Search

Found 4,137 results in 1167ms · Match type: Filtered list

0
KEVHas exploit
Reset
CVE Severity CVSS Risk Flags OS Vendor Published Description
CVE-2017-8926 high 7.8 8.8 EXP halliburton 9y ago Buffer overflow in Halliburton LogView Pro 10.0.1 allows attackers to cause a denial of service or possibly have unspecified other impact via a crafted .tif file.
CVE-2017-7478 high 7.5 8.5 EXPFIX arch archdebian debian openvpn 9y ago OpenVPN version 2.3.12 and newer is vulnerable to unauthenticated Denial of Service of server via received large control packet. Note that this issue is fixed in 2.3.15 and 2.4.2.
CVE-2017-8928 high 8.8 9.8 EXP mailcow 9y ago mailcow 0.14, as used in "mailcow: dockerized" and other products, has CSRF.
CVE-2016-10277 high 7.8 8.8 EXP linux-kernel 9y ago An elevation of privilege vulnerability in the Motorola bootloader could enable a local malicious application to execute arbitrary code within the context of the bootloader. This issue is rated as Cr…
CVE-2017-0214 high 7.0 8.0 EXP windows windows 9y ago Windows COM in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and R2, Windows RT 8.1, Windows 10 Gold, 1511, 1607, and 1703, and Windows Server 201…
CVE-2017-8912 high 7.2 8.2 EXP cmsmadesimple 9y ago CMS Made Simple (CMSMS) 2.1.6 allows remote authenticated administrators to execute arbitrary PHP code via the code parameter to admin/editusertag.php, related to the CreateTagFunction and CallUserTa…
CVE-2017-8798 critical 9.8 10.0 EXPFIX arch archdebian debian miniupnp_project 9y ago Integer signedness error in MiniUPnP MiniUPnPc v1.4.20101221 through v2.0 allows remote attackers to cause a denial of service or possibly have unspecified other impact.
CVE-2017-8895 critical 9.8 10.0 EXP veritas 9y ago In Veritas Backup Exec 2014 before build 14.1.1187.1126, 15 before build 14.2.1180.3160, and 16 before FP1, there is a use-after-free vulnerability in multiple agents that can lead to a denial of ser…
CVE-2017-8852 high 7.8 8.8 EXP sap 9y ago SAP SAPCAR 721.510 has a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted CAR archive file received from an untrusted remote source. The problem is that the length of da…
CVE-2017-3068 high 8.8 9.8 EXP slesmacos macos linux-kernel adobe 9y ago Adobe Flash Player versions 25.0.0.148 and earlier have an exploitable memory corruption vulnerability in the Advanced Video Coding engine. Successful exploitation could lead to arbitrary code execut…
CVE-2017-0290 high 7.8 8.8 EXP windows windows microsoft 9y ago The Microsoft Malware Protection Engine running on Microsoft Forefront and Microsoft Defender on Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1, Windows Server 2012 Gold and…
CVE-2017-6953 high 7.8 8.8 EXP gemalto 9y ago Gemalto SmartDiag Diagnosis Tool v2.5 has a stack-based Buffer Overflow with SEH Overwrite via long "Register a new card" input fields. There may be a risk of local code execution with untrusted inpu…
CVE-2017-3730 high 7.5 8.5 EXPFIX slesdebian debian openssloracle 9y ago In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a …
CVE-2016-7054 high 7.5 8.5 EXPFIX arch archdebian debian openssl 9y ago In OpenSSL 1.1.0 before 1.1.0c, TLS connections using *-CHACHA20-POLY1305 ciphersuites are susceptible to a DoS attack by corrupting larger payloads. This can result in an OpenSSL crash. This issue i…
CVE-2017-8779 high 7.5 8.5 EXPFIX arch arch slesdebian debian rpcbind_projectlibtirpc_projectntirpc_project 9y ago denial of service in rpcbind
CVE-2015-8257 high 8.8 9.8 EXP 9y ago The devtools.sh script in AXIS network cameras allows remote authenticated users to execute arbitrary commands via shell metacharacters in the app parameter to (1) app_license.shtml, (2) app_license_…
CVE-2017-7981 high 8.8 9.8 EXP enaleanphpwiki_project 9y ago Tuleap before 9.7 allows command injection via the PhpWiki 1.3.10 SyntaxHighlighter plugin. This occurs in the Project Wiki component because the proc_open PHP function is used within PhpWiki before …
CVE-2017-6553 critical 9.8 10.0 EXP quest 9y ago Buffer Overflow in Quest One Identity Privilege Manager for Unix before 6.0.0.061 allows remote attackers to obtain full access to the policy server via an ACT_ALERT_EVENT request that causes memory …
