Latest CVE Feed
-
6.1
MEDIUMCVE-2017-16815
installer.php in the Snap Creek Duplicator (WordPress Site Migration & Backup) plugin before 1.2.30 for WordPress has XSS because the values "url_new" (/wp-content/plugins/duplicator/installer/build/view.step4.php) and "logging" (wp-content/plugins/duplic... Read more
Affected Products : duplicator- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-16875
An issue was discovered in Teluu pjproject (pjlib and pjlib-util) in PJSIP before 2.7.1. The ioqueue component may issue a double key unregistration after an attacker initiates a socket connection with specific settings and sequences. Such double key unre... Read more
Affected Products : pjsip- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16782
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.... Read more
Affected Products : home-assistant- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-16789
Cross-site scripting (XSS) vulnerability in Integration Matters nJAMS 3 before 3.2.0 Hotfix 7, as used in TIBCO BusinessWorks Process Monitor through 3.0.1.3 and other products, allows remote authenticated administrators to inject arbitrary web script or ... Read more
- Published: Dec. 11, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2017-16820
The csnmp_read_table function in snmp.c in the SNMP plugin in collectd before 5.6.3 is susceptible to a double free in a certain error case, which could lead to a crash (or potentially have other impact).... Read more
Affected Products : collectd- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16784
In CMS Made Simple 2.2.2, there is Reflected XSS via the cntnt01detailtemplate parameter.... Read more
Affected Products : cms_made_simple- Published: Nov. 10, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16798
In CMS Made Simple 2.2.3.1, the is_file_acceptable function in modules/FileManager/action.upload.php only blocks file extensions that begin or end with a "php" substring, which allows remote attackers to bypass intended access restrictions or trigger XSS ... Read more
Affected Products : cms_made_simple- Published: Nov. 12, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-16794
The png_load function in lib/png.c in SWFTools 0.9.2 does not properly validate a multiplication of width and bits-per-pixel values, which allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a craft... Read more
Affected Products : swftools- Published: Nov. 12, 2017
- Modified: Apr. 20, 2025
-
10.0
CRITICALCVE-2017-16845
hw/input/ps2.c in Qemu does not validate 'rptr' and 'count' values during guest migration, leading to out-of-bounds access.... Read more
- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16796
In SWFTools 0.9.2, the png_load function in lib/png.c does not check the return value of a realloc call, which allows remote attackers to cause a denial of service (invalid write and application crash) or possibly have unspecified other impact via vectors... Read more
Affected Products : swftools- Published: Nov. 12, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16821
b3log Symphony (aka Sym) 2.2.0 has XSS in processor/AdminProcessor.java in the admin console, as demonstrated by a crafted X-Forwarded-For HTTP header that is mishandled during display of a client IP address in /admin/user/userid.... Read more
Affected Products : symphony- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16802
In the sharingGroupPopulateOrganisations function in app/webroot/js/misp.js in MISP 2.4.82, there is XSS via a crafted organisation name that is manually added.... Read more
Affected Products : misp- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-16810
Cross-site scripting (XSS) vulnerability in the All Variables tab in Octopus Deploy 3.4.0-3.13.6 (fixed in 3.13.7) allows remote attackers to inject arbitrary web script or HTML via the Variable Set Name parameter.... Read more
Affected Products : octopus_deploy- Published: Nov. 14, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-16804
In Redmine before 3.2.7 and 3.3.x before 3.3.4, the reminders function in app/models/mailer.rb does not check whether an issue is visible, which allows remote authenticated users to obtain sensitive information by reading e-mail reminder messages.... Read more
- Published: Nov. 13, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-16902
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.... Read more
- Published: Nov. 20, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-16923
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_AC15V1.0BR_V15.03.05.19_multi_TD01, Ac18 US_AC18V1.0BR_V1... Read more
- Published: Nov. 21, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-16851
Zoho ManageEngine Applications Manager 13 before build 13530 allows SQL injection via the /MyPage.do widgetid parameter.... Read more
- Published: Nov. 16, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-16818
RADOS Gateway in Ceph 12.1.0 through 12.2.1 allows remote authenticated users to cause a denial of service (assertion failure and application exit) by leveraging "full" (not necessarily admin) privileges to post an invalid profile to the admin API, relate... Read more
- Published: Dec. 20, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-16870
The UpdraftPlus plugin through 1.13.12 for WordPress has SSRF in the updraft_ajax_handler function in /wp-content/plugins/updraftplus/admin.php via an httpget subaction. NOTE: the vendor reports that this does not cross a privilege boundary... Read more
Affected Products : updraftplus- Published: Nov. 17, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-16833
Stored cross-site scripting (XSS) vulnerability in Gemirro before 0.16.0 allows attackers to inject arbitrary web script via a crafted javascript: URL in the "homepage" value of a ".gemspec" file.... Read more
Affected Products : gemirro- Published: Nov. 15, 2017
- Modified: Apr. 20, 2025