Latest CVE Feed
-
10.0
HIGHCVE-2015-8352
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.... Read more
Affected Products : zen_cart- EPSS Score: %38.49
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1264
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.... Read more
Affected Products : security_guardium- EPSS Score: %0.25
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12591
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.... Read more
- EPSS Score: %0.21
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-12285
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected softwa... Read more
Affected Products : prime_network_analysis_module- EPSS Score: %77.45
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12268
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insuffic... Read more
Affected Products : anyconnect_secure_mobility_client- EPSS Score: %0.07
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12257
A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insuf... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.16
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12224
A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due ... Read more
Affected Products : meeting_server- EPSS Score: %0.44
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12145
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : libquicktime- EPSS Score: %0.33
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12080
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.... Read more
Affected Products : photo_station- EPSS Score: %0.23
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12079
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.... Read more
Affected Products : photo_station- EPSS Score: %0.30
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-12077
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.... Read more
- EPSS Score: %0.47
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1195
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.15
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-11801
ChakraCore allows an attacker to execute arbitrary code in the context of the current user, due to how the ChakraCore scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2... Read more
Affected Products : chakracore- EPSS Score: %26.10
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11757
Heap-based buffer overflow in Actian Pervasive PSQL v12.10 and Zen v13 allows remote attackers to execute arbitrary code via crafted traffic to TCP port 1583. The overflow occurs after Server-Client encryption-key exchange. The issue results from an integ... Read more
- EPSS Score: %3.54
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11669
An out-of-bounds read flaw related to the assess_packet function in eapmd5pass.c:211 was found in the way eapmd5pass 1.4 handled processing of network packets. A remote attacker could potentially use this flaw to crash the eapmd5pass process under certain... Read more
Affected Products : eapmd5pass- EPSS Score: %0.65
- Published: Jul. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-11647
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to stored cross-site scripting attacks. Creating an SSID with an XSS payload results in successful exploitation.... Read more
- EPSS Score: %0.21
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-11646
NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mitigate CSRF vuln... Read more
- EPSS Score: %0.13
- Published: Jul. 28, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-11614
MEDHOST Connex contains hard-coded credentials that are used for customer database access. An attacker with knowledge of the hard-coded credentials and the ability to communicate directly with the database may be able to obtain or modify sensitive patient... Read more
Affected Products : connex- EPSS Score: %0.34
- Published: Jul. 25, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-11593
Cross-site scripting (XSS) vulnerability in the Markdown Preview Plus extension before 0.5.7 for Chrome allows remote attackers to inject arbitrary web script or HTML into some web applications via the upload and display of crafted text, markdown, or rst ... Read more
Affected Products : markdown_preview_plus- EPSS Score: %0.24
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-11587
On Cisco DDR2200 ADSL2+ Residential Gateway DDR2200B-NA-AnnexA-FCC-V00.00.03.45.4E and DDR2201v1 ADSL2+ Residential Gateway DDR2201v1-NA-AnnexA-FCC-V00.00.03.28.3 devices, there is directory traversal in the filename parameter to the /download.conf URI.... Read more
- EPSS Score: %0.72
- Published: Jul. 24, 2017
- Modified: Apr. 20, 2025