Latest CVE Feed
-
9.8
CRITICALCVE-2017-17586
FS Olx Clone 1.0 has SQL Injection via the subpage.php scat parameter or the message.php pid parameter.... Read more
Affected Products : olx_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17585
FS Monster Clone 1.0 has SQL Injection via the Employer_Details.php id parameter.... Read more
Affected Products : monster_clone- EPSS Score: %2.38
- Published: Dec. 13, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6591
There is a cross-site scripting vulnerability in django-epiceditor 0.2.3 via crafted content in a form field.... Read more
Affected Products : django-epiceditor- EPSS Score: %0.30
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6572
A SQL injection issue is exploitable, with WordPress admin access, in the Mail Masta (aka mail-masta) plugin 1.0 for WordPress. This affects ./inc/lists/add_member.php with the GET Parameter: filter_list.... Read more
Affected Products : mail-masta- EPSS Score: %0.93
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-6552
Livebox 3 Sagemcom SG30_sip-fr-5.15.8.1 devices have an insufficiently large default value for the maximum IPv6 routing table size: it can be filled within minutes. An attacker can exploit this issue to render the affected system unresponsive, resulting i... Read more
- EPSS Score: %8.40
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6489
Multiple Cross-Site Scripting (XSS) issues were discovered in EPESI 1.8.1.1. The vulnerabilities exist due to insufficient filtration of user-supplied data (element, state, cat, id, cid) passed to the EPESI-master/modules/Utils/Watchdog/subscribe.php URL.... Read more
Affected Products : epesi- EPSS Score: %0.21
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-6478
paintballrefjosh/MaNGOSWebV4 before 4.0.8 is vulnerable to a reflected XSS in install/index.php (step parameter).... Read more
Affected Products : mangoswebv4- EPSS Score: %0.31
- Published: Mar. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-17469
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact via a \\.\Viragtlt DeviceIoControl request of 0x82730008, a different vulnerability than CVE-2017-16948.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.03
- Published: Dec. 08, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-17384
ISPConfig 3.x before 3.1.9 allows remote authenticated users to obtain root access by creating a crafted cron job.... Read more
Affected Products : ispconfig- EPSS Score: %0.48
- Published: Dec. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6223
Ruckus Wireless Zone Director Controller firmware releases ZD9.9.x, ZD9.10.x, ZD9.13.0.x less than 9.13.0.0.232 contain OS Command Injection vulnerabilities in the ping functionality that could allow local authenticated users to execute arbitrary privileg... Read more
- EPSS Score: %1.24
- Published: Oct. 13, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6187
Buffer overflow in the built-in web server in DiskSavvy Enterprise 9.4.18 allows remote attackers to execute arbitrary code via a long URI in a GET request.... Read more
Affected Products : disksavvy_enterprise- EPSS Score: %69.38
- Published: Feb. 22, 2017
- Modified: Apr. 20, 2025
-
7.0
HIGHCVE-2017-6005
Waves MaxxAudio, as installed on Dell laptops, adds a "WavesSysSvc" Windows service with File Version 1.1.6.0. This service has a vulnerability known as Unquoted Service Path. This could potentially allow an authorized but non-privileged local user to exe... Read more
Affected Products : maxxaudio- EPSS Score: %0.05
- Published: Jul. 26, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-17111
Posty Readymade Classifieds Script 1.0 allows an attacker to inject SQL commands via a listings.php?catid= or ads-details.php?ID= request.... Read more
Affected Products : posty_readymade_classifieds- EPSS Score: %17.71
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5925
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers... Read more
Affected Products : celeron_n2840 core_i7-6700k xeon_e3-1240_v5 core_i7-3632qm core_i7-4500u a64 athlon_ii_640_x4 e-350 fx-8120_8-core fx-8320_8-core +10 more products- EPSS Score: %0.38
- Published: Feb. 27, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5892
ASUS RT-AC* and RT-N* devices with firmware before 3.0.0.4.380.7378 allow JSONP Information Disclosure such as a network map.... Read more
- EPSS Score: %0.31
- Published: May. 10, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-5831
Session fixation vulnerability in the forgot password mechanism in Revive Adserver before 4.0.1, when setting a new password, allows remote attackers to hijack web sessions via the session ID.... Read more
Affected Products : revive_adserver- EPSS Score: %0.22
- Published: Mar. 03, 2017
- Modified: Apr. 20, 2025
-
9.1
CRITICALCVE-2017-5738
Escalation of privilege vulnerability in admin portal for Intel Unite App versions 3.1.32.12, 3.1.41.18 and 3.1.45.26 allows an attacker with network access to cause a denial of service and/or information disclosure.... Read more
Affected Products : unite- EPSS Score: %0.51
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-16960
TP-Link TL-WVR, TL-WAR, TL-ER, and TL-R devices allow remote authenticated users to execute arbitrary commands via shell metacharacters in the t_bindif field of an admin/interface command to cgi-bin/luci, related to the get_device_byif function in /usr/li... Read more
- EPSS Score: %0.86
- Published: Nov. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16952
KMPlayer 4.2.2.4 allows remote attackers to cause a denial of service via a crafted NSV file.... Read more
Affected Products : kmplayer- EPSS Score: %1.25
- Published: Nov. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16948
TG Soft Vir.IT eXplorer Lite 8.5.42 allows local users to cause a denial of service (NULL pointer dereference) or possibly have unspecified other impact via a NULL value in a 0x82730008 DeviceIoControl request to \\.\Viragtlt.... Read more
Affected Products : vir.it_explorer- EPSS Score: %0.05
- Published: Nov. 26, 2017
- Modified: Apr. 20, 2025