CVE-2017-5135 critical 9.1 10.0 EXP 9y ago Certain Technicolor devices have an SNMP access-control bypass, possibly involving an ISP customization in some cases. The Technicolor (formerly Cisco) DPC3928SL with firmware D3928SL-P15-13-A386-c34…
CVE-2017-7293 high 7.8 8.8 EXP dolby 9y ago The Dolby DAX2 and DAX3 API services are vulnerable to a privilege escalation vulnerability that allows a normal user to get arbitrary system privileges, because these services have .NET code for DCO…
CVE-2017-8225 critical 9.8 10.0 EXP 9y ago On Wireless IP Camera (P2P) WIFICAM devices, access to .ini files (containing credentials) is not correctly checked. An attacker can bypass authentication by providing an empty loginuse parameter and…
CVE-2017-8224 critical 9.8 10.0 EXP 9y ago Wireless IP Camera (P2P) WIFICAM devices have a backdoor root account that can be accessed with TELNET.
CVE-2017-8223 high 7.5 8.5 EXP 9y ago On Wireless IP Camera (P2P) WIFICAM devices, an attacker can use the RTSP server on port 10554/tcp to watch the streaming without authentication via tcp/av0_1 or tcp/av0_0.
CVE-2017-8222 high 7.5 8.5 EXP 9y ago Wireless IP Camera (P2P) WIFICAM devices have an "Apple Production IOS Push Services" private RSA key and certificate stored in /system/www/pem/ck.pem inside the firmware, which allows attackers to o…
CVE-2017-8221 high 7.5 8.5 EXP 9y ago Wireless IP Camera (P2P) WIFICAM devices rely on a cleartext UDP tunnel protocol (aka the Cloud feature) for communication between an Android application and a camera device, which allows remote atta…
CVE-2017-1274 high 8.8 9.8 EXP ibm 9y ago IBM Domino 8.5.3, and 9.0 is vulnerable to a stack based overflow in the IMAP service that could allow an authenticated attacker to execute arbitrary code by specifying a large mailbox name. IBM X-Fo…
CVE-2017-7221 high 8.8 9.8 EXP opentext 9y ago OpenText Documentum Content Server has an inadequate protection mechanism against SQL injection, which allows remote authenticated users to execute arbitrary code with super-user privileges by levera…
CVE-2017-3623 critical 10.0 10.0 EXP 9y ago Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Kernel RPC). For supported versions that are affected see note. Easily "exploitable" vulnerability allows un…
CVE-2017-3622 high 7.8 8.8 EXP 9y ago Vulnerability in the Solaris component of Oracle Sun Systems Products Suite (subcomponent: Common Desktop Environment (CDE)). The supported version that is affected is 10. Easily "exploitable" vulner…
CVE-2017-3599 high 7.5 8.5 EXP sles oracle 9y ago Vulnerability in the MySQL Server component of Oracle MySQL (subcomponent: Server: Pluggable Auth). Supported versions that are affected are 5.6.35 and earlier and 5.7.17 and earlier. Easily "exploit…
CVE-2017-3587 high 8.4 9.4 EXPFIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Shared Folder). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "explo…
CVE-2017-3576 high 8.8 9.8 EXPFIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v…
CVE-2017-3575 high 7.9 8.9 EXPFIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v…
CVE-2017-3563 high 8.8 9.8 EXPFIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v…
CVE-2017-3561 high 8.8 9.8 EXPFIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v…
CVE-2017-3558 high 8.5 9.5 EXPFIX debian debian oracle 9y ago Vulnerability in the Oracle VM VirtualBox component of Oracle Virtualization (subcomponent: Core). Supported versions that are affected are Prior to 5.0.38 and Prior to 5.1.20. Easily "exploitable" v…
CVE-2017-3549 critical 9.1 10.0 EXP oracle 9y ago Vulnerability in the Oracle Scripting component of Oracle E-Business Suite (subcomponent: Scripting Administration). Supported versions that are affected are 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, 1…
CVE-2016-4313 high 7.8 8.8 EXP extplorer 9y ago Directory traversal vulnerability in unzip/extract feature in eXtplorer 2.1.9 allows remote attackers to execute arbitrary files via a .. (dot dot) in an archive file.
