CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-7336

    Last Modified: 20 Apr 2025

    A hard-coded account named 'upgrade' in Fortinet FortiWLM 8.3.0 and lower versions allows a remote attacker to log-in and execute commands with 'upgrade' account privileges.

    Published: 22 Jul 2017
    9.8
    Critical

    CVE-2017-3221

    Last Modified: 20 Apr 2025

    Blind SQL injection in Inmarsat AmosConnect 8 login form allows remote attackers to access user credentials, including user names and passwords.

    Published: 22 Jul 2017
    9.8
    Critical

    CVE-2017-3222

    Last Modified: 20 Apr 2025

    Hard-coded credentials in AmosConnect 8 allow remote attackers to gain full administrative privileges, including the ability to execute commands on the Microsoft Windows host platform with SYSTEM privileges by abusing AmosConnect Task Manager.

    Published: 22 Jul 2017
    7.5
    High

    CVE-2017-11521

    Last Modified: 20 Apr 2025

    The SdpContents::Session::Medium::parse function in resip/stack/SdpContents.cxx in reSIProcate 1.10.2 allows remote attackers to cause a denial of service (memory consumption) by triggering many media connections.

    Published: 22 Jul 2017
    7.5
    High

    CVE-2016-10400

    Last Modified: 20 Apr 2025

    Directory Traversal exists in ATutor before 2.2.2 via the icon parameter to /mods/_core/courses/users/create_course.php. The attacker can read an arbitrary file by visiting get_course_icon.php?id= after the traversal attack.

    Published: 22 Jul 2017
    8.8
    High

    CVE-2017-2273

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.

    Published: 22 Jul 2017
    7.2
    High

    CVE-2017-2276

    Last Modified: 20 Apr 2025

    Buffer overflow in WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary commands via unspecified vectors.

    Published: 22 Jul 2017
    9.1
    Critical

    CVE-2017-2277

    Last Modified: 20 Apr 2025

    WG-C10 v3.0.79 and earlier allows an attacker to bypass access restrictions to obtain or alter information stored in the external storage connected to the product via unspecified vectors.

    Published: 22 Jul 2017
    7.5
    High

    CVE-2017-11591

    Last Modified: 20 Apr 2025

    There is a Floating point exception in the Exiv2::ValueType function in Exiv2 0.26 that will lead to a remote denial of service attack via crafted input.

    Published: 22 Jul 2017
    7.5
    High

    CVE-2017-11592

    Last Modified: 20 Apr 2025

    There is a Mismatched Memory Management Routines vulnerability in the Exiv2::FileIo::seek function of Exiv2 0.26 that will lead to a remote denial of service attack (heap memory corruption) via crafted input.

    Published: 22 Jul 2017
    9.8
    Critical

    CVE-2017-2126

    Last Modified: 20 Apr 2025

    WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors.

    Published: 22 Jul 2017
    6.1
    Medium

    CVE-2017-2274

    Last Modified: 20 Apr 2025

    Cross-site scripting vulnerability in WMR-433 firmware Ver.1.02 and earlier, WMR-433W firmware Ver.1.40 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 22 Jul 2017
    7.2
    High

    CVE-2017-2275

    Last Modified: 20 Apr 2025

    WG-C10 v3.0.79 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.

    Published: 22 Jul 2017
    9.8
    Critical

    CVE-2017-7480

    Last Modified: 20 Apr 2025

    rkhunter versions before 1.4.4 are vulnerable to file download over insecure channel when doing mirror update resulting into potential remote code execution.

    Published: 21 Jul 2017
    7.5
    High

    CVE-2017-7523

    Last Modified: 20 Apr 2025

    Cygwin versions 1.7.2 up to and including 1.8.0 are vulnerable to buffer overflow vulnerability in wcsxfrm/wcsxfrm_l functions resulting into denial-of-service by crashing the process or potential hijack of the process running with administrative privileges triggered by specially crafted input string.

