CVE Feed

    Dashboard / CVE

    Unknown

    CVE-2017-1963

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1964

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1965

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1966

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1968

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1969

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1970

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1971

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1972

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1973

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1857

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1869

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    Unknown

    CVE-2017-1976

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 5 Jan 2018
    8.1
    High

    CVE-2017-16905

    Last Modified: 21 Nov 2024

    The DuoLingo TinyCards application before 1.0 for Android has one use of unencrypted HTTP, which allows remote attackers to spoof content, and consequently achieve remote code execution, via a man-in-the-middle attack.

    Published: 5 Jan 2018
    9.8
    Critical

    CVE-2017-16716

    Last Modified: 21 Nov 2024

    A SQL Injection issue was discovered in WebAccess versions prior to 8.3. WebAccess does not properly sanitize its inputs for SQL commands.

    Published: 5 Jan 2018
    9.8
    Critical

    CVE-2017-16720

    Last Modified: 21 Nov 2024

    A Path Traversal issue was discovered in WebAccess versions 8.3.2 and earlier. An attacker has access to files within the directory structure of the target device.

    Published: 5 Jan 2018
    9.8
    Critical

    CVE-2017-16724

    Last Modified: 21 Nov 2024

    A Stack-based Buffer Overflow issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple instances of a vulnerability that allows too much data to be written to a location on the stack.

    Published: 5 Jan 2018
    7.5
    High

    CVE-2017-16753

    Last Modified: 21 Nov 2024

    An Improper Input Validation issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows some inputs that may cause the program to crash.

    Published: 5 Jan 2018
    7.5
    High

    CVE-2017-16728

    Last Modified: 21 Nov 2024

    An Untrusted Pointer Dereference issue was discovered in Advantech WebAccess versions prior to 8.3. There are multiple vulnerabilities that may allow an attacker to cause the program to use an invalid memory address, resulting in a program crash.

    Published: 5 Jan 2018
    5.5
    Medium

    CVE-2017-15111

    Last Modified: 21 Nov 2024

    keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.

    Published: 5 Jan 2018
    7.8
    High

    CVE-2017-15112

    Last Modified: 21 Nov 2024

    keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.

    Published: 5 Jan 2018
    Unknown

    CVE-2017-17005

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17006

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17007

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17009

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-16999

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17000

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17001

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17002

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17003

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-17004

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    Unknown

    CVE-2017-16998

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 4 Jan 2018
    5.4
    Medium

    CVE-2018-5215

    Last Modified: 21 Nov 2024

    Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.

    Published: 4 Jan 2018
    5.4
    Medium

    CVE-2018-5216

    Last Modified: 21 Nov 2024

    Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.

    Published: 4 Jan 2018
    7.8
    High

    CVE-2018-5217

    Last Modified: 21 Nov 2024

    In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002578.

    Published: 4 Jan 2018
    7.8
    High

    CVE-2018-5218

    Last Modified: 21 Nov 2024

    In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x950025b0.

    Published: 4 Jan 2018
    7.8
    High

    CVE-2018-5219

    Last Modified: 21 Nov 2024

    In K7 Antivirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002168.

    Published: 4 Jan 2018
    8.8
    High

    CVE-2017-17867

    Last Modified: 21 Nov 2024

    Inteno iopsys 2.0-3.14 and 4.0 devices allow remote authenticated users to execute arbitrary OS commands by modifying the leasetrigger field in the odhcpd configuration to specify an arbitrary program, as demonstrated by a program located on an SMB share. This issue existed because the /etc/uci-defaults directory was not being used to secure the OpenWrt configuration.

    Published: 4 Jan 2018
    7.8
    High

    CVE-2018-5220

    Last Modified: 21 Nov 2024

    In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002610.

    Published: 4 Jan 2018
    5.4
    Medium

    CVE-2018-5212

    Last Modified: 21 Nov 2024

    The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.

    Published: 4 Jan 2018
    5.4
    Medium

    CVE-2018-5214

    Last Modified: 21 Nov 2024

    The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php.

    Published: 4 Jan 2018
    5.4
    Medium

    CVE-2018-5213

    Last Modified: 21 Nov 2024

    The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.

    Published: 4 Jan 2018
    5.9
    Medium

    CVE-2017-1664

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133557.

    Published: 4 Jan 2018
    3.3
    Low

    CVE-2017-1699

    Last Modified: 21 Nov 2024

    IBM MQ Managed File Transfer Agent 8.0 and 9.0 sets insecure permissions on certain files it creates. A local attacker could exploit this vulnerability to modify or delete data contained in the files with an unknown impact. IBM X-Force ID: 134391.

    Published: 4 Jan 2018
    3.7
    Low

    CVE-2017-1669

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 stores sensitive information in URL parameters. This may lead to information disclosure if unauthorized parties have access to the URLs via server logs, referrer header or browser history. IBM X-Force ID: 133636.

    Published: 4 Jan 2018
    9.8
    Critical

    CVE-2014-7862

    Last Modified: 21 Nov 2024

    The DCPluginServelet servlet in ManageEngine Desktop Central and Desktop Central MSP before build 90109 allows remote attackers to create administrator accounts via an addPlugInUser action.

    Published: 4 Jan 2018
    4.3
    Medium

    CVE-2017-1727

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 discloses sensitive information in error messages that could aid an attacker in further attacks against the system. IBM X-Force ID: 134869.

    Published: 4 Jan 2018
    7.5
    High

    CVE-2017-14960

    Last Modified: 21 Nov 2024

    xDashboard in OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 has SQL Injection.

    Published: 4 Jan 2018
    5.9
    Medium

    CVE-2017-1665

    Last Modified: 21 Nov 2024

    IBM Tivoli Key Lifecycle Manager 2.5, 2.6, and 2.7 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 133559.

    Published: 4 Jan 2018