8.8
    High

    CVE-2017-14848

    Last Modified: 1 Oct 2017

    WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.

    Source:Ihsan Sencan
    Published:2 Oct 2017
    8.8
    High

    CVE-2017-14847

    Last Modified: 28 Sept 2017

    Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14846

    Last Modified: 28 Sept 2017

    Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14845

    Last Modified: 28 Sept 2017

    Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14844

    Last Modified: 28 Sept 2017

    Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14843

    Last Modified: 28 Sept 2017

    Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14842

    Last Modified: 28 Sept 2017

    Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    6.5
    Medium

    CVE-2017-14841

    Last Modified: 28 Sept 2017

    Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14840

    Last Modified: 28 Sept 2017

    TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14839

    Last Modified: 28 Sept 2017

    TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    8.8
    High

    CVE-2017-14838

    Last Modified: 28 Sept 2017

    TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.

    Source:Ihsan Sencan
    Published:27 Sept 2017
    7.3
    High

    CVE-2017-14798

    Last Modified: 13 Aug 2018

    A race condition in the postgresql init script could be used by attackers able to access the postgresql account to escalate their privileges to root.

    Source:Johannes Segitz
    Published:1 Mar 2018
    8.8
    High

    CVE-2017-14758

    Last Modified: 11 Oct 2017

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xAdmin/html/cm_doclist_view_uc.jsp, parameter: documentId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

    Source:Marcin Woloszyn
    Published:2 Oct 2017
    8.8
    High

    CVE-2017-14757

    Last Modified: 11 Oct 2017

    OpenText Document Sciences xPression (formerly EMC Document Sciences xPression) v4.5SP1 Patch 13 (older versions might be affected as well) is prone to SQL Injection: /xDashboard/html/jobhistory/downloadSupportFile.action, parameter: jobRunId. In order for this vulnerability to be exploited, an attacker must authenticate to the application first.

    Source:Marcin Woloszyn
    Published:2 Oct 2017
    9.8
    Critical

    CVE-2017-14738

    Last Modified: 30 Sept 2017

    FileRun (version 2017.09.18 and below) suffers from a remote SQL injection vulnerability due to a failure to sanitize input in the metafield parameter inside the metasearch module (under the search function).

    Source:SPARC
    Published:29 Sept 2017
    6.1
    Medium

    CVE-2017-14735

    Last Modified: 20 Apr 2025

    OWASP AntiSamy before 1.5.7 allows XSS via HTML5 entities, as demonstrated by use of : to construct a javascript: URL.

    Published:25 Sept 2017
    7.5
    High

    CVE-2017-14719

    Last Modified: 20 Apr 2025

    Before version 4.8.2, WordPress was vulnerable to a directory traversal attack during unzip operations in the ZipArchive and PclZip components.

    Published:23 Sept 2017
    5.4
    Medium

    CVE-2017-14717

    Last Modified: 4 Oct 2017

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Description parameter.

    Source:Zeeshan Shaikh
    Published:22 Sept 2017
    5.4
    Medium

    CVE-2017-14712

    Last Modified: 4 Oct 2017

    In EPESI 1.8.2 rev20170830, there is Stored XSS in the Tasks Phonecall Notes Title parameter.

    Source:Zeeshan Shaikh
    Published:22 Sept 2017
    8.8
    High

    CVE-2017-14704

    Last Modified: 24 Sept 2017

    Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file in images/profile.

    Source:Ihsan Sencan
    Published:26 Sept 2017
    9.8
    Critical

    CVE-2017-14703

    Last Modified: 24 Sept 2017

    SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.

    Source:Ihsan Sencan
    Published:26 Sept 2017
    9.8
    Critical

    CVE-2017-14702

    Last Modified: 4 Oct 2017

    ERS Data System 1.8.1.0 allows remote attackers to execute arbitrary code, related to "com.branaghgroup.ecers.update.UpdateRequest" object deserialization.

    Source:West Shepherd
    Published:29 Sept 2017
    7.5
    High

    CVE-2017-14680

    Last Modified: 20 Oct 2017

    ZKTeco ZKTime Web 2.0.1.12280 allows remote attackers to obtain sensitive employee metadata via a direct request for a PDF document.

    Source:Arvind V
    Published:21 Sept 2017
    7.8
    High

    CVE-2017-14627

    Last Modified: 13 Dec 2018

    Stack-based buffer overflows in CyberLink LabelPrint 2.5 allow remote attackers to execute arbitrary code via the (1) author (inside the INFORMATION tag), (2) name (inside the INFORMATION tag), (3) artist (inside the TRACK tag), or (4) default (inside the TEXT tag) parameter in an lpp project file.