    Published: 21 Jul 2017
    9.8
    Critical

    CVE-2017-11519

    Last Modified: 20 Apr 2025

    passwd_recovery.lua on the TP-Link Archer C9(UN)_V2_160517 allows an attacker to reset the admin password by leveraging a predictable random number generator seed. This is fixed in C9(UN)_V2_170511.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2017-1371

    Last Modified: 20 Apr 2025

    Builder tools running in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute Builder tool actions they do not have access to. IBM X-Force ID: 126864.

    Published: 21 Jul 2017
    5.4
    Medium

    CVE-2017-1372

    Last Modified: 20 Apr 2025

    IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 126865.

    Published: 21 Jul 2017
    9.8
    Critical

    CVE-2017-11517

    Last Modified: 20 Apr 2025

    Stack-based buffer overflow in GCoreServer.exe in the server in Geutebrueck Gcore 1.3.8.42 and 1.4.2.37 allows remote attackers to execute arbitrary code via a long URI in a GET request.

    Published: 21 Jul 2017
    7.5
    High

    CVE-2017-1267

    Last Modified: 20 Apr 2025

    IBM Security Guardium 10.0 and 10.1 processes patches, image backups and other updates without sufficiently verifying the origin and integrity of the code. IBM X-Force ID: 124742.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2017-1373

    Last Modified: 20 Apr 2025

    Reports executed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 contains a vulnerability that could allow an authenticated user to execute a report they do not have access to. IBM X-Force ID: 126866.

    Published: 21 Jul 2017
    6.5
    Medium

    CVE-2017-1374

    Last Modified: 20 Apr 2025

    Sensitive data can be exposed in the IBM TRIRIGA Application Platform 3.3, 3.4, and 3.5 that can lead to an attacker gaining unauthorized access to the system. IBM X-Force ID: 126867.

    Published: 21 Jul 2017
    3.3
    Low

    CVE-2017-1381

    Last Modified: 20 Apr 2025

    IBM WebSphere Application Server Proxy Server or On-demand-router (ODR) 7.0, 8.0, 8.5, 9.0 and could allow a local attacker to obtain sensitive information, caused by stale data being cached and then served. IBM X-Force ID: 127152.

    Published: 21 Jul 2017
    Unknown

    CVE-2011-4365

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4090. Reason: This candidate is a reservation duplicate of CVE-2011-4090. Notes: All CVE users should reference CVE-2011-4090 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2011-4366

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-4090. Reason: This candidate is a reservation duplicate of CVE-2011-4090. Notes: All CVE users should reference CVE-2011-4090 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2010-3068

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2010-2938. Reason: This candidate is a reservation duplicate of CVE-2010-2938. Notes: All CVE users should reference CVE-2010-2938 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2012-2323

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-2214. Reason: This candidate is a reservation duplicate of CVE-2012-2214. Notes: All CVE users should reference CVE-2012-2214 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2012-5637

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-4518. Reason: This candidate is a reservation duplicate of CVE-2012-4518. Notes: All CVE users should reference CVE-2012-4518 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2017-3734

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Jul 2017
    Unknown

    CVE-2016-7057

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 21 Jul 2017
    Unknown

    CVE-2016-7058

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 21 Jul 2017
    6.1
    Medium

    CVE-2017-11516

    Last Modified: 20 Apr 2025

    An XSS vulnerability exists in framework/views/errorHandler/exception.php in Yii Framework 2.0.12 affecting the exception screen when debug mode is enabled, because $exception->errorInfo is mishandled.

    Published: 21 Jul 2017
    Unknown

    CVE-2011-1014

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-0465. Reason: This candidate is a reservation duplicate of CVE-2011-0465. Notes: All CVE users should reference CVE-2011-0465 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2012-2382

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2011-1930. Reason: This candidate is a reservation duplicate of CVE-2011-1930. Notes: All CVE users should reference CVE-2011-1930 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2012-3550

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2012-3467. Reason: This candidate is a reservation duplicate of CVE-2012-3467. Notes: All CVE users should reference CVE-2012-3467 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 21 Jul 2017
    Unknown

    CVE-2016-7059

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 21 Jul 2017
    6.1
    Medium

    CVE-2015-3421

    Last Modified: 20 Apr 2025

    The eshop_checkout function in checkout.php in the Wordpress Eshop plugin 6.3.11 and earlier does not validate variables in the "eshopcart" HTTP cookie, which allows remote attackers to perform cross-site scripting (XSS) attacks, or a path disclosure attack via crafted variables named after target PHP variables.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2015-4639

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in opac-addbybiblionumber.pl in Koha 3.14.x before 3.14.16, 3.16.x before 3.16.12, and 3.20.x before 3.20.1 allows remote attackers to inject arbitrary web script or HTML via a crafted list name.

