Latest CVE Feed
-
8.8
HIGHCVE-2017-6803
Multiple cross-site request forgery (CSRF) vulnerabilities in the web interface in the Scheduler in SolarWinds (formerly Serv-U) FTP Voyager 16.2.0 allow remote attackers to hijack the authentication of users for requests that (1) change the admin passwor... Read more
Affected Products : ftp_voyager- Published: Mar. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-8708
Pluck CMS 4.7.2 allows remote attackers to execute arbitrary code via the blog form feature.... Read more
Affected Products : pluck- Published: Mar. 17, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-6366
Cross-site request forgery (CSRF) vulnerability in NETGEAR DGN2200 routers with firmware 10.0.0.20 through 10.0.0.50 allows remote attackers to hijack the authentication of users for requests that perform DNS lookups via the host_name parameter to dnslook... Read more
- Published: Mar. 15, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-5626
OxygenOS before version 4.0.2, on OnePlus 3 and 3T, has two hidden fastboot oem commands (4F500301 and 4F500302) that allow the attacker to lock/unlock the bootloader, disregarding the 'OEM Unlocking' checkbox, without user confirmation and without a fact... Read more
- Published: Mar. 12, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5872
The TCP/IP networking module in Unisys ClearPath MCP systems with TCP-IP-SW 57.1 before 57.152, 58.1 before 58.142, or 59.1 before 59.172, when running a TLS 1.2 service, allows remote attackers to cause a denial of service (network connectivity disruptio... Read more
Affected Products : clearpath_mcp- Published: Mar. 10, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-6432
An issue was discovered on Dahua DHI-HCVR7216A-S3 3.210.0001.10 build 2016-06-06 devices. The Dahua DVR Protocol, which operates on TCP Port 37777, is an unencrypted, binary protocol. Performing a Man-in-the-Middle attack allows both sniffing and injectio... Read more
- Published: Mar. 09, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-0533
An information disclosure vulnerability in the Qualcomm video driver could enable a local malicious application to access data outside of its permission levels. This issue is rated as Moderate because it first requires compromising a privileged process. P... Read more
- Published: Mar. 08, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9087
SQL injection vulnerability in framework/modules/filedownloads/controllers/filedownloadController.php in Exponent CMS 2.3.9 and earlier allows remote attackers to execute arbitrary SQL commands via the fileid parameter.... Read more
Affected Products : exponent_cms- Published: Mar. 07, 2017
- Modified: Apr. 20, 2025
-
6.4
MEDIUMCVE-2017-7306
Riverbed RiOS through 9.6.0 has a weak default password for the secure vault, which makes it easier for physically proximate attackers to defeat the secure-vault protection mechanism by leveraging knowledge of the password algorithm and the appliance seri... Read more
Affected Products : rios- Published: Apr. 04, 2017
- Modified: Apr. 20, 2025
-
3.3
LOWCVE-2017-2384
An issue was discovered in certain Apple products. iOS before 10.3 is affected. The issue involves mishandling of deletion within the SQLite subsystem of the "Safari" component. It allows local users to identify the web-site visits that occurred in Privat... Read more
Affected Products : iphone_os- Published: Apr. 02, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-9125
Revive Adserver before 3.2.3 suffers from session fixation, by allowing arbitrary session identifiers to be forced and, at the same time, by not invalidating the existing session upon a successful authentication. Under some circumstances, that could have ... Read more
Affected Products : revive_adserver- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-9122
go-jose before 1.0.4 suffers from multiple signatures exploitation. The go-jose library supports messages with multiple signatures. However, when validating a signed message the API did not indicate which signature was valid, which could potentially lead ... Read more
Affected Products : go-jose- Published: Mar. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2016-5760
Multiple cross-site scripting (XSS) vulnerabilities in the administrator console in Novell GroupWise before 2014 R2 Service Pack 1 Hot Patch 1 allow remote attackers to inject arbitrary web script or HTML via the (1) token parameter to gwadmin-console/ins... Read more
Affected Products : groupwise- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-6554
pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privileges via an ACT_NEWFILESENT action.... Read more
Affected Products : privilege_manager- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
8.5
HIGHCVE-2016-1713
Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated users to execute arbitrary code by uploading a crafted ... Read more
Affected Products : vtiger_crm- Published: Apr. 14, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-0564
An elevation of privilege vulnerability in the kernel ION subsystem could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Critical due to the possibility of a local permanent device c... Read more
Affected Products : linux_kernel- Published: Apr. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-6624
A vulnerability in Cisco IOS 15.5(3)M Software for Cisco CallManager Express (CME) could allow an unauthenticated, remote attacker to make unauthorized phone calls. The vulnerability is due to a configuration restriction in the toll-fraud protections comp... Read more
Affected Products : ios- Published: May. 03, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6564
On Franklin Fueling Systems TS-550 evo 2.3.0.7332 devices, the Guest user, which contains the lowest privileges, can post to the idSourceFileName parameter found within the /download directory. This ability allows for an attacker to download sensitive sys... Read more
- Published: May. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-6054
A Use of Hard-Coded Cryptographic Key issue was discovered in Hyundai Motor America Blue Link 3.9.5 and 3.9.4. The application uses a hard-coded decryption password to protect sensitive user information.... Read more
Affected Products : blue_link- Published: Apr. 26, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-3581
Vulnerability in the Automatic Service Request (ASR) component of Oracle Support Tools (subcomponent: ASR Manager). The supported version that is affected is Prior to 5.7. Easily "exploitable" vulnerability allows low privileged attacker with logon to the... Read more
Affected Products : automatic_service_request- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025