CVE-2015-7570 high 7.2 8.2 EXP yeager 9y ago Multiple server-side request forgery (SSRF) vulnerabilities in Yeager CMS 1.2.1 allow remote attackers to trigger outbound requests and enumerate open ports via the dbhost parameter to libs/org/adodb…
CVE-2015-7569 high 8.8 9.8 EXP yeager 9y ago SQL injection vulnerability in "yeager/y.php/tab_USERLIST" in Yeager CMS 1.2.1 allows local users to execute arbitrary SQL commands via the "pagedir_orderby" parameter.
CVE-2015-7568 critical 9.8 10.0 EXP yeager 9y ago SQL injection vulnerability in the password recovery feature in Yeager CMS 1.2.1 allows remote attackers to change the account credentials of known users via the "userEmail" parameter.
CVE-2015-7247 critical 9.8 10.0 EXP 9y ago D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 discloses usernames, passwords, keys, values, and web account hashes (super and admin) in plaintext when running a configuration…
CVE-2015-7246 critical 9.8 10.0 EXP 9y ago D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 has a default password of root for the root account and tw for the tw account, which makes it easier for remote attackers to obt…
CVE-2015-7245 high 7.5 8.5 EXP 9y ago Directory traversal vulnerability in D-Link DVG-N5402SP with firmware W1000CN-00, W1000CN-03, or W2000EN-00 allows remote attackers to read sensitive information via a .. (dot dot) in the errorpage p…
CVE-2017-7852 high 8.8 9.8 EXP 9y ago D-Link DCS cameras have a weak/insecure CrossDomain.XML file that allows sites hosting malicious Flash objects to access and/or change the device's settings via a CSRF attack. This is because of the …
CVE-2015-0104 high 8.8 9.8 EXP ibm 9y ago IBM Tivoli IT Asset Management for IT, Tivoli Service Request Manager, and Change and Configuration Management Database 7.1 through 7.1.1.8 and 7.2 and Maximo Asset Management and Maximo Industry Sol…
CVE-2016-5399 high 7.8 8.8 EXP sles php 9y ago The bzread function in ext/bz2/bz2.c in PHP before 5.5.38, 5.6.x before 5.6.24, and 7.x before 7.0.9 allows remote attackers to cause a denial of service (out-of-bounds write) or execute arbitrary co…
CVE-2016-1561 high 7.5 8.5 EXP 9y ago ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a pri…
CVE-2016-1560 critical 9.8 10.0 EXP 9y ago ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote …
CVE-2017-8051 critical 9.8 10.0 EXP tenable 9y ago Tenable Appliance 3.5 - 4.4.0, and possibly prior versions, contains a flaw in the simpleupload.py script in the Web UI. Through the manipulation of the tns_appliance_session_user parameter, a remote…
CVE-2015-8285 high 7.5 8.5 EXP quickheal 9y ago The webssx.sys driver in QuickHeal 16.00 allows remote attackers to cause a denial of service.
