Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-16876 2 Fedoraproject, Mistune Project 2 Fedora, Mistune 2018-01-10 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in the _keyify function in mistune.py in Mistune before 0.8.1 allows remote attackers to inject arbitrary web script or HTML by leveraging failure to escape the "key" argument.
CVE-2017-16768 1 Synology 1 Mailplus Server 2018-01-10 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in User Policy editor in Synology MailPlus Server before 1.4.0-0415 allows remote authenticated users to inject arbitrary HTML via the name parameter.
CVE-2016-3695 2 Linux, Redhat 2 Linux Kernel, Enterprise Linux 2018-01-10 2.1 LOW 5.5 MEDIUM
The einj_error_inject function in drivers/acpi/apei/einj.c in the Linux kernel allows local users to simulate hardware errors and consequently cause a denial of service by leveraging failure to disable APEI error injection through EINJ when securelevel is set.
CVE-2017-17937 1 Vanguard Project 1 Marketplace Digital Products Php 2018-01-10 4.3 MEDIUM 6.1 MEDIUM
Vanguard Marketplace Digital Products PHP has XSS via the phps_query parameter to /search.
CVE-2017-17929 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Professional Service Script has XSS via the admin/bannerview.php view parameter.
CVE-2017-17925 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Professional Service Script has XSS via the admin/general_settingupd.php website_title parameter.
CVE-2017-17924 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 5.0 MEDIUM 5.3 MEDIUM
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via the id parameter to admin/review_userwise.php.
CVE-2017-17926 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 5.0 MEDIUM 5.3 MEDIUM
PHP Scripts Mall Professional Service Script has a predicable registration URL, which makes it easier for remote attackers to register with an invalid or spoofed e-mail address.
CVE-2017-17927 1 Ordermanagementscript 1 Professional Service Script 2018-01-10 5.0 MEDIUM 5.3 MEDIUM
PHP Scripts Mall Professional Service Script allows remote attackers to obtain sensitive full-path information via a crafted PATH_INFO to service-list/category/.
CVE-2017-10907 1 Spiqe 1 Onethird Cms Show Off 2018-01-09 4.0 MEDIUM 4.3 MEDIUM
Directory traversal vulnerability in OneThird CMS Show Off v1.85 and earlier. Show Off v1.85 en and earlier allows an attacker to read arbitrary files via unspecified vectors.
CVE-2017-17988 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_add.php event_title parameter.
CVE-2017-17985 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/state_view.php cou_id parameter.
CVE-2017-17984 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/event_edit.php edit_id parameter.
CVE-2017-17986 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/caste_view.php comm_id parameter.
CVE-2017-17982 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 6.0 MEDIUM 6.8 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has CSRF via admin/subadmin_edit.php.
CVE-2017-17981 1 Muslim Matrimonial Script Project 1 Muslim Matrimonial Script 2018-01-09 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.
CVE-2017-17940 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Single Theater Booking has XSS via the title parameter to admin/sitesettings.php.
CVE-2017-17938 1 Single Theater Booking Script Project 1 Single Theater Booking Script 2018-01-09 3.5 LOW 4.8 MEDIUM
PHP Scripts Mall Single Theater Booking has XSS via the admin/viewtheatre.php theatreid parameter.
CVE-2017-17904 1 Fortunescripts 1 Lynda Clone 2018-01-09 3.5 LOW 5.4 MEDIUM
FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_profile.
CVE-2017-17893 1 Readymade Video Sharing Script Project 1 Readymade Video Sharing Script 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
Readymade Video Sharing Script has XSS via the search_video.php search parameter, the viewsubs.php chnlid parameter, or the user-profile-edit.php fname parameter.
CVE-2017-17868 1 Liferay 1 Liferay Portal 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
In Liferay Portal 6.1.0, the tags section has XSS via a Public Render Parameter (p_r_p) value, as demonstrated by p_r_p_564233524_tag.
CVE-2017-17907 1 Car Rental Script Project 1 Car Rental Script 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
PHP Scripts Mall Car Rental Script has XSS via the admin/areaedit.php carid parameter or the admin/sitesettings.php websitename parameter.
CVE-2017-1698 1 Ibm 1 Websphere Portal 2018-01-09 5.0 MEDIUM 5.3 MEDIUM
IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 could reveal sensitive information from an error message that could lead to further attacks against the system. IBM X-Force ID: 124390.
