CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2017-1000043

    Last Modified: 20 Apr 2025

    Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control

    Published: 13 Jul 2017
    Unknown

    CVE-2017-1000045

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000046

    Last Modified: 20 Apr 2025

    Mautic 2.6.1 and earlier fails to set flags on session cookies

    Published: 13 Jul 2017
    Unknown

    CVE-2017-1000049

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2015-8864. Reason: This candidate is a reservation duplicate of CVE-2015-8864. Notes: All CVE users should reference CVE-2015-8864 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000051

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content

    Published: 13 Jul 2017
    7.8
    High

    CVE-2017-1000052

    Last Modified: 20 Apr 2025

    Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions.

    Published: 13 Jul 2017
    8.1
    High

    CVE-2017-1000053

    Last Modified: 20 Apr 2025

    Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000054

    Last Modified: 20 Apr 2025

    Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages.

    Published: 13 Jul 2017
    Unknown

    CVE-2017-1000057

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA due to lack of a reference providing provenance. Notes: none

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000058

    Last Modified: 20 Apr 2025

    Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000059

    Last Modified: 20 Apr 2025

    Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000060

    Last Modified: 20 Apr 2025

    EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000062

    Last Modified: 20 Apr 2025

    kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000063

    Last Modified: 20 Apr 2025

    kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000064

    Last Modified: 20 Apr 2025

    kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000067

    Last Modified: 20 Apr 2025

    MODX Revolution version 2.x - 2.5.6 is vulnerable to blind SQL injection caused by improper sanitization by the escape method resulting in authenticated user accessing database and possibly escalating privileges.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000068

    Last Modified: 20 Apr 2025

    TestTrack Server versions 1.0 and earlier are vulnerable to an authentication flaw in the split disablement feature resulting in the ability to disable arbitrary running splits and cause denial of service to clients in the field.

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000069

    Last Modified: 20 Apr 2025

    CSRF in Bitly oauth2_proxy 2.1 during authentication flow

    Published: 13 Jul 2017
    8.1
    High

    CVE-2017-1000071

    Last Modified: 20 Apr 2025

    Jasig phpCAS version 1.3.4 is vulnerable to an authentication bypass in the validateCAS20 function when configured to authenticate against an old CAS server.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000072

    Last Modified: 20 Apr 2025

    Creolabs Gravity version 1.0 is vulnerable to a Double Free in gravity_value resulting potentially leading to modification of unexpected memory locations

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000074

    Last Modified: 20 Apr 2025

    Creolabs Gravity version 1.0 is vulnerable to a stack overflow in the string_repeat() function.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000078

    Last Modified: 20 Apr 2025

    Linux foundation ONOS 1.9 is vulnerable to XSS in the device. registration

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000079

    Last Modified: 20 Apr 2025

    Linux foundation ONOS 1.9.0 is vulnerable to a DoS.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000080

    Last Modified: 20 Apr 2025

    Linux foundation ONOS 1.9.0 allows unauthenticated use of websockets.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000003

    Last Modified: 20 Apr 2025

    ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Social Application component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to an incorrect access control check vulnerability in the Module component resulting in privilege escalation. ATutor versions 2.2.1 and earlier are vulnerable to a incorrect access control check vulnerability in the Alternative Content component resulting in privilege escalation.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000004

    Last Modified: 20 Apr 2025

    ATutor version 2.2.1 and earlier are vulnerable to a SQL injection in the Assignment Dropbox, BasicLTI, Blog Post, Blog, Group Course Email, Course Alumni, Course Enrolment, Group Membership, Course unenrolment, Course Enrolment List Search, Glossary, Social Group Member Search, Social Friend Search, Social Group Search, File Comment, Gradebook Test Title, User Group Membership, Inbox/Sent Items, Sent Messages, Links, Photo Album, Poll, Social Application, Social Profile, Test, Content Menu, Auto-Login, and Gradebook components resulting in information disclosure, database modification, or potential code execution.

    Published: 13 Jul 2017
    5.9
    Medium

    CVE-2017-1000007

    Last Modified: 20 Apr 2025

    txAWS (all current versions) fail to perform complete certificate verification resulting in vulnerability to MitM attacks and information disclosure.

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000008

    Last Modified: 20 Apr 2025

    Chyrp Lite version 2016.04 is vulnerable to a CSRF in the user settings function allowing attackers to hijack the authentication of logged in users to modify account information, including their password.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000012

    Last Modified: 20 Apr 2025

    MySQL Dumper version 1.24 is vulnerable to stored XSS when displaying the data in the database to the user

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000020

    Last Modified: 20 Apr 2025

    SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood packets fails to validate and handle the packets and does not ask for any sign of authentication resulting in Authentication Bypass. An attacker can take complete advantage of this bug and take over the device remotely or locally. The bug has been successfully tested and reproduced in some versions of SOHO Routers manufactured by TOTOLINK, GREATEK and others."