    Source:Metasploit
    Published:23 Sept 2017
    6.1
    Medium

    CVE-2017-14620

    Last Modified: 1 Oct 2017

    SmarterStats Version 11.3.6347 will Render the Referer Field of HTTP Logfiles from URL /Data/Reports/ReferringURLsWithQueries resulting in Stored Cross Site Scripting.

    Source:sqlhacker
    Published:29 Sept 2017
    6.1
    Medium

    CVE-2017-14619

    Last Modified: 17 Nov 2017

    Cross-site scripting (XSS) vulnerability in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the "Title of your FAQ" field in the Configuration Module.

    Source:Ishaq Mohammed
    Published:20 Sept 2017
    4.8
    Medium

    CVE-2017-14618

    Last Modified: 17 Nov 2017

    Cross-site scripting (XSS) vulnerability in inc/PMF/Faq.php in phpMyFAQ through 2.9.8 allows remote attackers to inject arbitrary web script or HTML via the Questions field in an "Add New FAQ" action.

    Source:Ishaq Mohammed
    Published:20 Sept 2017
    6.5
    Medium

    CVE-2017-14537

    Last Modified: 28 May 2021

    trixbox 2.8.0.4 has path traversal via the xajaxargs array parameter to /maint/index.php?packages or the lang parameter to /maint/modules/home/index.php.

    Source:Ron Jost
    Published:16 Feb 2018
    8.8
    High

    CVE-2017-14535

    Last Modified: 28 May 2021

    trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.

    Source:Ron Jost
    Published:16 Feb 2018
    7.5
    High

    CVE-2017-14523

    Last Modified: 5 Feb 2018

    WonderCMS 2.3.1 is vulnerable to an HTTP Host header injection attack. It uses user-entered values to redirect pages. NOTE: the vendor reports that exploitation is unlikely because the attack can only come from a local machine or from the administrator as a self attack

    Source:Samrat Das
    Published:26 Jan 2018
    8.8
    High

    CVE-2017-14521

    Last Modified: 11 Sept 2018

    In WonderCMS 2.3.1, the upload functionality accepts random application extensions and leads to malicious File Upload.

    Source:Samrat Das
    Published:26 Jan 2018
    9.8
    Critical

    CVE-2017-14507

    Last Modified: 27 Sept 2017

    Multiple SQL injection vulnerabilities in the Content Timeline plugin 4.4.2 for WordPress allow remote attackers to execute arbitrary SQL commands via the (1) timeline parameter in content_timeline_class.php; or the id parameter to (2) pages/content_timeline_edit.php or (3) pages/content_timeline_index.php.

    Source:Jeroen - IT Nerdbox
    Published:28 Sept 2017
    7.5
    High

    CVE-2017-14496

    Last Modified: 2 Oct 2017

    Integer underflow in the add_pseudoheader function in dnsmasq before 2.78 , when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service via a crafted DNS request.

    Source:Google Security Research
    Published:2 Oct 2017
    7.5
    High

    CVE-2017-14495

    Last Modified: 2 Oct 2017

    Memory leak in dnsmasq before 2.78, when the --add-mac, --add-cpe-id or --add-subnet option is specified, allows remote attackers to cause a denial of service (memory consumption) via vectors involving DNS response creation.

    Source:Google Security Research
    Published:2 Oct 2017
    5.9
    Medium

    CVE-2017-14494

    Last Modified: 2 Oct 2017

    dnsmasq before 2.78, when configured as a relay, allows remote attackers to obtain sensitive memory information via vectors involving handling DHCPv6 forwarded requests.

    Source:Google Security Research
    Published:2 Oct 2017
    9.8
    Critical

    CVE-2017-14493

    Last Modified: 2 Oct 2017

    Stack-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DHCPv6 request.

    Source:Google Security Research
    Published:2 Oct 2017
    9.8
    Critical

    CVE-2017-14492

    Last Modified: 2 Oct 2017

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted IPv6 router advertisement request.

    Source:Google Security Research
    Published:2 Oct 2017
    9.8
    Critical

    CVE-2017-14491

    Last Modified: 2 Oct 2017

    Heap-based buffer overflow in dnsmasq before 2.78 allows remote attackers to cause a denial of service (crash) or execute arbitrary code via a crafted DNS response.

