Latest CVE Feed
-
5.4
MEDIUMCVE-2017-9394
A stored cross-site scripting vulnerability in CA Identity Governance 12.6 allows remote authenticated attackers to display HTML or execute script in the context of another user.... Read more
Affected Products : identity_governance- EPSS Score: %0.18
- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-9337
The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post.... Read more
Affected Products : markdown_on_save_improved- EPSS Score: %0.21
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9333
OpenWebif 1.2.5 allows remote code execution via a URL to the CallOPKG function in the IpkgController class in plugin/controllers/ipkg.py, when the URL refers to an attacker-controlled web site with a Trojan horse package. This has security implications i... Read more
Affected Products : openwebif- EPSS Score: %0.86
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9424
IdeaBlade Breeze Breeze.Server.NET before 1.6.5 allows remote attackers to execute arbitrary code, related to use of TypeNameHandling in JSON deserialization.... Read more
Affected Products : breeze.server.net- EPSS Score: %4.73
- Published: Jun. 22, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9448
Cross-site scripting (XSS) vulnerabilities in BigTree CMS through 4.2.18 allow remote authenticated users to inject arbitrary web script or HTML via the description parameter. This issue exists in core\admin\ajax\pages\save-revision.php and core\admin\mod... Read more
Affected Products : bigtree_cms- EPSS Score: %0.14
- Published: Jun. 06, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9331
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers to inject arbitrary web script or HTML via a crafted meet... Read more
Affected Products : epesi- EPSS Score: %0.16
- Published: Jun. 01, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9340
An attacker is logged in as a normal user and can somehow make admin to delete shared folders in ownCloud Server before 10.0.2.... Read more
Affected Products : owncloud- EPSS Score: %0.32
- Published: Jul. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9350
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the openSAFETY dissector could crash or exhaust system memory. This was addressed in epan/dissectors/packet-opensafety.c by checking for a negative length.... Read more
Affected Products : wireshark- EPSS Score: %1.26
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9436
TeamPass before 2.1.27.4 is vulnerable to a SQL injection in users.queries.php.... Read more
Affected Products : teampass- EPSS Score: %0.23
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9351
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DHCP dissector could read past the end of a buffer. This was addressed in epan/dissectors/packet-bootp.c by extracting the Vendor Class Identifier more carefully.... Read more
Affected Products : wireshark- EPSS Score: %0.77
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9372
PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (buffer overflow and application crash) via a SIP pack... Read more
- EPSS Score: %3.66
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9349
In Wireshark 2.2.0 to 2.2.6 and 2.0.0 to 2.0.12, the DICOM dissector has an infinite loop. This was addressed in epan/dissectors/packet-dcm.c by validating a length value.... Read more
- EPSS Score: %0.81
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9379
Multiple CSRF issues exist in BigTree CMS through 4.2.18 - the clear parameter to core\admin\modules\dashboard\vitals-statistics\404\clear.php and the from or to parameter to core\admin\modules\dashboard\vitals-statistics\404\create-301.php.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.11
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-9463
The application Piwigo is affected by a SQL injection vulnerability in version 2.9.0 and possibly prior. This vulnerability allows remote authenticated attackers to obtain information in the context of the user used by the application to retrieve data fro... Read more
Affected Products : piwigo- EPSS Score: %0.22
- Published: Jun. 14, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-9359
The multi-part body parser in PJSIP, as used in Asterisk Open Source 13.x before 13.15.1 and 14.x before 14.4.1, Certified Asterisk 13.13 before 13.13-cert4, and other products, allows remote attackers to cause a denial of service (out-of-bounds read and ... Read more
- EPSS Score: %0.32
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9393
CA Identity Manager r12.6 to r12.6 SP8, 14.0, and 14.1 allows remote attackers to potentially identify passwords of locked accounts through an exhaustive search.... Read more
- EPSS Score: %0.42
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-9374
Memory leak in QEMU (aka Quick Emulator), when built with USB EHCI Emulation support, allows local guest OS privileged users to cause a denial of service (memory consumption) by repeatedly hot-unplugging the device.... Read more
Affected Products : qemu- EPSS Score: %0.09
- Published: Jun. 16, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9443
BigTree CMS through 4.2.18 allows remote authenticated users to conduct SQL injection attacks via a crafted tables object in manifest.json in an uploaded package. This issue exists in core\admin\modules\developer\extensions\install\process.php and core\ad... Read more
Affected Products : bigtree_cms- EPSS Score: %0.55
- Published: Jun. 05, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9363
Untrusted Java serialization in Soffid IAM console before 1.7.5 allows remote attackers to achieve arbitrary remote code execution via a crafted authentication request.... Read more
Affected Products : iam- EPSS Score: %5.47
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-9364
Unrestricted File Upload exists in BigTree CMS through 4.2.18: if an attacker uploads an 'xxx.pht' or 'xxx.phtml' file, they could bypass a safety check and execute any code.... Read more
Affected Products : bigtree_cms- EPSS Score: %0.34
- Published: Jun. 02, 2017
- Modified: Apr. 20, 2025