Latest CVE Feed
-
8.8
HIGHCVE-2017-17990
Biometric Shift Employee Management System has CSRF via index.php in an edit_holiday action.... Read more
Affected Products : biometric_shift_employee_management_system- EPSS Score: %0.13
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-17985
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.... Read more
Affected Products : muslim_matrimonial_script- EPSS Score: %0.22
- Published: Dec. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17931
PHP Scripts Mall Resume Clone Script has SQL Injection via the forget.php username parameter.... Read more
Affected Products : resume_clone_script- EPSS Score: %0.25
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17907
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.... Read more
Affected Products : car_rental_script- EPSS Score: %0.24
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-6883
The ConvertToPDF plugin in Foxit Reader before 8.2.1 and PhantomPDF before 8.2.1 on Windows, when the gflags app is enabled, allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted TIFF image. The vuln... Read more
- EPSS Score: %0.11
- Published: Mar. 14, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17875
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.... Read more
Affected Products : jextn_faq_pro- EPSS Score: %1.41
- Published: Dec. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-17737
The BrightSign Digital Signage (4k242) device (Firmware 6.2.63 and below) has XSS via the REF parameter to /network_diagnostics.html or /storage_info.html.... Read more
- EPSS Score: %0.34
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17731
DedeCMS through 5.7 has SQL Injection via the $_FILES superglobal to plus/recommend.php.... Read more
Affected Products : dedecms- EPSS Score: %86.44
- Published: Dec. 18, 2017
- Modified: Apr. 20, 2025
-
5.1
MEDIUMCVE-2017-6706
A vulnerability in the logging subsystem of the Cisco Prime Collaboration Provisioning tool could allow an unauthenticated, local attacker to acquire sensitive information. More Information: CSCvd07260. Known Affected Releases: 12.1.... Read more
Affected Products : prime_collaboration_provisioning- EPSS Score: %0.07
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-6690
A vulnerability in the file check operation of Cisco ASR 5000 Series Aggregated Services Routers running the Cisco StarOS operating system could allow an authenticated, remote attacker to overwrite or modify arbitrary files on an affected system. More Inf... Read more
- EPSS Score: %0.16
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6685
A vulnerability in Cisco Ultra Services Framework Staging Server could allow an authenticated, remote attacker with access to the management network to log in as an admin user of the affected device, aka an Insecure Default Credentials Vulnerability. More... Read more
Affected Products : ultra_services_framework_staging_server- EPSS Score: %0.77
- Published: Jun. 13, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-6679
The Cisco Umbrella Virtual Appliance Version 2.0.3 and prior contained an undocumented encrypted remote support tunnel (SSH) which auto initiated from the customer's appliance to Cisco's SSH Hubs in the Umbrella datacenters. These tunnels were primarily l... Read more
Affected Products : umbrella- EPSS Score: %0.10
- Published: Dec. 01, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17640
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.... Read more
Affected Products : advanced_world_database- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17627
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.... Read more
Affected Products : readymade_video_sharing_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6646
A vulnerability in the web interface of Cisco Remote Expert Manager Software 11.0.0 could allow an unauthenticated, remote attacker to access sensitive Order information on an affected system. The vulnerability exists because the affected software does no... Read more
Affected Products : remote_expert_manager- EPSS Score: %0.37
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6636
A vulnerability in the web interface of Cisco Prime Collaboration Provisioning Software (prior to Release 11.1) could allow an authenticated, remote attacker to view any file on an affected system. The vulnerability exists because the affected software do... Read more
Affected Products : prime_collaboration_provisioning- EPSS Score: %3.77
- Published: May. 22, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17617
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.... Read more
Affected Products : foodspotting_clone_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17616
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.... Read more
Affected Products : event_calendar_category_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17609
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.... Read more
Affected Products : chartered_accountant_booking_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17596
Entrepreneur Job Portal Script 2.0.6 has SQL Injection via the jobsearch_all.php rid1 parameter.... Read more
Affected Products : entrepreneur_job_portal_script- EPSS Score: %2.51
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025