Latest CVE Feed
-
6.1
MEDIUMCVE-2017-9419
Cross-site scripting (XSS) vulnerability in the Webhammer WP Custom Fields Search plugin 0.3.28 for WordPress allows remote attackers to inject arbitrary JavaScript via the cs-all-0 parameter.... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9674
In SimpleCE 2.3.0, an authenticated XSS vulnerability was found on index.php/content/text/1?return_url=[XSS] exploitable as a regular or admin user.... Read more
Affected Products : simplece- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2017-9673
In SimpleCE 2.3.0, a CSRF vulnerability can be exploited to add an administrator account (via the index.php/user/new URI) or change its settings (via the index.php/user/1 URI), including its password.... Read more
Affected Products : simplece- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-9613
Stored Cross-site scripting (XSS) vulnerability in SAP SuccessFactors before b1705.1234962 allows remote authenticated users to inject arbitrary web script or HTML via the file upload functionality.... Read more
Affected Products : successfactors- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-9505
Atlassian Confluence starting with 4.3.0 before 6.2.1 did not check if a user had permission to view a page when creating a workbox notification about new comments. An attacker who can login to Confluence could receive workbox notifications, which contain... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-10395
In FlexNet Publisher versions before Luton SP1 (11.14.1.1) running FlexNet Publisher Licensing Service on Windows platform, a boundary error related to a named pipe within the FlexNet Publisher Licensing Service can be exploited to cause an out-of-bounds ... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
3.5
LOWCVE-2017-5244
Routes used to stop running Metasploit tasks (either particular ones or all tasks) allowed GET requests. Only POST requests should have been allowed, as the stop/stop_all routes change the state of the service. This could have allowed an attacker to stop ... Read more
Affected Products : metasploit- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-7732
The Avira Mobile Security app before 1.5.11 for iOS sends sensitive login information in cleartext.... Read more
Affected Products : avira_mobile_security- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-9670
An uninitialized stack variable vulnerability in load_tic_series() in set.c in gnuplot 5.2.rc1 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact when a victim opens a special... Read more
- Published: Jun. 15, 2017
- Modified: Aug. 14, 2025
-
7.5
HIGHCVE-2017-1379
IBM API Connect 5.0.0.0 could allow a remote attacker to obtain sensitive information, caused by improper handling of requests to the Developer Portal. IBM X-Force ID: 127002.... Read more
Affected Products : api_connect- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-1197
IBM BigFix Compliance (TEMA SUAv1 SCA SCM) uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 123672.... Read more
Affected Products : bigfix_security_compliance_analytics- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.3
HIGHCVE-2017-9606
Infotecs ViPNet Client and Coordinator before 4.3.2-42442 allow local users to gain privileges by placing a Trojan horse ViPNet update file in the update folder. The attack succeeds because of incorrect folder permissions in conjunction with a lack of int... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
4.3
MEDIUMCVE-2017-8555
Microsoft Edge in Microsoft Windows 10 1703 allows an attacker to trick a user into loading a page with malicious content when the Edge Content Security Policy (CSP) fails to properly validate certain specially crafted documents, aka "Microsoft Edge Secur... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
4.7
MEDIUMCVE-2017-8553
An information disclosure vulnerability exists in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, and Windows Server 2016 when the Windows kernel improperly handles objects in memory, aka "GDI In... Read more
Affected Products : windows_8.1 windows_rt_8.1 windows_server_2008 windows_server_2012 windows_server_2016- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-8552
A kernel-mode driver in Microsoft Windows XP SP3, Windows XP x64 XP2, Windows Server 2003 SP2, Windows Vista, Windows 7 SP1, Windows Server 2008 SP2 and R2 SP1, and Windows 8 allows an elevation of privilege when it fails to properly handle objects in mem... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-8551
An elevation of privilege vulnerability exists when Microsoft SharePoint software fails to properly sanitize a specially crafted requests, aka "Microsoft SharePoint XSS vulnerability".... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
5.4
MEDIUMCVE-2017-8550
A remote code execution vulnerability exists in Skype for Business when the software fails to sanitize specially crafted content, aka "Skype for Business Remote Code Execution Vulnerability".... Read more
Affected Products : office- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-8549
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Mem... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-8548
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system when Microsoft Edge improperly handles objects in memory, aka "Scripting Engine Mem... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025
-
7.6
HIGHCVE-2017-8547
Internet Explorer in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8.1 and Windows RT 8.1, and Windows Server 2012 and R2 allow an attacker to execute arbitrary code in the context of the current user when Internet Explorer improperly acces... Read more
- Published: Jun. 15, 2017
- Modified: Apr. 20, 2025