CVE-2017-7692 high 8.8 9.8 EXP squirrelmail 9y ago SquirrelMail 1.4.22 (and other versions before 20170427_0200-SVN) allows post-authentication remote code execution via a sendmail.cf file that is mishandled in a popen call. It's possible to exploit …
CVE-2017-7615 high 8.8 9.8 EXP mantisbt 9y ago MantisBT allows arbitrary password reset
CVE-2017-7690 high 7.8 8.8 EXP proxifier 9y ago Proxifier for Mac before 2.19.2, when first run, allows local users to gain privileges by replacing the KLoader binary with a Trojan horse program.
CVE-2017-6554 high 7.2 8.2 EXP quest 9y ago pmmasterd in Quest Privilege Manager before 6.0.0.061, when configured as a policy server, allows remote attackers to write to arbitrary files and consequently execute arbitrary code with root privil…
CVE-2016-1713 high 7.3 8.3 EXP vtiger 9y ago Unrestricted file upload vulnerability in the Settings_Vtiger_CompanyDetailsSave_Action class in modules/Settings/Vtiger/actions/CompanyDetailsSave.php in Vtiger CRM 6.4.0 allows remote authenticated…
CVE-2016-0727 high 7.8 8.8 EXPFIX ubuntu ubuntudebian debian 9y ago The crontab script in the ntp package before 1:4.2.6.p3+dfsg-1ubuntu3.11 on Ubuntu 12.04 LTS, before 1:4.2.6.p5+dfsg-3ubuntu2.14.04.10 on Ubuntu 14.04 LTS, on Ubuntu Wily, and before 1:4.2.8p4+dfsg-3…
CVE-2015-6568 high 8.8 9.8 EXP wolfcms 9y ago Wolf CMS before 0.8.3.1 allows unrestricted file rename and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not prevent a change of a file extension to ".php" …
CVE-2015-6567 high 8.8 9.8 EXP wolfcms 9y ago Wolf CMS before 0.8.3.1 allows unrestricted file upload and PHP Code Execution because admin/plugin/file_manager/browse/ (aka the filemanager) does not validate the parameter "filename" properly. Exp…
CVE-2017-7643 high 7.8 8.8 EXP proxifier 9y ago Proxifier for Mac before 2.19 allows local users to gain privileges via the first parameter to the KLoader setuid program.
CVE-2017-7456 high 7.5 8.5 EXP moxa 9y ago Moxa MXView 2.8 allows remote attackers to cause a Denial of Service by sending overly long junk payload for the MXView client login credentials.
CVE-2017-7455 high 7.5 8.5 EXP moxa 9y ago Moxa MXView 2.8 allows remote attackers to read web server's private key file, no access control.
CVE-2015-8356 high 8.0 9.0 EXP bitrix_project 9y ago Multiple SQL injection vulnerabilities in the mcart.xls module 6.5.2 and earlier for Bitrix allow remote authenticated users to execute arbitrary SQL commands via the (1) xls_profile parameter to adm…
CVE-2016-2555 critical 9.8 10.0 EXP atutor 9y ago SQL injection vulnerability in include/lib/mysql_connect.inc.php in ATutor 2.2.1 allows remote attackers to execute arbitrary SQL commands via the searchFriends function to friends.inc.php.
CVE-2016-1914 high 8.8 9.8 EXP blackberry 9y ago Multiple SQL injection vulnerabilities in the com.rim.mdm.ui.server.ImageServlet servlet in BlackBerry Enterprise Server 12 (BES12) Self-Service before 12.4 allow remote attackers to execute arbitrar…
CVE-2015-8284 high 8.8 9.8 EXP seawell_networks 9y ago SeaWell Networks Spectrum SDC 02.05.00 allows remote viewer users to perform administrative functions.
CVE-2015-8282 critical 9.8 10.0 EXP seawell_networks 9y ago SeaWell Networks Spectrum SDC 02.05.00 has a default password of "admin" for the "admin" account.
