Latest CVE Feed
-
9.8
CRITICAL- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2014-3931
fastping.c in MRLG (aka Multi-Router Looking Glass) before 5.5.0 allows remote attackers to cause an arbitrary memory write and memory corruption.... Read more
Affected Products : multi-router_looking_glass- Actively Exploited
- Published: Mar. 31, 2017
- Modified: Jul. 08, 2025
-
9.8
CRITICALCVE-2008-7313
The _httpsrequest function in Snoopy allows remote attackers to execute arbitrary commands. NOTE: this issue exists dues to an incomplete fix for CVE-2008-4796.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7363
Pixie 1.0.4 allows an admin/index.php s=publish&m=module&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7362
Pixie 1.0.4 allows an admin/index.php s=publish&m=dynamic&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7361
Pixie 1.0.4 allows an admin/index.php s=publish&m=static&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7360
Pixie 1.0.4 allows an admin/index.php s=settings&x= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
6.1
MEDIUMCVE-2017-7359
Pixie 1.0.4 allows an admin/index.php s=login&m= XSS attack.... Read more
- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-7309
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted 'config_option' parameter. This is fixed in 1.3.9, ... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-7241
A cross-site scripting (XSS) vulnerability in the MantisBT Move Attachments page (move_attachments_page.php, part of admin tools) allows remote attackers to inject arbitrary code through a crafted 'type' parameter, if Content Security Protection (CSP) set... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
4.8
MEDIUMCVE-2017-6973
A cross-site scripting (XSS) vulnerability in the MantisBT Configuration Report page (adm_config_report.php) allows remote attackers to inject arbitrary code through a crafted 'action' parameter. This is fixed in 1.3.8, 2.1.2, and 2.2.2.... Read more
Affected Products : mantisbt- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
7.8
HIGHCVE-2017-2647
The KEYS subsystem in the Linux kernel before 3.18 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) via vectors involving a NULL value for a certain match field, related to the keyring_search_i... Read more
Affected Products : linux_kernel- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.9
MEDIUMCVE-2016-9319
There is Missing SSL Certificate Validation in the Trend Micro Enterprise Mobile Security Android Application before 9.7.1193, aka VRTS-398.... Read more
Affected Products : mobile_security- Published: Mar. 31, 2017
- Modified: Apr. 20, 2025
-
5.5
MEDIUMCVE-2017-7346
The vmw_gb_surface_define_ioctl function in drivers/gpu/drm/vmwgfx/vmwgfx_surface.c in the Linux kernel through 4.10.7 does not validate certain levels data, which allows local users to cause a denial of service (system hang) via a crafted ioctl call for ... Read more
Affected Products : linux_kernel- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
9.0
HIGHCVE-2017-7253
Dahua IP Camera devices 3.200.0001.6 can be exploited via these steps: 1. Use the default low-privilege credentials to list all users via a request to a certain URI. 2. Login to the IP camera with admin credentials so as to obtain full control of the targ... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
8.1
HIGHCVE-2017-6412
In Sophos Web Appliance (SWA) before 4.3.1.2, Session Fixation could occur, aka NSWA-1310.... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
6.5
MEDIUMCVE-2017-6184
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via the token parameter, aka NSWA-1303.... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
7.2
HIGHCVE-2017-6183
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's configuration utilities for adding (and detecting) Active Directory servers was vulnerable to remote command injection, aka NSWA-1314.... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
9.8
CRITICALCVE-2017-6182
In Sophos Web Appliance (SWA) before 4.3.1.2, a section of the machine's interface responsible for generating reports was vulnerable to remote command injection via functions, aka NSWA-1304.... Read more
- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025
-
7.5
HIGHCVE-2017-5185
A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service.... Read more
Affected Products : sentinel- Published: Mar. 30, 2017
- Modified: Apr. 20, 2025