Latest CVE Feed
-
7.5
HIGHCVE-2017-12817
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.... Read more
Affected Products : internet_security- EPSS Score: %0.14
- Published: Aug. 25, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-12786
Network interfaces of the cliengine and noviengine services, included in the NoviWare software distribution through NW400.2.6 and deployed on NoviSwitch devices, can be inadvertently exposed if an operator attempts to modify ACLs, because of a bug when AC... Read more
Affected Products : noviware- EPSS Score: %35.14
- Published: Aug. 22, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12737
An issue was discovered on Siemens SICAM RTUs SM-2556 COM Modules with the firmware variants ENOS00, ERAC00, ETA2, ETLS00, MODi00, and DNPi00. The integrated web server (port 80/tcp) of the affected devices could allow unauthenticated remote attackers to ... Read more
- EPSS Score: %0.30
- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12731
A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The appli... Read more
- EPSS Score: %0.28
- Published: Sep. 09, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1269
IBM Security Guardium 10.0 and 10.1 is vulnerable to SQL injection. A remote attacker could send specially-crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-force ID: 124744... Read more
Affected Products : security_guardium- EPSS Score: %0.68
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12582
Unprivileged user can access all functions in the Surveillance Station component in QNAP TS212P devices with firmware 4.2.1 build 20160601. Unprivileged user cannot login at front end but with that unprivileged user SID, all function can access at Surveil... Read more
- EPSS Score: %0.34
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-12651
Cross Site Request Forgery (CSRF) exists in the Blacklist and Whitelist IP Wizard in init.php in the Loginizer plugin before 1.3.6 for WordPress because the HTTP Referer header is not checked.... Read more
Affected Products : loginizer- EPSS Score: %0.12
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-12650
SQL Injection exists in the Loginizer plugin before 1.3.6 for WordPress via the X-Forwarded-For HTTP header.... Read more
Affected Products : loginizer- EPSS Score: %0.60
- Published: Aug. 07, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-8352
Directory traversal vulnerability in Zen Cart 1.5.4 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the act parameter to ajax.php.... Read more
Affected Products : zen_cart- EPSS Score: %38.49
- Published: Aug. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1264
IBM Security Guardium 10.0 does not prove or insufficiently proves that the actors identity is correct which can lead to exposure of resources or functionality to unintended actors. IBM X-Force ID: 124739.... Read more
Affected Products : security_guardium- EPSS Score: %0.25
- Published: Jul. 05, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-12591
ASUS DSL-N10S V2.1.16_APAC devices have reflected and stored cross site scripting, as demonstrated by the snmpSysName parameter.... Read more
- EPSS Score: %0.21
- Published: Aug. 18, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-12285
A vulnerability in the web interface of Cisco Network Analysis Module Software could allow an unauthenticated, remote attacker to delete arbitrary files from an affected system, aka Directory Traversal. The vulnerability exists because the affected softwa... Read more
Affected Products : prime_network_analysis_module- EPSS Score: %77.45
- Published: Oct. 19, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12268
A vulnerability in the Network Access Manager (NAM) of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to enable multiple network adapters, aka a Dual-Homed Interface vulnerability. The vulnerability is due to insuffic... Read more
Affected Products : anyconnect_secure_mobility_client- EPSS Score: %0.07
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-12257
A vulnerability in the web framework of Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the web interface of an affected system. The vulnerability is due to insuf... Read more
Affected Products : webex_meetings_server- EPSS Score: %0.16
- Published: Oct. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12224
A vulnerability in the ability for guest users to join meetings via a hyperlink with Cisco Meeting Server could allow an authenticated, remote attacker to enter a meeting with a hyperlink URL, even though access should be denied. The vulnerability is due ... Read more
Affected Products : meeting_server- EPSS Score: %0.44
- Published: Sep. 07, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-12145
In libquicktime 1.2.4, an allocation failure was found in the function quicktime_read_ftyp in ftyp.c, which allows attackers to cause a denial of service via a crafted file.... Read more
Affected Products : libquicktime- EPSS Score: %0.33
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-12080
An information exposure vulnerability in default HTTP configuration file in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain sensitive system information via .htaccess file.... Read more
Affected Products : photo_station- EPSS Score: %0.23
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-12079
Files or directories accessible to external parties vulnerability in picasa.php in Synology Photo Station before 6.8.1-3458 and before 6.3-2970 allows remote attackers to obtain arbitrary files via prog_id field.... Read more
Affected Products : photo_station- EPSS Score: %0.30
- Published: Dec. 04, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-12077
Uncontrolled Resource Consumption vulnerability in SYNO.Core.PortForwarding.Rules in Synology Router Manager (SRM) before 1.1.4-6509 allows remote authenticated attacker to exhaust the memory resources of the machine, causing a denial of service attack.... Read more
- EPSS Score: %0.47
- Published: Aug. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-1195
IBM Curam Social Program Management 6.0, 6.1, 6.2, and 7.0 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnera... Read more
Affected Products : curam_social_program_management- EPSS Score: %0.15
- Published: Aug. 29, 2017
- Modified: Apr. 20, 2025