Latest CVE Feed
-
4.3
MEDIUMCVE-2017-2137
ProSAFE Plus Configuration Utility prior to 2.3.29 allows remote attackers to bypass access restriction and change configurations of the switch via SOAP requests.... Read more
Affected Products : prosafe_plus_configuration_utility- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.8
MEDIUMCVE-2017-2152
WNC01WH firmware 1.0.0.9 and earlier allows authenticated attackers to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-2142
Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2164
Cross-site scripting vulnerability in SOY CMS with installer 1.8.12 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : soy_cms- Published: May. 12, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2138
Cross-site request forgery (CSRF) vulnerability in CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to hijack the authentication of a... Read more
- Published: Aug. 02, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2191
Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2140
Tablacus Explorer 17.3.30 and earlier allows arbitrary scripts to be executed in the context of the application due to specially crafted directory.... Read more
Affected Products : tablacus_explorer- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2244
Cross-site request forgery (CSRF) vulnerability in MFC-J960DWN firmware ver.D and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.... Read more
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2150
Directory traversal vulnerability in Booking Calendar version 7.0 and earlier allows remote attackers to read arbitrary files via specially crafted captcha_chalange parameter.... Read more
Affected Products : booking_calendar- Published: Apr. 28, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2179
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allows remote code execution via unspecified vectors, a different vulnerability than CVE-2017-2181 and CVE-2017-2182.... Read more
Affected Products : appgoat- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2182
Hands-on Vulnerability Learning Tool "AppGoat" for Web Application V3.0.2 and earlier allow remote attackers to obtain local files via unspecified vectors, a different vulnerability than CVE-2017-2179 and CVE-2017-2181.... Read more
Affected Products : appgoat- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-2216
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2177
Untrusted search path vulnerability in Installer of Shogyo Touki Denshi Ninsho Software Ver 1.7 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : touki_denshi- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2208
Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.... Read more
Affected Products : installer_of_electronic_tendering- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2178
Untrusted search path vulnerability in Installer of electronic tendering and bid opening system available prior to May 25, 2017 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-2186
HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI.... Read more
- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2209
Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation)... Read more
Affected Products : installer_of_houkokusyo_sakusei_shien_tool- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2189
Untrusted search path vulnerability in RW-4040 driver installer for Windows 7 version 2.27 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : rw-4040- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2215
Untrusted search path vulnerability in Installer of "Setup file of advance preparation" (jizen_setup.exe) (The version which was available on the website prior to 2017 June 12) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified... Read more
Affected Products : e-tax- Published: Jul. 07, 2017
- Modified: Apr. 20, 2025
-
9.3
HIGHCVE-2017-2193
Untrusted search path vulnerability in the installer of Tera Term 4.94 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : tera_term- Published: Jun. 09, 2017
- Modified: Apr. 20, 2025