %0.22
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16807
A cross-site Scripting (XSS) vulnerability in Kirby Panel before 2.3.3, 2.4.x before 2.4.2, and 2.5.x before 2.5.7 exists when displaying a specially prepared SVG document that has been uploaded as a content file.... Read more
- EPSS Score: %0.15
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-17051
An issue was discovered in the default FilterScheduler in OpenStack Nova 16.0.3. By repeatedly rebuilding an instance with new images, an authenticated user may consume untracked resources on a hypervisor host leading to a denial of service, aka doubled r... Read more
Affected Products : nova- EPSS Score: %0.84
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2017-16857
It is possible to bypass the bitbucket auto-unapprove plugin via minimal brute-force because it is relying on asynchronous events on the back-end. This allows an attacker to merge any code into unsuspecting repositories. This affects all versions of the a... Read more
Affected Products : bitbucket_auto_unapprove_plugin- EPSS Score: %0.27
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1689
IBM DOORS Next Generation (DNG/RRC) 6.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a... Read more
Affected Products : rational_doors_next_generation- EPSS Score: %0.27
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-1484
IBM WebSphere Commerce Enterprise, Professional, Express, and Developer 7.0 and 8.0 could allow an authenticated attacker to obtain information such as user personal data. IBM X-Force ID: 128622.... Read more
Affected Products : websphere_commerce- EPSS Score: %0.21
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17775
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.... Read more
Affected Products : piwigo- EPSS Score: %0.24
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-14101
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a m... Read more
Affected Products : conserus_image_repository- EPSS Score: %0.50
- Published: Dec. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-1536
IBM Support Tools for Lotus WCM (IBM WebSphere Portal 7.0, 8.0, 8.5 and 9.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leadi... Read more
Affected Products : websphere_portal- EPSS Score: %0.25
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-10896
Cross-site scripting vulnerability in Buffalo BBR-4HG and and BBR-4MG broadband routers with firmware 1.00 to 1.48 and 2.00 to 2.07 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
- EPSS Score: %0.26
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2014-3706
ovirt-engine, as used in Red Hat MRG 3, allows man-in-the-middle attackers to spoof servers by leveraging failure to verify key attributes in vdsm X.509 certificates.... Read more
Affected Products : enterprise_mrg- EPSS Score: %0.22
- Published: Oct. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9841
inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.... Read more
Affected Products : ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation leap active_iq_unified_manager cloud_backup solidfire mysql +30 more products- EPSS Score: %11.87
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12812
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.... Read more
Affected Products : phpjabbers_night_club_booking_software- EPSS Score: %0.24
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17949
Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.... Read more
Affected Products : blog- EPSS Score: %0.24
- Published: Dec. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17900
SQL injection vulnerability in fourn/index.php in Dolibarr ERP/CRM version 6.0.4 allows remote attackers to execute arbitrary SQL commands via the socid parameter.... Read more
Affected Products : dolibarr_erp\/crm- EPSS Score: %0.41
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-17888
cgi-bin/write.cgi in Anti-Web through 3.8.7, as used on NetBiter / HMS, Ouman EH-net, Alliance System WS100 --> AWU 500, Sauter ERW100F001, Carlo Gavazzi SIU-DLG, AEDILIS SMART-1, SYXTHSENSE WebBiter, ABB SREA, and ASCON DY WebServer devices, allows remot... Read more
Affected Products : antiweb- EPSS Score: %9.49
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025