CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2016-3114

    Last Modified: 20 Apr 2025

    Kallithea before 0.3.2 allows remote authenticated users to edit or delete open pull requests or delete comments by leveraging read access.

    Published: 24 Apr 2017
    8.8
    High

    CVE-2016-3691

    Last Modified: 20 Apr 2025

    Routes in Kallithea before 0.3.2 allows remote attackers to bypass the CSRF protection by using the GET HTTP request method.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2015-7245

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage parameter.

    Published: 24 Apr 2017
    8.1
    High

    CVE-2017-8099

    Last Modified: 20 Apr 2025

    There is CSRF in the WHIZZ plugin before 1.1.1 for WordPress, allowing attackers to delete any WordPress users and change the plugin's status via a GET request.

    Published: 24 Apr 2017
    8.8
    High

    CVE-2017-8101

    Last Modified: 20 Apr 2025

    There is CSRF in Serendipity 2.0.5, allowing attackers to install any themes via a GET request.

    Published: 24 Apr 2017
    9.8
    Critical

    CVE-2015-7246

    Last Modified: 20 Apr 2025

    D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obtain administrative access.

    Published: 24 Apr 2017
    9.8
    Critical

    CVE-2015-7247

    Last Modified: 20 Apr 2025

    D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration backup, which allows remote attackers to obtain sensitive information.

    Published: 24 Apr 2017
    9.8
    Critical

    CVE-2015-7568

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.

    Published: 24 Apr 2017
    8.8
    High

    CVE-2015-7569

    Last Modified: 20 Apr 2025

    SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.

    Published: 24 Apr 2017
    7.2
    High

    CVE-2015-7570

    Last Modified: 20 Apr 2025

    Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb_lite/tests/test_adodb_lite.php, libs/org/adodb_lite/tests/test_datadictionary.php, or libs/org/adodb_lite/tests/test_adodb_lite_sessions.php.

    Published: 24 Apr 2017
    Unknown

    CVE-2015-7572

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-0237. Reason: This candidate is a duplicate of CVE-2013-0237. Notes: All CVE users should reference CVE-2013-0237 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 24 Apr 2017
    6.1
    Medium

    CVE-2017-7723

    Last Modified: 20 Apr 2025

    XSS exists in Easy WP SMTP (before 1.2.5), a WordPress Plugin, via the e-mail subject or body.

    Published: 24 Apr 2017
    7.8
    High

    CVE-2016-4313

    Last Modified: 20 Apr 2025

    Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.

    Published: 24 Apr 2017
    5.5
    Medium

    CVE-2017-2322

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1, may allow an authenticated user to cause widespread denials of service to system services by consuming TCP and UDP ports which are normally reserved for other system services.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-8100

    Last Modified: 20 Apr 2025

    There is CSRF in the CopySafe Web Protection plugin before 2.6 for WordPress, allowing attackers to change plugin settings.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-8098

    Last Modified: 20 Apr 2025

    e107 2.1.4 is vulnerable to cross-site request forgery in plugin-installing, meta-changing, and settings-changing. A malicious web page can use forged requests to make e107 download and install a plug-in provided by the attacker.

    Published: 24 Apr 2017
    5.3
    Medium

    CVE-2017-8104

    Last Modified: 20 Apr 2025

    In MyBB before 1.8.11, the smilie module allows Directory Traversal via the pathfolder parameter.

    Published: 24 Apr 2017
    6.1
    Medium

    CVE-2017-5191

    Last Modified: 20 Apr 2025

    An XSS vulnerability on the /NAGErrors URI in NetIQ Access Manager 4.2 and 4.3 exists because Access Gateway Error pages do not validate the HTTP Referer header.

    Published: 24 Apr 2017
    5.4
    Medium

    CVE-2017-8102

    Last Modified: 20 Apr 2025

    Stored XSS in Serendipity v2.1-rc1 allows an attacker to steal an admin's cookie and other information by composing a new entry as an editor user. This is related to lack of the serendipity_event_xsstrust plugin and a set_config error in that plugin.

    Published: 24 Apr 2017
    6.1
    Medium

    CVE-2017-8103

    Last Modified: 20 Apr 2025

    In MyBB before 1.8.11, the Email MyCode component allows XSS, as demonstrated by an onmouseover event.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2017-2313

    Last Modified: 20 Apr 2025

    Juniper Networks devices running affected Junos OS versions may be impacted by the receipt of a crafted BGP UPDATE which can lead to an rpd (routing process daemon) crash and restart. Repeated crashes of the rpd daemon can result in an extended denial of service condition. The affected Junos OS versions are: 15.1 prior to 15.1F2-S15, 15.1F5-S7, 15.1F6-S5, 15.1F7, 15.1R4-S7, 15.1R5-S2, 15.1R6; 15.1X49 prior to 15.1X49-D78, 15.1X49-D80; 15.1X53 prior to 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 prior to 16.1R3-S3, 16.1R4; 16.2 prior to 16.2R1-S3, 16.2R2; Releases prior to Junos OS 15.1 are unaffected by this vulnerability. 17.1R1, 17.2R1, and all subsequent releases have a resolution for this vulnerability.

