Latest CVE Feed
-
4.8
MEDIUMCVE-2017-7309
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, ... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7255
XSS exists in the CMS Made Simple (CMSMS) 2.1.6 "Content-->News-->Add Article" feature via the m1_title parameter. Someone must login to conduct the attack.... Read more
Affected Products : cms_made_simple- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7315
An issue was discovered on Humax Digital HG100R 2.0.6 devices. To download the backup file it's not necessary to use credentials, and the router credentials are stored in plaintext inside the backup, aka GatewaySettings.bin.... Read more
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7271
Reflected Cross-site scripting (XSS) vulnerability in Yii Framework before 2.0.11, when development mode is used, allows remote attackers to inject arbitrary web script or HTML via crafted request data that is mishandled on the debug-mode exception screen... Read more
- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7299
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has an invalid read (of size 8) because the code to emit relocs (bfd_elf_final_link function in bfd/elflink.c) does not check the format of the input file before t... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7274
The r_pkcs7_parse_cms function in libr/util/r_pkcs7.c in radare2 1.3.0 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PE file.... Read more
Affected Products : radare2- Published: Mar. 27, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7266
Netflix Security Monkey before 0.8.0 has an Open Redirect. The logout functionality accepted the "next" parameter which then redirects to any domain irrespective of the Host header.... Read more
Affected Products : security_monkey- Published: Mar. 26, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7288
Cross-site scripting (XSS) vulnerability in Zimbra Collaboration Suite (ZCS) before 8.7.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: May. 23, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-7317
An issue was discovered on Humax Digital HG100 2.0.6 devices. The attacker can find the root credentials in the backup file, aka GatewaySettings.bin.... Read more
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025
-
7.1
HIGHCVE-2017-7282
An issue was discovered in Unitrends Enterprise Backup before 9.1.1. The function downloadFile in api/includes/restore.php blindly accepts any filename passed to /api/restore/download as valid. This allows an authenticated attacker to read any file in the... Read more
Affected Products : enterprise_backup- Published: Apr. 20, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7294
The vmw_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.6 does not validate addition of certain levels data, which allows local users to trigger an integer overflow and out-of-bounds write, and cau... Read more
Affected Products : linux_kernel- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7336
A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.... Read more
Affected Products : fortiwlm- Published: Jul. 22, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7281
An issue was discovered in Unitrends Enterprise Backup before 9.1.2. A lack of sanitization of user input in the createReportName and saveReport functions in recoveryconsole/bpl/reports.php allows for an authenticated user to create a randomly named file ... Read more
Affected Products : enterprise_backup- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-7284
An attacker that has hijacked a Unitrends Enterprise Backup (before 9.1.2) web server session can leverage api/includes/users.php to change the password of the logged in account without knowing the current password. This allows for an account takeover.... Read more
Affected Products : enterprise_backup- Published: Apr. 12, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7389
Multiple Cross-Site Scripting (XSS) were discovered in 'openeclass Release_3.5.4'. The vulnerabilities exist due to insufficient filtration of user-supplied data (meeting_id, user) passed to the 'openeclass-master/modules/tc/webconf/webconf.php' URL. An a... Read more
Affected Products : openeclass- Published: Apr. 01, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-7302
The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.28, has a swap_std_reloc_out function in bfd/aoutx.h that is vulnerable to an invalid read (of size 4) because of missing checks for relocs that could not be recognise... Read more
Affected Products : binutils- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-7310
A buffer overflow vulnerability in Import Command in SyncBreeze before 10.6, DiskSorter before 10.6, DiskBoss before 8.9, DiskPulse before 10.6, DiskSavvy before 10.6, DupScout before 10.6, and VX Search before 10.6 allows attackers to execute arbitrary c... Read more
- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-7298
In Moodle 3.2.2+, there is XSS in the Course summary filter of the "Add a new course" page, as demonstrated by a crafted attribute of an SVG element.... Read more
Affected Products : moodle- Published: Mar. 29, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-7321
setup/controllers/welcome.php in MODX Revolution 2.5.4-pl and earlier allows remote attackers to execute arbitrary PHP code via the config_key parameter to the setup/index.php?action=welcome URI.... Read more
Affected Products : modx_revolution- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7316
An issue was discovered on Humax Digital HG100R 2.0.6 devices. There is XSS on the 404 page.... Read more
- Published: Jul. 04, 2017
- Modified: Apr. 20, 2025