CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2017-0783

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63145701.

    Published: 14 Sept 2017
    6.5
    Medium

    CVE-2017-0785

    Last Modified: 20 Apr 2025

    A information disclosure vulnerability in the Android system (bluetooth). Product: Android. Versions: 4.4.4, 5.0.2, 5.1.1, 6.0, 6.0.1, 7.0, 7.1.1, 7.1.2, 8.0. Android ID: A-63146698.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-2809

    Last Modified: 20 Apr 2025

    An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.

    Published: 14 Sept 2017
    6.5
    Medium

    CVE-2017-13761

    Last Modified: 20 Apr 2025

    The Fastly CDN module before 1.2.26 for Magento2, when used with a third-party authentication plugin, might allow remote authenticated users to obtain sensitive information from authenticated sessions via vectors involving caching of redirect responses.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2013-7429

    Last Modified: 20 Apr 2025

    The Googlemaps plugin before 3.1 for Joomla! allows remote attackers to conduct XML injection attacks via the url parameter to plugin_googlemap2_proxy.php.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-13067

    Last Modified: 20 Apr 2025

    QNAP has patched a remote code execution vulnerability affecting the QTS Media Library in all versions prior to QTS 4.2.6 build 20170905 and QTS 4.3.3.0299 build 20170901. This particular vulnerability allows a remote attacker to execute commands on a QNAP NAS using a transcoding service on port 9251. A remote user does not require any privileges to successfully execute an attack.

    Published: 14 Sept 2017
    Unknown

    CVE-2017-14113

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-13067. Reason: This candidate is a reservation duplicate of CVE-2017-13067. Notes: All CVE users should reference CVE-2017-13067 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 14 Sept 2017
    5.3
    Medium

    CVE-2017-1490

    Last Modified: 20 Apr 2025

    An unspecified vulnerability in the Lifecycle Query Engine of Jazz Reporting Service 6.0 through 6.0.4 could disclose highly sensitive information.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002001

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

    Published: 14 Sept 2017
    6.1
    Medium

    CVE-2017-1002017

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin gift-certificate-creator v1.0, The code in gc-list.php doesn't sanitize user input to prevent a stored XSS vulnerability.

    Published: 14 Sept 2017
    8.8
    High

    CVE-2017-1002026

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin Event Expresso Free v3.1.37.11.L, The function edit_event_category does not sanitize user-supplied input via the $id parameter before passing it into an SQL statement.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002008

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin membership-simplified-for-oap-members-only v1.58, The file download code located membership-simplified-for-oap-members-only/download.php does not check whether a user is logged in and has download privileges.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002016

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin flickr-picture-backup v0.7, The code in flickr-picture-download.php doesn't check to see if the user is authenticated or that they have permission to upload files.

    Published: 14 Sept 2017
    4.3
    Medium

    CVE-2017-1002024

    Last Modified: 20 Apr 2025

    Vulnerability in web application Kind Editor v4.1.12, kindeditor/php/upload_json.php does not check authentication before allow users to upload files.

    Published: 14 Sept 2017
    7.2
    High

    CVE-2017-1002025

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin add-edit-delete-listing-for-member-module v1.0, The plugin author does not sanitize user supplied input via $act before passing it into an SQL statement.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002002

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002003

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-1002004

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/download.php user input isn't sanitized via the id variable before adding it to the end of an SQL query.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-1002005

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin DTracker v1.5, In file ./dtracker/delete.php user input isn't sanitized via the contact_id variable before adding it to the end of an SQL query.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-1002006

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_contact.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-1002007

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin DTracker v1.5, The code dtracker/save_mail.php doesn't check that the user is authorized before injecting new contacts into the wp_contact table.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002009

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete function.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002010

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin Membership Simplified v1.58, The code in membership-simplified-for-oap-members-only/updateDB.php is vulnerable to blind SQL injection because it doesn't sanitize user input via recordId in the delete_media function.

    Published: 14 Sept 2017
    5.4
    Medium

    CVE-2017-1002011

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, There is a stored XSS vulnerability via the $value->gallery_name and $value->gallery_description where anyone with privileges to modify or add galleries/images and inject javascript into the database.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002012

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, In image-gallery-with-slideshow/admin_setting.php the following snippet of code does not sanitize input via the gid variable before passing it into an SQL statement.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002013

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection via imgid parameter in image-gallery-with-slideshow/admin_setting.php.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002014

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via gallery_name parameter.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002015

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin image-gallery-with-slideshow v1.5.2, Blind SQL Injection in image-gallery-with-slideshow/admin_setting.php via selectMulGallery parameter.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002018

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and attendees.php code do not sanitize input, this allows for blind SQL injection via the event parameter.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002019