    Published: 21 Jul 2017
    7.5
    High

    CVE-2017-9415

    Last Modified: 20 Apr 2025

    Cross-site request forgery (CSRF) vulnerability in subsonic 6.1.1 allows remote attackers with knowledge of the target username to hijack the authentication of users for requests that change passwords via a crafted request to userSettings.view.

    Published: 21 Jul 2017
    5.5
    Medium

    CVE-2015-1323

    Last Modified: 20 Apr 2025

    The simulate dbus method in aptdaemon before 1.1.1+bzr982-0ubuntu3.1 as packaged in Ubuntu 15.04, before 1.1.1+bzr980-0ubuntu1.1 as packaged in Ubuntu 14.10, before 1.1.1-1ubuntu5.2 as packaged in Ubuntu 14.04 LTS, before 0.43+bzr805-0ubuntu10 as packaged in Ubuntu 12.04 LTS allows local users to obtain sensitive information, or access files with root permissions.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2015-3638

    Last Modified: 20 Apr 2025

    phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts via the path, filename, and period parameters to scheduled.php, and making requests to injected scripts, or by injecting PHP into a PHP configuration variable via a PHP variable variable.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2015-3639

    Last Modified: 20 Apr 2025

    phpMyBackupPro 2.5 and earlier does not properly sanitize input strings, which allows remote authenticated users to execute arbitrary PHP code by storing a crafted string in a user configuration file.

    Published: 21 Jul 2017
    7.5
    High

    CVE-2015-3640

    Last Modified: 20 Apr 2025

    phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and execute arbitrary PHP scripts by injecting scripts via the path, filename, and dirs parameters to scheduled.php, and making requests to injected scripts.

    Published: 21 Jul 2017
    9.8
    Critical

    CVE-2015-3886

    Last Modified: 20 Apr 2025

    libinfinity before 0.6.6-1 does not validate expired SSL certificates, which allows remote attackers to have unspecified impact via unknown vectors.

    Published: 21 Jul 2017
    7.8
    High

    CVE-2015-3931

    Last Modified: 20 Apr 2025

    Microsec e-Szigno before 3.2.7.12 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.

    Published: 21 Jul 2017
    7.8
    High

    CVE-2015-3932

    Last Modified: 20 Apr 2025

    Netlock Mokka before 2.7.8.1204 allows remote attackers to perform XML signature wrapping attacks via an e-akta signed document with a ds:Object node with a crafted payload prepended to a valid ds:Object.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2017-10993

    Last Modified: 20 Apr 2025

    Contao before 3.5.28 and 4.x before 4.4.1 allows remote attackers to include and execute arbitrary local PHP files via a crafted parameter in a URL, aka Directory Traversal.

    Published: 21 Jul 2017
    8.8
    High

    CVE-2017-9930

    Last Modified: 20 Apr 2025

    Cross-Site Request Forgery (CSRF) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by a request to ajax.cgi that enables UPnP.

    Published: 21 Jul 2017
    6.1
    Medium

    CVE-2017-9931

    Last Modified: 20 Apr 2025

    Cross-Site Scripting (XSS) exists in Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb, as demonstrated by the action parameter to ajax.cgi.

    Published: 21 Jul 2017
    9.8
    Critical

    CVE-2017-9932

    Last Modified: 20 Apr 2025

    Green Packet DX-350 Firmware version v2.8.9.5-g1.4.8-atheeb has a default password of admin for the admin account.

    Published: 21 Jul 2017