Latest CVE Feed
-
5.5
MEDIUMCVE-2017-14971
Infocus Mondopad 2.2.08 is vulnerable to a Hashed Credential Disclosure vulnerability. The attacker provides a crafted Microsoft Office document containing a link that has a UNC pathname associated with an attacker-controller server. In one specific scena... Read more
Affected Products : infocus_mondopad- EPSS Score: %0.22
- Published: Oct. 09, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-3810
A vulnerability in the web framework of Cisco Prime Service Catalog could allow an authenticated, remote attacker to conduct a web URL redirect attack against a user who is logged in to an affected system. More Information: CSCvb21745. Known Affected Rele... Read more
Affected Products : prime_service_catalog- EPSS Score: %0.28
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-3806
A vulnerability in CLI command processing in the Cisco Firepower 4100 Series Next-Generation Firewall and Cisco Firepower 9300 Security Appliance could allow an authenticated, local attacker to inject arbitrary shell commands that are executed by the devi... Read more
- EPSS Score: %0.10
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
5.8
MEDIUMCVE-2017-3800
A vulnerability in the content scanning engine of Cisco AsyncOS Software for Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass configured message or content filters on the device. Affected Products: This vulne... Read more
Affected Products : email_security_appliance- EPSS Score: %0.21
- Published: Jan. 26, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-14918
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, in the GPS location wireless interface, a Use After Free condition can occur.... Read more
Affected Products : android- EPSS Score: %0.12
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14901
In Android for MSM, Firefox OS for MSM, QRD Android, with all Android releases from CAF using the Linux kernel, while processing the QCA_NL80211_VENDOR_SUBCMD_SET_TXPOWER_SCALE vendor command, in which attribute QCA_WLAN_VENDOR_ATTR_TXPOWER_SCALE contains... Read more
Affected Products : android- EPSS Score: %0.02
- Published: Dec. 05, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14841
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.... Read more
Affected Products : annual_maintenance_contract_management_system- EPSS Score: %1.68
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14840
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.... Read more
Affected Products : ticketplus- EPSS Score: %2.39
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14839
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.... Read more
Affected Products : photo_fusion- EPSS Score: %2.39
- Published: Sep. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-14821
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 8.3.1.21155. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malic... Read more
- EPSS Score: %0.10
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-3572
Vulnerability in the Oracle Commerce Guided Search / Oracle Commerce Experience Manager component of Oracle Commerce (subcomponent: MDEX). Supported versions that are affected are 6.2.2, 6.3.0, 6.4.1.2, 6.5.0, 6.5.1 and 6.5.2. Easily "exploitable" vulnera... Read more
- EPSS Score: %1.66
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-14771
Skybox Manager Client Application prior to 8.5.501 is prone to an arbitrary file upload vulnerability due to insufficient input validation of user-supplied files path when uploading files via the application. During a debugger-pause state, a local authent... Read more
Affected Products : skybox_manager_client_application- EPSS Score: %0.12
- Published: Oct. 03, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-14764
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.... Read more
Affected Products : genixcms- EPSS Score: %0.83
- Published: Sep. 27, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-14743
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.... Read more
- EPSS Score: %0.45
- Published: Sep. 26, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-3495
Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: Pre-Login). Supported versions that are affected are 12.0.2 and 12.0.3. Easily "exploitable" vulnerability allows unauthenticated attack... Read more
Affected Products : flexcube_direct_banking- EPSS Score: %0.52
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14693
IrfanView 4.44 - 32bit allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address controls Branch Selection starting at DJVU!GetPlugInInfo+0x000000000001c613."... Read more
Affected Products : irfanview- EPSS Score: %0.05
- Published: Sep. 22, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-14620
SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.... Read more
Affected Products : smarterstats- EPSS Score: %1.26
- Published: Sep. 30, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14541
XnView Classic for Windows Version 2.40 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .svg file, related to "Data from Faulting Address controls Branch Selection starting at CADImage+0x000000000001f2... Read more
- EPSS Score: %0.05
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14555
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .djvu file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at STDUDjV... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-14544
STDU Viewer 1.6.375 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .epub file, related to "Data from Faulting Address is used as one or more arguments in a subsequent Function Call starting at STDUEPu... Read more
Affected Products : stdu_viewer- EPSS Score: %0.05
- Published: Sep. 18, 2017
- Modified: Apr. 20, 2025