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin eventr v1.02.2, The edit.php form and event_form.php code do not sanitize input, this allows for blind SQL injection via the event parameter.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002020

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin surveys v1.01.8, The code in survey_form.php does not sanitize the action variable before placing it inside of an SQL query.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002021

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin surveys v1.01.8, The code in individual_responses.php does not sanitize the survey_id variable before placing it inside of an SQL query.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002022

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin surveys v1.01.8, The code in questions.php does not sanitize the survey variable before placing it inside of an SQL query.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002023

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin Easy Team Manager v1.3.2, The code does not sanitize id before making it part of an SQL statement in file ./easy-team-manager/inc/easy_team_manager_desc_edit.php

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002027

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin rk-responsive-contact-form v1.0, The variable $delid isn't sanitized before being passed into an SQL query in file ./rk-responsive-contact-form/include/rk_user_list.php.

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002028

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin wordpress-gallery-transformation v1.0, SQL injection is in ./wordpress-gallery-transformation/gallery.php via $jpic parameter being unsanitized before being passed into an SQL query.

    Published: 14 Sept 2017
    6.1
    Medium

    CVE-2017-1002150

    Last Modified: 20 Apr 2025

    python-fedora 0.8.0 and lower is vulnerable to an open redirect resulting in loss of CSRF protection

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-1002151

    Last Modified: 20 Apr 2025

    Pagure 3.3.0 and earlier is vulnerable to loss of confidentially due to improper authorization

    Published: 14 Sept 2017
    9.8
    Critical

    CVE-2017-1002000

    Last Modified: 20 Apr 2025

    Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.

    Published: 14 Sept 2017
    7.8
    High

    CVE-2017-13779

    Last Modified: 20 Apr 2025

    GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions. This allows local users to gain privileges by replacing winstart-server.vbs with arbitrary VBScript code. For example, a local user could create VBScript code for a TCP reverse shell, and use that later for Remote Command Execution.

    Published: 14 Sept 2017
    8.8
    High

    CVE-2017-10784

    Last Modified: 20 Apr 2025

    The Basic authentication code in WEBrick library in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows remote attackers to inject terminal emulator escape sequences into its log and possibly execute arbitrary commands via a crafted user name.

    Published: 14 Sept 2017
    8.1
    High

    CVE-2017-14245

    Last Modified: 20 Apr 2025

    An out of bounds read in the function d2alaw_array() in alaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-14976

    Last Modified: 20 Apr 2025

    The FoFiType1C::convertToType0 function in FoFiType1C.cc in Poppler 0.59.0 has a heap-based buffer over-read vulnerability if an out-of-bounds font dictionary index is encountered, which allows an attacker to launch a denial of service attack.

    Published: 14 Sept 2017
    8.1
    High

    CVE-2017-14246

    Last Modified: 20 Apr 2025

    An out of bounds read in the function d2ulaw_array() in ulaw.c of libsndfile 1.0.28 may lead to a remote DoS attack or information disclosure, related to mishandling of the NAN and INFINITY floating-point values.

    Published: 14 Sept 2017
    9.1
    Critical

    CVE-2017-0898

    Last Modified: 20 Apr 2025

    Ruby before 2.4.2, 2.3.5, and 2.2.8 is vulnerable to a malicious format string which contains a precious specifier (*) with a huge minus value. Such situation can lead to a buffer overrun, resulting in a heap memory corruption or an information disclosure from the heap.

    Published: 14 Sept 2017
    5.5
    Medium

    CVE-2017-12167

    Last Modified: 21 Nov 2024

    It was found in EAP 7 before 7.0.9 that properties based files of the management and the application realm configuration that contain user to role mapping are world readable allowing access to users and roles information to all the users logged in to the system.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-14033

    Last Modified: 20 Apr 2025

    The decode method in the OpenSSL::ASN1 module in Ruby before 2.2.8, 2.3.x before 2.3.5, and 2.4.x through 2.4.1 allows attackers to cause a denial of service (interpreter crash) via a crafted string.

    Published: 14 Sept 2017
    6.5
    Medium

    CVE-2017-14634

    Last Modified: 20 Apr 2025

    In libsndfile 1.0.28, a divide-by-zero error exists in the function double64_init() in double64.c, which may lead to DoS when playing a crafted audio file.

    Published: 14 Sept 2017
    7.5
    High

    CVE-2017-15033

    Last Modified: 20 Apr 2025

    ImageMagick version 7.0.7-2 contains a memory leak in ReadYUVImage in coders/yuv.c.

    Published: 14 Sept 2017
    7.8
    High

    CVE-2017-16526

    Last Modified: 20 Apr 2025

    drivers/uwb/uwbd.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (general protection fault and system crash) or possibly have unspecified other impact via a crafted USB device.

    Published: 14 Sept 2017