CVE-2016-4337 critical 9.8 10.0 EXP ktools 9y ago SQL injection vulnerability in the mgr.login.php file in Ktools.net Photostore before 4.7.5 allows remote attackers to execute arbitrary SQL commands via the email parameter in a recover_login action.
CVE-2015-7564 critical 9.8 10.0 EXP teampass 9y ago TeamPass vulnerable to SQL Injection
CVE-2015-7563 high 8.8 9.8 EXP teampass 9y ago Cross-site request forgery (CSRF) vulnerability in TeamPass 2.1.24 and earlier allows remote attackers to hijack the authentication of an authenticated user.
CVE-2017-7722 critical 10.0 10.0 EXP solarwinds 9y ago In SolarWinds Log & Event Manager (LEM) before 6.3.1 Hotfix 4, a menu system is encountered when the SSH service is accessed with "cmc" and "password" (the default username and password). By exploiti…
CVE-2017-3064 high 7.8 8.8 EXP linux-kernelwindows windowsmacos macos adobe 9y ago Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability when parsing a shape outline. Successful exploitation could lead to arbitrary code execution.
CVE-2017-3061 critical 9.8 10.0 EXP linux-kernelwindows windowsmacos macos adobe 9y ago Adobe Flash Player versions 25.0.0.127 and earlier have an exploitable memory corruption vulnerability in the SWF parser. Successful exploitation could lead to arbitrary code execution.
CVE-2017-3006 high 8.8 9.8 EXP adobe 9y ago Adobe Thor versions 3.9.5.353 and earlier have a vulnerability related to the use of improper resource permissions during the installation of Creative Cloud desktop applications.
CVE-2017-0202 high 7.5 8.5 EXP microsoft 9y ago A remote code execution vulnerability exists when Internet Explorer improperly accesses objects in memory. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrar…
CVE-2017-0165 high 7.8 8.8 EXP windows windows 9y ago An elevation of privilege vulnerability exists when Microsoft Windows running on Windows 10, Windows 10 1511, Windows 8.1, Windows RT 8.1, and Windows Server 2012 R2 fails to properly sanitize handle…
CVE-2017-0160 high 7.8 8.8 EXP microsoft 9y ago Microsoft .NET Framework 2.0, 3.5, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allows an attacker with access to the local system to execute malicious code, aka ".NET Remote Code Execution Vulnerability."
CVE-2017-7588 critical 9.8 10.0 EXP 9y ago On certain Brother devices, authorization is mishandled by including a valid AuthCookie cookie in the HTTP response to a failed login attempt. Affected models are: MFC-J6973CDW MFC-J4420DW MFC-8710DW…
CVE-2016-7552 critical 9.8 10.0 EXP trendmicro 9y ago On the Trend Micro Threat Discovery Appliance 2.6.1062r1, directory traversal when processing a session_id cookie allows a remote, unauthenticated attacker to delete arbitrary files as root. This can…
CVE-2016-7547 critical 9.8 10.0 EXP trendmicro 9y ago A command execution flaw on the Trend Micro Threat Discovery Appliance 2.6.1062r1 exists with the timezone parameter in the admin_sys_time.cgi interface.
CVE-2015-7893 high 8.8 9.8 EXP 9y ago SecEmailUI in Samsung Galaxy S6 does not sanitize HTML email content, allows remote attackers to execute arbitrary JavaScript.
CVE-2017-6088 high 7.2 8.2 EXP eyesofnetwork 9y ago Multiple SQL injection vulnerabilities in EyesOfNetwork (aka EON) 5.0 and earlier allow remote authenticated users to execute arbitrary SQL commands via the (1) bp_name, (2) display, (3) search, or (…
CVE-2017-7462 critical 9.8 10.0 EXP 9y ago Intellinet NFC-30ir IP Camera has a vendor backdoor that can allow a remote attacker access to a vendor-supplied CGI script in the web directory.
