Latest CVE Feed
-
9.8
CRITICALCVE-2015-4464
Kguard Digital Video Recorder 104, 108, v2 does not have any authorization or authentication between an ActiveX client and the application server.... Read more
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-5256
In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Device Name and System Description fields in the web administration console, and those fields are vulnerable to persistent cross-site script... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5177
A Stack Buffer Overflow issue was discovered in VIPA Controls WinPLC7 5.0.45.5921 and prior. A stack-based buffer overflow vulnerability has been identified, where an attacker with a specially crafted packet could overflow the fixed length buffer. This co... Read more
- Published: May. 19, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-5167
An issue was discovered in BINOM3 Universal Multifunctional Electric Power Quality Meter. Users do not have any option to change their own passwords.... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5163
An issue was discovered in Belden Hirschmann GECKO Lite Managed switch, Version 2.0.00 and prior versions. After an administrator downloads a configuration file, a copy of the configuration file, which includes hashes of user passwords, is saved to a loca... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5157
An issue was discovered in Schneider Electric homeLYnk Controller, LSS100100, all versions prior to V1.5.0. The homeLYnk controller is susceptible to a cross-site scripting attack. User inputs can be manipulated to cause execution of JavaScript code.... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-1203
The get_login_ip_config_file function in Eyou Mail System before 3.6 allows remote attackers to execute arbitrary commands via shell metacharacters in the domain parameter to admin/domain/ip_login_set/d_ip_login_get.php.... Read more
Affected Products : eyou- Published: Oct. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5154
An issue was discovered in Advantech WebAccess Version 8.1. To be able to exploit the SQL injection vulnerability, an attacker must supply malformed input to the WebAccess software. Successful attack could result in administrative access to the applicatio... Read more
Affected Products : webaccess- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5151
An issue was discovered in VideoInsight Web Client Version 6.3.5.11 and previous versions. A SQL Injection vulnerability has been identified, which may allow remote code execution.... Read more
Affected Products : video_insight_web_client- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-5144
An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication.... Read more
- Published: Feb. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3829
A vulnerability in the web-based management interface of Cisco Unified Communications Manager Switches could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web-based management interface of a... Read more
Affected Products : unified_communications_manager- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-4973
An issue was discovered in Cloud Foundry Foundation cf-release versions prior to v257; UAA release 2.x versions prior to v2.7.4.14, 3.6.x versions prior to v3.6.8, 3.9.x versions prior to v3.9.10, and other versions prior to v3.15.0; and UAA bosh release ... Read more
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2841
An exploitable command injection vulnerability exists in the web management interface used by the Foscam C1 Indoor HD Camera running application firmware 2.52.2.37. A specially crafted HTTP request can allow for a user to inject arbitrary data in the "msm... Read more
- Published: Jun. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-3821
A vulnerability in the serviceability page of Cisco Unified Communications Manager could allow an unauthenticated, remote attacker to conduct reflected cross-site scripting (XSS) attacks. More Information: CSCvc49348. Known Affected Releases: 10.5(2.14076... Read more
Affected Products : unified_communications_manager- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10225
The sunxi-debug driver in Allwinner 3.4 legacy kernel for H3, A83T and H8 devices allows local users to gain root privileges by sending "rootmydevice" to /proc/sunxi_debug/sunxi_debug.... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-10185
An issue was discovered on the D-Link DWR-932B router. A secure_mode=no line exists in /var/miniupnpd.conf.... Read more
- Published: Jan. 30, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2016-6649
EMC RecoverPoint versions before 4.4.1.1 and EMC RecoverPoint for Virtual Machines versions before 5.0 are affected by multiple command injection vulnerabilities where a malicious administrator with configuration privileges may bypass the user interface a... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-10154
The smbhash function in fs/cifs/smbencrypt.c in the Linux kernel 4.9.x before 4.9.1 interacts incorrectly with the CONFIG_VMAP_STACK option, which allows local users to cause a denial of service (system crash or memory corruption) or possibly have unspeci... Read more
Affected Products : linux_kernel- Published: Feb. 06, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-6561
illumos smbsrv NULL pointer dereference allows system crash.... Read more
Affected Products : illumos- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-6286
The "spiffy-cgi-handlers" egg would convert a nonexistent "Proxy" header to the HTTP_PROXY environment variable, which would allow attackers to direct CGI programs which use this environment variable to use an attacker-specified HTTP proxy server (also kn... Read more
Affected Products : http-client- Published: Jan. 10, 2017
- Modified: Apr. 20, 2025