CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-1000501

    Last Modified: 21 Nov 2024

    Awstats version 7.6 and earlier is vulnerable to a path traversal flaw in the handling of the "config" and "migrate" parameters resulting in unauthenticated remote code execution.

    Published: 3 Jan 2018
    Unknown

    CVE-2017-14393

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15540

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15541

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15542

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15543

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15544

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15545

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-2771

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-2772

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-2769

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-2770

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-4957

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-4958

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-4968

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8009

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8030

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8049

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15557

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15558

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-15559

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-2774

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-4956

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-4993

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8029

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8008

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8027

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    Unknown

    CVE-2017-8042

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 3 Jan 2018
    8.8
    High

    CVE-2017-1000499

    Last Modified: 21 Nov 2024

    phpMyAdmin versions 4.7.x (prior to 4.7.6.1/4.7.7) are vulnerable to a CSRF weakness. By deceiving a user to click on a crafted URL, it is possible to perform harmful database operations such as deleting records, dropping/truncating tables etc.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2017-1000498

    Last Modified: 21 Nov 2024

    AndroidSVG version 1.2.2 is vulnerable to XXE attacks in the SVG parsing component resulting in denial of service and possibly remote code execution

    Published: 3 Jan 2018
    7.8
    High

    CVE-2017-1000494

    Last Modified: 21 Nov 2024

    Uninitialized stack variable vulnerability in NameValueParserEndElt (upnpreplyparse.c) in miniupnpd < 2.0 allows an attacker to cause Denial of Service (Segmentation fault and Memory Corruption) or possibly have unspecified other impact

    Published: 3 Jan 2018
    5.4
    Medium

    CVE-2017-1000495

    Last Modified: 21 Nov 2024

    QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account

    Published: 3 Jan 2018
    8.8
    High

    CVE-2017-1000496

    Last Modified: 21 Nov 2024

    Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2017-1000497

    Last Modified: 21 Nov 2024

    Pepperminty-Wiki version 0.15 is vulnerable to XXE attacks in the getsvgsize function resulting in denial of service and possibly remote code execution

    Published: 3 Jan 2018
    5.5
    Medium

    CVE-2018-4868

    Last Modified: 21 Nov 2024

    The Exiv2::Jp2Image::readMetadata function in jp2image.cpp in Exiv2 0.26 allows remote attackers to cause a denial of service (excessive memory allocation) via a crafted file.

    Published: 3 Jan 2018
    8.8
    High

    CVE-2018-4862

    Last Modified: 21 Nov 2024

    In Octopus Deploy versions 3.2.11 - 4.1.5 (fixed in 4.1.6), an authenticated user with ProcessEdit permission could reference an Azure account in such a way as to bypass the scoping restrictions, resulting in a potential escalation of privileges.

    Published: 3 Jan 2018
    5.4
    Medium

    CVE-2017-1000466

    Last Modified: 21 Nov 2024

    Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.

    Published: 3 Jan 2018
    6.1
    Medium

    CVE-2017-1000492

    Last Modified: 21 Nov 2024

    Leanote-desktop version v2.5 is vulnerable to a XSS which leads to code execution due to enabled node integration

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2017-1000493

    Last Modified: 21 Nov 2024

    Rocket.Chat Server version 0.59 and prior is vulnerable to a NoSQL injection leading to administrator account takeover

    Published: 3 Jan 2018
    6.1
    Medium

    CVE-2017-1000491

    Last Modified: 21 Nov 2024

    Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.

    Published: 3 Jan 2018
    4.3
    Medium

    CVE-2013-4317

    Last Modified: 21 Nov 2024

    In Apache CloudStack 4.1.0 and 4.1.1, when calling the CloudStack API call listProjectAccounts as a regular, non-administrative user, the user is able to see information for accounts other than their own.

    Published: 3 Jan 2018
    6.1
    Medium

    CVE-2017-1000459

    Last Modified: 21 Nov 2024

    Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes

    Published: 3 Jan 2018
    6.5
    Medium

    CVE-2017-1000483

    Last Modified: 21 Nov 2024

    Accessing private content via str.format in through-the-web templates and scripts in Plone 2.5-5.1rc1. This improves an earlier hotfix. Since the format method was introduced in Python 2.6, this part of the hotfix is only relevant for Plone 4 and 5.

    Published: 3 Jan 2018
    5.4
    Medium

    CVE-2017-1000463

    Last Modified: 21 Nov 2024

    Leafpub version 1.2.0-beta6 is vulnerable to stored cross-site scripting vulnerability, within the edit blog post page, which can result in disruption of service and execution of javascript code.

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2018-5703

    Last Modified: 21 Nov 2024

    The tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service (slab out-of-bounds write) or possibly have unspecified other impact via vectors involving TLS.

    Published: 3 Jan 2018
    7.8
    High

    CVE-2017-12189

    Last Modified: 21 Nov 2024

    It was discovered that the jboss init script as used in Red Hat JBoss Enterprise Application Platform 7.0.7.GA performed unsafe file handling which could result in local privilege escalation. This issue is a result of an incomplete fix for CVE-2016-8656.

    Published: 3 Jan 2018
    9.8
    Critical

    CVE-2017-18017

    Last Modified: 3 Jan 2025

    The tcpmss_mangle_packet function in net/netfilter/xt_TCPMSS.c in the Linux kernel before 4.11, and 4.9.x before 4.9.36, allows remote attackers to cause a denial of service (use-after-free and memory corruption) or possibly have unspecified other impact by leveraging the presence of xt_TCPMSS in an iptables action.

    Published: 3 Jan 2018
    5.5
    Medium

    CVE-2018-5333

    Last Modified: 21 Nov 2024

    In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.

    Published: 3 Jan 2018
    6.1
    Medium

    CVE-2017-1000425

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the /html/portal/flash.jsp page in Liferay Portal CE 7.0 GA4 and older allows remote attackers to inject arbitrary web script or HTML via a javascript: URI in the "movie" parameter.

    Published: 2 Jan 2018
    6.1
    Medium

    CVE-2017-1000434

    Last Modified: 21 Nov 2024

    Wordpress plugin Furikake version 0.1.0 is vulnerable to an Open Redirect The furikake-redirect parameter on a page allows for a redirect to an attacker controlled page classes/Furigana.php: header('location:'.urldecode($_GET['furikake-redirect']));

    Published: 2 Jan 2018