CVE-2017-7185 high 7.5 8.5 EXP cesanta 9y ago Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows r…
CVE-2017-5607 low 3.5 4.5 EXP splunk 9y ago Splunk Enterprise 5.0.x before 5.0.18, 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.13.1, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3 and Splunk Light before 6.5.2 a…
CVE-2017-6190 high 7.5 8.5 EXP 9y ago Directory traversal vulnerability in the web interface on the D-Link DWR-116 device with firmware before V1.05b09 allows remote attackers to read arbitrary files via a .. (dot dot) in a "GET /uir/" r…
CVE-2015-8258 high 7.5 8.5 EXP 9y ago AXIS Communications products with firmware through 5.80.x allow remote attackers to modify arbitrary files as root via vectors involving Open Script Editor, aka a "resource injection vulnerability."
CVE-2015-8255 high 8.8 9.8 EXP 9y ago AXIS Communications products allow CSRF, as demonstrated by admin/pwdgrp.cgi, vaconfig.cgi, and admin/local_del.cgi.
CVE-2017-6019 high 7.5 8.5 EXP 9y ago An issue was discovered in Schneider Electric Conext ComBox, model 865-1058, all firmware versions prior to V3.03 BN 830. A series of rapid requests to the device may cause it to reboot.
CVE-2017-0569 high 7.0 8.0 EXP linux-kernel 9y ago An elevation of privilege vulnerability in the Broadcom Wi-Fi driver could enable a local malicious application to execute arbitrary code within the context of the kernel. This issue is rated as High…
CVE-2017-0561 critical 9.8 10.0 EXPFIX debian debian linux-kernel 9y ago A remote code execution vulnerability in the Broadcom Wi-Fi firmware could enable a remote attacker to execute arbitrary code within the context of the Wi-Fi SoC. This issue is rated as Critical due …
CVE-2016-7786 high 8.8 9.8 EXP 9y ago Sophos Cyberoam UTM CR25iNG 10.6.3 MR-5 allows remote authenticated users to bypass intended access restrictions via direct object reference, as demonstrated by a request for Licenseinformation.jsp. …
CVE-2017-7581 critical 9.8 10.0 EXP news_system_project 9y ago SQL injection vulnerability in NewsController.php in the News module 5.3.2 and earlier for TYPO3 allows unauthenticated users to execute arbitrary SQL commands via vectors involving overwriteDemand f…
CVE-2017-7571 high 8.0 9.0 EXP ladybirdweb 9y ago public/rolechangeadmin in Faveo 1.9.3 allows CSRF. The impact is obtaining admin privileges.
CVE-2017-7237 critical 9.8 10.0 EXP spiceworks 9y ago The Spiceworks TFTP Server, as distributed with Spiceworks Inventory 7.5, allows remote attackers to access the Spiceworks data\configurations directory by leveraging the unauthenticated nature of th…
CVE-2017-7447 high 8.8 9.8 EXP helpdezk 9y ago HelpDEZk 1.1.1 has CSRF in admin/home#/logos/ with an impact of remote execution of arbitrary PHP code.
CVE-2017-7446 high 8.8 9.8 EXP helpdezk 9y ago HelpDEZk 1.1.1 has CSRF in admin/home#/person/ with an impact of obtaining admin privileges.
CVE-2016-9091 high 7.2 8.2 EXP bluecoat 9y ago Blue Coat Advanced Secure Gateway (ASG) 6.6 before 6.6.5.4 and Content Analysis System (CAS) 1.3 before 1.3.7.4 are susceptible to an OS command injection vulnerability. An authenticated malicious ad…
CVE-2017-7358 high 7.3 8.3 EXPFIX arch archdebian debianubuntu ubuntu lightdm_project 9y ago In LightDM through 1.22.0, a directory traversal issue in debian/guest-account.sh allows local attackers to own arbitrary directory path locations and escalate privileges to root when the guest user …
CVE-2017-7398 high 8.8 9.8 EXP 9y ago D-Link DIR-615 HW: T1 FW:20.09 is vulnerable to Cross-Site Request Forgery (CSRF) vulnerability. This enables an attacker to perform an unwanted action on a wireless router for which the user/admin i…