Latest CVE Feed
-
6.5
MEDIUMCVE-2017-8098
e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.... Read more
Affected Products : e107- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7723
XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.... Read more
Affected Products : easy_wp_smtp- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-5191
An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.... Read more
Affected Products : access_manager- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-2322
A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which ar... Read more
Affected Products : northstar_controller- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2016-4313
Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.... Read more
Affected Products : extplorer- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2016-3691
Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.... Read more
Affected Products : kallithea- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2016-3114
Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access.... Read more
Affected Products : kallithea- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2016-3076
Heap-based buffer overflow in the j2k_encode_entry function in Pillow 2.5.0 through 3.1.1 allows remote attackers to cause a denial of service (memory corruption) via a crafted Jpeg2000 file.... Read more
Affected Products : pillow- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2015-7570
Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tes... Read more
Affected Products : yeager_cms- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
8.8
HIGHCVE-2015-7569
SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.... Read more
Affected Products : yeager_cms- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7568
SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.... Read more
Affected Products : yeager_cms- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2015-7247
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensiti... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
10.0
HIGHCVE-2015-7246
D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2015-7245
Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000361
DOMRpcImplementationNotAvailableException when sending Port-Status packets to OpenDaylight. Controller launches exceptions and consumes more CPU resources. Component: OpenDaylight is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3... Read more
Affected Products : opendaylight- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1000360
StreamCorruptedException and NullPointerException in OpenDaylight odl-mdsal-xsql. Controller launches exceptions in the console. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.... Read more
Affected Products : opendaylight- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-1000359
Java out of memory error and significant increase in resource consumption. Component: OpenDaylight odl-mdsal-xsql is vulnerable to this flaw. Version: The tested versions are OpenDaylight 3.3 and 4.0.... Read more
Affected Products : opendaylight- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-1000358
Controller throws an exception and does not allow user to add subsequent flow for a particular switch. Component: OpenDaylight odl-restconf feature contains this flaw. Version: OpenDaylight 4.0 is affected by this flaw.... Read more
Affected Products : opendaylight- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-1000357
Denial of Service attack when the switch rejects to receive packets from the controller. Component: This vulnerability affects OpenDaylight odl-l2switch-switch, which is the feature responsible for the OpenFlow communication. Version: OpenDaylight version... Read more
Affected Products : opendaylight- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025
-
5.3
MEDIUMCVE-2017-2340
On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers... Read more
- Published: Apr. 24, 2017
- Modified: Apr. 20, 2025