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-1000021

    Last Modified: 20 Apr 2025

    LogicalDoc Community Edition 7.5.3 and prior is vulnerable to XXE when indexing XML documents.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000026

    Last Modified: 20 Apr 2025

    Chef Software's mixlib-archive versions 0.3.0 and older are vulnerable to a directory traversal attack allowing attackers to overwrite arbitrary files by using ".." in tar archive entries

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000029

    Last Modified: 20 Apr 2025

    Oracle, GlassFish Server Open Source Edition 3.0.1 (build 22) is vulnerable to Local File Inclusion vulnerability, that makes it possible to include arbitrary files on the server, this vulnerability can be exploited without any prior authentication.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000037

    Last Modified: 20 Apr 2025

    RVM automatically loads environment variables from files in $PWD resulting in command execution RVM vulnerable to command injection when automatically loading environment variables from files in $PWD RVM automatically executes hooks located in $PWD resulting in code execution RVM automatically installs gems as specified by files in $PWD resulting in code execution RVM automatically does "bundle install" on a Gemfile specified by .versions.conf in $PWD resulting in code execution

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000038

    Last Modified: 20 Apr 2025

    WordPress plugin Relevanssi version 3.5.7.1 is vulnerable to stored XSS resulting in attacker being able to execute JavaScript on the affected site

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-1000066

    Last Modified: 20 Apr 2025

    The entry details view function in KeePass version 1.32 inadvertently decrypts certain database entries into memory, which may result in the disclosure of sensitive information.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-1000070

    Last Modified: 20 Apr 2025

    The Bitly oauth2_proxy in version 2.1 and earlier was affected by an open redirect vulnerability during the start and termination of the 2-legged OAuth flow. This issue was caused by improper input validation and a violation of RFC-6819

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2017-1000081

    Last Modified: 20 Apr 2025

    Linux foundation ONOS 1.9.0 is vulnerable to unauthenticated upload of applications (.oar) resulting in remote code execution.

    Published: 13 Jul 2017
    7
    High

    CVE-2017-6249

    Last Modified: 20 Apr 2025

    An elevation of privilege vulnerability in the NVIDIA sound driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as Moderate because it first requires compromising a privileged process. Product: Android. Versions: N/A. Android ID: A-34373711. References: N-CVE-2017-6249.

    Published: 13 Jul 2017
    9.8
    Critical

    CVE-2016-8964

    Last Modified: 20 Apr 2025

    IBM BigFix Inventory v9 9.2 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 118853.

    Published: 13 Jul 2017
    6.5
    Medium

    CVE-2017-1308

    Last Modified: 20 Apr 2025

    IBM Daeja ViewONE Professional, Standard & Virtual 4.1.5.1 and 5.0 could allow an authenticated attacker to download files they should not have access to due to improper access controls. IBM X-Force ID: 125462.

    Published: 13 Jul 2017
    5.9
    Medium

    CVE-2017-7672

    Last Modified: 20 Apr 2025

    If an application allows enter an URL in a form field and built-in URLValidator is used, it is possible to prepare a special URL which will be used to overload server process when performing validation of the URL. Solution is to upgrade to Apache Struts version 2.5.12.

    Published: 13 Jul 2017
    5.4
    Medium

    CVE-2016-6019

    Last Modified: 20 Apr 2025

    IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 116739.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2016-8951

    Last Modified: 20 Apr 2025

    IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to a denial of service attack. An attacker can exploit a vulnerability in the authentication features that could log out users and flood user accounts with emails. IBM X-Force ID: 118838.

    Published: 13 Jul 2017
    5.4
    Medium

    CVE-2016-8952

    Last Modified: 20 Apr 2025

    IBM Emptoris Strategic Supply Management Platform 10.0.0.x through 10.1.1.x is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 118839.

    Published: 13 Jul 2017
    7.5
    High

    CVE-2017-9787

    Last Modified: 20 Apr 2025

    When using a Spring AOP functionality to secure Struts actions it is possible to perform a DoS attack. Solution is to upgrade to Apache Struts version 2.5.12 or 2.3.33.

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-11173

    Last Modified: 20 Apr 2025

    Missing anchor in generated regex for rack-cors before 0.4.1 allows a malicious third-party site to perform CORS requests. If the configuration were intended to allow only the trusted example.com domain name and not the malicious example.net domain name, then example.com.example.net (as well as example.com-example.net) would be inadvertently allowed.

    Published: 13 Jul 2017
    6.1
    Medium

    CVE-2017-11198

    Last Modified: 20 Apr 2025

    Cross-site scripting (XSS) vulnerability in /application/lib/ajax/get_image.php in FineCMS through 2017-07-12 allows remote attackers to inject arbitrary web script or HTML via the folder, id, or name parameter.

    Published: 13 Jul 2017
    8.8
    High

    CVE-2017-11200

    Last Modified: 20 Apr 2025

    SQL Injection exists in FineCMS through 2017-07-12 via the application/core/controller/excludes.php visitor_ip parameter.

    Published: 13 Jul 2017
    5.4
    Medium

    CVE-2017-11201

    Last Modified: 20 Apr 2025

    application/core/controller/images.php in FineCMS through 2017-07-12 allows remote authenticated admins to conduct XSS attacks by uploading an image via a route=images action.

    Published: 13 Jul 2017