    Published: 24 Apr 2017
    10
    Critical

    CVE-2017-2320

    Last Modified: 20 Apr 2025

    A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various denials of services leading to targeted information disclosure, modification of any component of the NorthStar system, including managed systems, and full denial of services to any systems under management which NorthStar interacts with using read-only or read-write credentials.

    Published: 24 Apr 2017
    5.5
    Medium

    CVE-2017-2327

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to consume large amounts of system resources leading to a cascading denial of services.

    Published: 24 Apr 2017
    5.3
    Medium

    CVE-2017-2340

    Last Modified: 20 Apr 2025

    On Juniper Networks Junos OS 15.1 releases from 15.1R3 to 15.1R4, 16.1 prior to 16.1R3, on M/MX platforms where Enhanced Subscriber Management for DHCPv6 subscribers is configured, a vulnerability in processing IPv6 ND packets originating from subscribers and destined to M/MX series routers can result in a PFE (Packet Forwarding Engine) hang or crash.

    Published: 24 Apr 2017
    8.3
    High

    CVE-2017-2319

    Last Modified: 20 Apr 2025

    A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker to compromise the systems confidentiality or integrity without authentication, leading to managed systems being compromised or services being denied to authentic end users and systems as a result.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2017-2315

    Last Modified: 20 Apr 2025

    On Juniper Networks EX Series Ethernet Switches running affected Junos OS versions, a vulnerability in IPv6 processing has been discovered that may allow a specially crafted IPv6 Neighbor Discovery (ND) packet destined to an EX Series Ethernet Switch to cause a slow memory leak. A malicious network-based packet flood of these crafted IPv6 NDP packets may eventually lead to resource exhaustion and a denial of service. The affected Junos OS versions are: 12.3 prior to 12.3R12-S4, 12.3R13; 13.3 prior to 13.3R10; 14.1 prior to 14.1R8-S3, 14.1R9; 14.1X53 prior ro 14.1X53-D12, 14.1X53-D40; 14.1X55 prior to 14.1X55-D35; 14.2 prior to 14.2R6-S4, 14.2R7-S6, 14.2R8; 15.1 prior to 15.1R5; 16.1 before 16.1R3; 16.2 before 16.2R1-S3, 16.2R2. 17.1R1 and all subsequent releases have a resolution for this vulnerability.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-2316

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.

    Published: 24 Apr 2017
    8.6
    High

    CVE-2017-2317

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause denials of services to underlying database tables leading to potential information disclosure, modification of system states, and partial to full denial of services relying upon data modified by an attacker.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-2318

    Last Modified: 20 Apr 2025

    A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to read log files which will compromise the integrity of the system, or provide elevation of privileges.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2017-2323

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious attacker crafting packets destined to the device to cause a persistent denial of service to the path computation server service.

    Published: 24 Apr 2017
    5.3
    Medium

    CVE-2017-2324

    Last Modified: 20 Apr 2025

    A command injection vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to cause a denial of service condition.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-2325

    Last Modified: 20 Apr 2025

    A buffer overflow vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an authenticated malicious user to cause a buffer overflow leading to a denial of service.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-2326

    Last Modified: 20 Apr 2025

    An information disclosure vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, network-based attacker to replicate the underlying Junos OS VM and all data it maintains to their local system for future analysis.

    Published: 24 Apr 2017
    6.2
    Medium

    CVE-2017-2329

    Last Modified: 20 Apr 2025

    An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to execute certain specific unprivileged system files capable of causing widespread denials of system services.

    Published: 24 Apr 2017
    7.3
    High

    CVE-2017-2331

    Last Modified: 20 Apr 2025

    A firewall bypass vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to bypass firewall policies, leading to authentication bypass methods, information disclosure, modification of system files, and denials of service.

    Published: 24 Apr 2017
    8.8
    High

    CVE-2017-2332

    Last Modified: 20 Apr 2025

    An insufficient authentication vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network based, unauthenticated attacker to perform privileged actions to gain complete control over the environment.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-2333

    Last Modified: 20 Apr 2025

    A persistent denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a malicious, network-based, authenticated attacker to consume enough system resources to cause a persistent denial of service by visiting certain specific URLs on the server.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2017-2312

    Last Modified: 20 Apr 2025

    On Juniper Networks devices running Junos OS affected versions and with LDP enabled, a specific LDP packet destined to the RE (Routing Engine) will consume a small amount of the memory allocated for the rpd (routing protocol daemon) process. Over time, repeatedly receiving this type of LDP packet(s) will cause the memory to exhaust and the rpd process to crash and restart. It is not possible to free up the memory that has been consumed without restarting the rpd process. This issue affects Junos OS based devices with either IPv4 or IPv6 LDP enabled via the [protocols ldp] configuration (the native IPv6 support for LDP is available in Junos OS 16.1 and higher). The interface on which the packet arrives needs to have LDP enabled. The affected Junos versions are: 13.3 prior to 13.3R10; 14.1 prior to 14.1R8; 14.2 prior to 14.2R7-S6 or 14.2R8; 15.1 prior to 15.1F2-S14, 15.1F6-S4, 15.1F7, 15.1R4-S7, 15.1R5; 15.1X49 before 15.1X49-D70; 15.1X53 before 15.1X53-D230, 15.1X53-D63, 15.1X53-D70; 16.1 before 16.1R2. 16.2R1 and all subsequent releases have a resolution for this vulnerability.

