Latest CVE Feed
-
6.1
MEDIUMCVE-2017-2118
Cross-site scripting vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wbce_cms- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-2098
Directory traversal vulnerability in CubeCart versions prior to 6.1.4 allows remote authenticated attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : cubecart- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-1889
Integer overflow in the bhyve hypervisor in FreeBSD 10.1, 10.2, 10.3, and 11.0 when configured with a large amount of guest memory, allows local users to gain privilege via a crafted device descriptor.... Read more
Affected Products : freebsd- Published: Feb. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2111
HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM... Read more
Affected Products : ts-ptcam\/poe_firmware ts-ptcam_firmware ts-wrlc_firmware ts-wlc2_firmware ts-wlce_firmware ts-wptcam2_firmware ts-wptcam_firmware ts-ptcam\/poe ts-ptcam ts-wrlc +4 more products- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.6
HIGHCVE-2017-2119
Directory traversal vulnerability in WBCE CMS 1.1.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : wbce_cms- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-2146
Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.2.4 allows remote attackers to inject arbitrary web script or HTML via application menu.... Read more
Affected Products : garoon- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2095
Cybozu Garoon 3.0.0 to 4.2.3 allows remote authenticated attackers to bypass access restriction in the mail function leading to an alteration of the order of mail folders via unspecified vectors.... Read more
Affected Products : garoon- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.9
MEDIUMCVE-2017-2117
Directory traversal vulnerability in CubeCart versions prior to 6.1.5 allows attacker with administrator rights to read arbitrary files via unspecified vectors.... Read more
Affected Products : cubecart- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-2115
Cybozu Office 10.0.0 to 10.5.0 allows remote authenticated attackers to bypass access restriction to obtain "customapp" information via unspecified vectors.... Read more
Affected Products : office- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2133
SQL injection vulnerability in Panasonic KX-HJB1000 Home unit devices with firmware GHX1YG 14.50 or HJB1000_4.47 allows authenticated attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
- Published: Oct. 20, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2016-2148
Heap-based buffer overflow in the DHCP client (udhcpc) in BusyBox before 1.25.0 allows remote attackers to have unspecified impact via vectors involving OPTION_6RD parsing.... Read more
- Published: Feb. 09, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-2100
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.1 and earlier allows remote attackers to conduct DNS rebinding attacks via unspecified vectors.... Read more
Affected Products : appgoat- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2122
Cross-site scripting vulnerability in Nessus versions 6.8.0, 6.8.1, 6.9.0, 6.9.1 and 6.9.2 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : nessus- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-2096
smalruby-editor v0.4.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : smalruby-editor- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-2127
Cross-site scripting vulnerability in YOP Poll versions prior to 5.8.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : yop_poll- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2016-2225
The __read_etc_hosts_r function in libc/inet/resolv.c in uClibc-ng before 1.0.12 allows remote DNS servers to cause a denial of service (infinite loop) via a crafted packet.... Read more
Affected Products : uclibc-ng- Published: Mar. 24, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2017-2103
The LaLa Call App for Android 2.4.7 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : lala_call- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2123
Cross-site scripting vulnerability in OneThird CMS v1.73 Heaven's Door and earlier allows remote attackers to inject arbitrary web script or HTML via language.php.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-2318
GraphicsMagick 1.3.23 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted SVG file, related to the (1) DrawImage function in magick/render.c, (2) SVGStartElement function in coders/svg.c, and (3) TraceArcPath func... Read more
- Published: Feb. 03, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-2120
SQL injection vulnerability in the WBCE CMS 1.1.10 and earlier allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : wbce_cms- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025