    Source:Google Security Research
    Published:2 Oct 2017
    5.5
    Medium

    CVE-2017-14489

    Last Modified: 7 Mar 2019

    The iscsi_if_rx function in drivers/scsi/scsi_transport_iscsi.c in the Linux kernel through 4.13.2 allows local users to cause a denial of service (panic) by leveraging incorrect length validation.

    Source:Wang Chenyu
    Published:27 Aug 2017
    10
    Critical

    CVE-2017-14459

    Last Modified: 3 Apr 2018

    An exploitable OS Command Injection vulnerability exists in the Telnet, SSH, and console login functionality of Moxa AWK-3131A Industrial IEEE 802.11a/b/g/n wireless AP/bridge/client in firmware versions 1.4 to 1.7 (current). An attacker can inject commands via the username parameter of several services (SSH, Telnet, console), resulting in remote, unauthenticated, root-level operating system command execution.

    Source:Talos
    Published:11 Apr 2018
    9.8
    Critical

    CVE-2017-14396

    Last Modified: 30 Mar 2018

    In osTicket before 1.10.1, SQL injection is possible by constructing an array via use of square brackets at the end of a parameter name, as demonstrated by the key parameter to file.php.

    Source:Mehmet Ince
    Published:12 Sept 2017
    7.8
    High

    CVE-2017-14355

    Last Modified: 23 Jan 2018

    A potential security vulnerability has been identified in HPE Connected Backup versions 8.6 and 8.8.6. The vulnerability could be exploited locally to allow escalation of privilege.

    Source:Peter Lapp
    Published:5 Dec 2017
    7.8
    High

    CVE-2017-14344

    Last Modified: 15 Sept 2017

    This vulnerability allows local attackers to escalate privileges on Jungo WinDriver 12.4.0 and earlier. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x95382673 by the windrvr1240 kernel driver. The issue lies in the failure to properly validate user-supplied data which can result in a kernel pool overflow. An attacker can leverage this vulnerability to execute arbitrary code under the context of kernel.

    Source:mr_me
    Published:12 Sept 2017
    7.5
    High

    CVE-2017-14335

    Last Modified: 15 Feb 2018

    On Beijing Hanbang Hanbanggaoke devices, because user-controlled input is not sufficiently sanitized, sending a PUT request to /ISAPI/Security/users/1 allows an admin password change.

    Source:SecuriTeam
    Published:12 Sept 2017
    9.8
    Critical

    CVE-2017-14322

    Last Modified: 24 Apr 2018

    The function in charge to check whether the user is already logged in init.php in Interspire Email Marketer (IEM) prior to 6.1.6 allows remote attackers to bypass authentication and obtain administrative access by using the IEM_CookieLogin cookie with a specially crafted value.

    Source:devcoinfet
    Published:18 Oct 2017
    7.8
    High

    CVE-2017-14311

    Last Modified: 17 Sept 2017

    The Winring0x32.sys driver in NetMechanica NetDecision 5.8.2 allows local users to gain privileges via a crafted 0x9C402088 IOCTL call.

    Source:Peter Baris
    Published:19 Sept 2017
    7.8
    High

    CVE-2017-14266

    Last Modified: 12 Sept 2017

    tcprewrite in Tcpreplay 3.4.4 has a Heap-Based Buffer Overflow vulnerability triggered by a crafted PCAP file, a related issue to CVE-2016-6160.

    Source:FarazPajohan
    Published:12 Sept 2017
    8.1
    High

    CVE-2017-14263

    Last Modified: 20 Apr 2025

    Honeywell NVR devices allow remote attackers to create a user account in the admin group by leveraging access to a guest account to obtain a session ID, and then sending that session ID in a userManager.addUser request to the /RPC2 URI. The attacker can login to the device with that new user account to fully control the device.

    Published:11 Sept 2017
    8.1
    High

    CVE-2017-14262

    Last Modified: 20 Apr 2025

    On Samsung NVR devices, remote attackers can read the MD5 password hash of the 'admin' account via certain szUserName JSON data to cgi-bin/main-cgi, and login to the device with that hash in the szUserPasswd parameter.

    Published:11 Sept 2017
    9.8
    Critical

    CVE-2017-14244

    Last Modified: 18 Sept 2017

    An authentication bypass vulnerability on iBall Baton ADSL2+ Home Router FW_iB-LR7011A_1.0.2 devices potentially allows attackers to directly access administrative router settings by crafting URLs with a .cgi extension, as demonstrated by /info.cgi and /password.cgi.

    Source:Gem George
    Published:17 Sept 2017