    Published: 24 Apr 2017
    8.6
    High

    CVE-2017-2321

    Last Modified: 20 Apr 2025

    A vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, unprivileged, network-based attacker to cause various system services partial to full denials of services, modification of system states and files, and potential disclosure of sensitive information which may assist the attacker in further attacks on the system through the use of multiple attack vectors, including man-in-the-middle attacks, file injections, and malicious execution of commands causing out of bound memory conditions leading to other attacks.

    Published: 24 Apr 2017
    5.5
    Medium

    CVE-2017-2328

    Last Modified: 20 Apr 2025

    An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unprivileged, authenticated, user to elevate their permissions through reading unprivileged information stored in the NorthStar controller.

    Published: 24 Apr 2017
    6.2
    Medium

    CVE-2017-2330

    Last Modified: 20 Apr 2025

    A denial of service vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow an unauthenticated, local user, to create a fork bomb scenario, also known as a rabbit virus, or wabbit, which will create processes that replicate themselves, until all resources are consumed on the system, leading to a denial of service to the entire system until it is restarted. Continued attacks by an unauthenticated, local user, can lead to persistent denials of services.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2017-2334

    Last Modified: 20 Apr 2025

    An information leak vulnerability in Juniper Networks NorthStar Controller Application prior to version 2.1.0 Service Pack 1 may allow a network-based malicious attacker to perform a man-in-the-middle attack, thereby stealing authentic credentials from encrypted paths which are easily decrypted, and subsequently gain complete control of the system.

    Published: 24 Apr 2017
    6.1
    Medium

    CVE-2017-8085

    Last Modified: 20 Apr 2025

    In Exponent CMS before 2.4.1 Patch #5, XSS in elFinder is possible in framework/modules/file/connector/elfinder.php.

    Published: 24 Apr 2017
    6.1
    Medium

    CVE-2017-7944

    Last Modified: 20 Apr 2025

    XOOPS Core 2.5.8.1 has XSS due to unescaped HTML output of an Install DB failure error message in page_dbsettings.php.

    Published: 24 Apr 2017
    8.8
    High

    CVE-2017-7852

    Last Modified: 20 Apr 2025

    D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the 'allow-access-from domain' child element set to *, thus accepting requests from any domain. If a victim logged into the camera's web console visits a malicious site hosting a malicious Flash file from another Browser tab, the malicious Flash file then can send requests to the victim's DCS series Camera without knowing the credentials. An attacker can host a malicious Flash file that can retrieve Live Feeds or information from the victim's DCS series Camera, add new admin users, or make other changes to the device. Known affected devices are DCS-933L with firmware before 1.13.05, DCS-5030L, DCS-5020L, DCS-2530L, DCS-2630L, DCS-930L, DCS-932L, and DCS-932LB1.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2015-1521

    Last Modified: 20 Apr 2025

    analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not properly handle zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overflow or buffer over-read if NDEBUG; otherwise assertion failure) via a crafted DNP3 packet.

    Published: 24 Apr 2017
    8.8
    High

    CVE-2015-0104

    Last Modified: 20 Apr 2025

    IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to execute arbitrary code via unspecified vectors.

    Published: 24 Apr 2017
    7.5
    High

    CVE-2015-1522

    Last Modified: 20 Apr 2025

    analyzer/protocol/dnp3/DNP3.cc in Bro before 2.3.2 does not reject certain non-zero values of a packet length, which allows remote attackers to cause a denial of service (buffer overflow or buffer over-read) via a crafted DNP3 packet.

    Published: 24 Apr 2017
    6.5
    Medium

    CVE-2015-0107

    Last Modified: 20 Apr 2025

    IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Solutions 7.1 through 7.1.1.8, 7.5 before 7.5.0.7 IFIX003, and 7.6 before 7.6.0.0 IFIX002 allow remote authenticated users to conduct directory traversal attacks via unspecified vectors.

    Published: 24 Apr 2017
    7
    High

    CVE-2015-8109

    Last Modified: 20 Apr 2025

    Lenovo System Update (formerly ThinkVantage System Update) before 5.07.0019 allows local users to gain privileges by making a prediction of tvsu_tmp_xxxxxXXXXX account credentials that requires knowledge of the time that this account was created, aka a "temporary administrator account vulnerability."

    Published: 24 Apr 2017