CVE Feed

    Dashboard / CVE

    8.1
    High

    CVE-2017-17919

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the 'order' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id desc' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

    Published: 29 Dec 2017
    8.1
    High

    CVE-2017-17920

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the 'reorder' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'name' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

    Published: 29 Dec 2017
    8.1
    High

    CVE-2017-17917

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the 'where' method in Ruby on Rails 5.1.4 and earlier allows remote attackers to execute arbitrary SQL commands via the 'id' parameter. NOTE: The vendor disputes this issue because the documentation states that this method is not intended for use with untrusted input

    Published: 29 Dec 2017
    7.5
    High

    CVE-2013-7400

    Last Modified: 20 Apr 2025

    The Direct Mail (direct_mail) extension before 3.1.2 for TYPO3 allows remote attackers to obtain sensitive information by leveraging improper checking of authentication codes.

    Published: 29 Dec 2017
    9.8
    Critical

    CVE-2017-17968

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in NetTransport.exe in NetTransport Download Manager 2.96L and earlier could allow remote HTTP servers to execute arbitrary code on NAS devices via a long HTTP response.

    Published: 29 Dec 2017
    6.1
    Medium

    CVE-2017-16876

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.

    Published: 29 Dec 2017
    9.8
    Critical

    CVE-2014-4914

    Last Modified: 20 Apr 2025

    The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.

    Published: 29 Dec 2017
    6.5
    Medium

    CVE-2017-18013

    Last Modified: 21 Nov 2024

    In LibTIFF 4.0.9, there is a Null-Pointer Dereference in the tif_print.c TIFFPrintDirectory function, as demonstrated by a tiffinfo crash.

    Published: 29 Dec 2017
    7.5
    High

    CVE-2017-17997

    Last Modified: 20 Apr 2025

    In Wireshark before 2.2.12, the MRDISC dissector misuses a NULL pointer and crashes. This was addressed in epan/dissectors/packet-mrdisc.c by validating an IPv4 address. This vulnerability is similar to CVE-2017-9343.

    Published: 29 Dec 2017
    8.8
    High

    CVE-2017-17973

    Last Modified: 20 Apr 2025

    In LibTIFF 4.0.8, there is a heap-based use-after-free in the t2p_writeproc function in tiff2pdf.c. NOTE: there is a third-party report of inability to reproduce this issue

    Published: 29 Dec 2017
    5.5
    Medium

    CVE-2017-17967

    Last Modified: 20 Apr 2025

    pptreader.dll in Kingsoft WPS Office 10.1.0.6930 allows remote attackers to cause a denial of service via a crafted PPT file, aka CNVD-2017-35482.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17949

    Last Modified: 20 Apr 2025

    Cells Blog 3.5 has XSS via the pub_readpost.php fmid parameter.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17948

    Last Modified: 20 Apr 2025

    Cells Blog 3.5 has XSS via the jfdname parameter in an act=showpic request.

    Published: 28 Dec 2017
    8.6
    High

    CVE-2017-17952

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17953

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the category.php chid1 parameter.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17955

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the shopping-cart.php cusid parameter.

    Published: 28 Dec 2017
    9.8
    Critical

    CVE-2017-17959

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the seller-view.php usid parameter.

    Published: 28 Dec 2017
    8.8
    High

    CVE-2017-17960

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has CSRF via admin/sellerupd.php.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17958

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the my_wishlist.php fid parameter.

    Published: 28 Dec 2017
    8.8
    High

    CVE-2017-17950

    Last Modified: 20 Apr 2025

    Cells Blog 3.5 has SQL Injection via the pub_readpost.php ptid parameter.

    Published: 28 Dec 2017
    9.8
    Critical

    CVE-2017-17951

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the shopping-cart.php cusid parameter.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17954

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the seller-view.php usid parameter.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17956

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has XSS via the admin/sellerupd.php companyname parameter.

    Published: 28 Dec 2017
    9.8
    Critical

    CVE-2017-17957

    Last Modified: 20 Apr 2025

    PHP Scripts Mall PHP Multivendor Ecommerce has SQL Injection via the my_wishlist.php fid parameter.

    Published: 28 Dec 2017
    7.5
    High

    CVE-2017-15667

    Last Modified: 20 Apr 2025

    In Flexense SysGauge Server 3.6.18, the Control Protocol suffers from a denial of service. The attack vector is a crafted SERVER_GET_INFO packet sent to control port 9221.

    Published: 28 Dec 2017
    9.8
    Critical

    CVE-2017-5641

    Last Modified: 20 Apr 2025

    Previous versions of Apache Flex BlazeDS (4.7.2 and earlier) did not restrict which types were allowed for AMF(X) object deserialization by default. During the deserialization process code is executed that for several known types has undesired side-effects. Other, unknown types may also exhibit such behaviors. One vector in the Java standard library exists that allows an attacker to trigger possibly further exploitable Java deserialization of untrusted data. Other known vectors in third party libraries can be used to trigger remote code execution.

    Published: 28 Dec 2017
    6.5
    Medium

    CVE-2017-15886

    Last Modified: 20 Apr 2025

    Server-side request forgery (SSRF) vulnerability in Link Preview in Synology Chat before 2.0.0-1124 allows remote authenticated users to download arbitrary local files via a crafted URI.

    Published: 28 Dec 2017
    5.4
    Medium

    CVE-2017-15892

    Last Modified: 20 Apr 2025

    Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow remote authenticated users to inject arbitrary web script or HTML via (1) COMMAND, (2) COMMANDS INSTRUCTION, or (3) DESCRIPTION parameter.

    Published: 28 Dec 2017
    Unknown

    CVE-2017-15711

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 28 Dec 2017
    9.8
    Critical

    CVE-2017-17932

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability exists in MediaServer.exe in ALLPlayer ALLMediaServer 0.95 and earlier that could allow remote attackers to execute arbitrary code and/or cause denial of service on the victim machine/computer via a long string to TCP port 888.

    Published: 28 Dec 2017
    8.8
    High

    CVE-2017-17936

    Last Modified: 20 Apr 2025

    Vanguard Marketplace Digital Products PHP has CSRF via /search.

    Published: 28 Dec 2017
    6.1
    Medium

    CVE-2017-17937

    Last Modified: 20 Apr 2025

    Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.

    Published: 28 Dec 2017
    4.8
    Medium

    CVE-2017-17938

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.

    Published: 28 Dec 2017
    8.8
    High

    CVE-2017-17939

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Single Theater Booking has CSRF via admin/sitesettings.php.

    Published: 28 Dec 2017
    4.8
    Medium

    CVE-2017-17940

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.

    Published: 28 Dec 2017
    7.2
    High

    CVE-2017-17941

    Last Modified: 20 Apr 2025

    PHP Scripts Mall Single Theater Booking has SQL Injection via the admin/movieview.php movieid parameter.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3614

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3618

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3622

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3636

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3637

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3642

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3644

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3647

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3648

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3653

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3654

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3656

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3660

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017
    Unknown

    CVE-2018-3664

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none.

    Published: 28 Dec 2017