CVE-2017-17896 1 Basic Job Site Script Project 1 Basic Job Site Script 2018-01-09 4.3 MEDIUM 6.1 MEDIUM
Readymade Job Site Script has XSS via the keyword parameter to the /job URI.
CVE-2017-15322 1 Huawei 2 Baggio-l03a, Baggio-l03a Firmware 2018-01-09 3.3 LOW 6.5 MEDIUM
Some Huawei smartphones with software of BGO-L03C158B003CUSTC158D001 and BGO-L03C331B009CUSTC331D001 have a DoS vulnerability due to insufficient input validation. An attacker could exploit this vulnerability by sending specially crafted NFC messages to the target device. Successful exploit could make a service crash.
CVE-2017-17995 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.
CVE-2017-17994 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria request.
CVE-2017-17993 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction request.
CVE-2017-17991 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.
CVE-2017-17989 1 Iwcnetwork 1 Biometric Shift Employee Management System 2018-01-09 3.5 LOW 5.4 MEDIUM
Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.
CVE-2017-15939 1 Gnu 1 Binutils 2018-01-09 4.3 MEDIUM 5.5 MEDIUM
dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, mishandles NULL files in a .debug_line file table, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename. NOTE: this issue is caused by an incomplete fix for CVE-2017-15023.
CVE-2017-7224 1 Gnu 1 Binutils 2018-01-09 4.3 MEDIUM 5.5 MEDIUM
The find_nearest_line function in objdump in GNU Binutils 2.28 is vulnerable to an invalid write (of size 1) while disassembling a corrupt binary that contains an empty function name, leading to a program crash.
CVE-2017-15023 1 Gnu 1 Binutils 2018-01-09 4.3 MEDIUM 5.5 MEDIUM
read_formatted_entries in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, does not properly validate the format count, which allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted ELF file, related to concat_filename.
CVE-2017-11552 1 Underbit 1 Mad Libmad 2018-01-09 4.3 MEDIUM 6.5 MEDIUM
mpg321.c in mpg321 0.3.2-1 does not properly manage memory for use with libmad 0.15.1b, which allows remote attackers to cause a denial of service (memory corruption seen in a crash in the mad_decoder_run function in decoder.c in libmad) via a crafted MP3 file.
CVE-2017-7210 1 Gnu 1 Binutils 2018-01-09 4.3 MEDIUM 5.5 MEDIUM
objdump in GNU Binutils 2.28 is vulnerable to multiple heap-based buffer over-reads (of size 1 and size 8) while handling corrupt STABS enum type strings in a crafted object file, leading to program crash.
CVE-2017-7209 1 Gnu 1 Binutils 2018-01-09 4.3 MEDIUM 5.5 MEDIUM
The dump_section_as_bytes function in readelf in GNU Binutils 2.28 accesses a NULL pointer while reading section contents in a corrupt binary, leading to a program crash.
CVE-2017-17744 1 Webdesi9 1 Custom Map 2018-01-08 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the custom-map plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the map_id parameter to view/advancedsettings.php.
CVE-2017-17719 1 Olyos 1 Wp-concours 2018-01-08 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the wp-concours plugin through 1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the result_message parameter to includes/concours_page.php.
CVE-2017-17752 1 Codecrafters 1 Ability Mail Server 2018-01-08 4.3 MEDIUM 6.1 MEDIUM
Ability Mail Server 3.3.2 has Cross Site Scripting (XSS) via the body of an e-mail message, with JavaScript code executed on the Read Mail screen (aka the /_readmail URI). This is fixed in version 4.2.4.
CVE-2017-16786 1 Meinbergglobal 10 Lantime Firmware, Lantime M100, Lantime M1000 and 7 more 2018-01-08 6.8 MEDIUM 6.5 MEDIUM
The Web Configuration Utility in Meinberg LANTIME devices with firmware before 6.24.004 allows remote authenticated users with certain privileges to read arbitrary files via (1) the ntpclientcounterlogfile parameter to cgi-bin/mainv2 or (2) vectors involving curl support of the "file" schema in the firmware update functionality.
CVE-2017-0304 1 F5 1 Big-ip Advanced Firewall Manager 2018-01-08 5.5 MEDIUM 5.4 MEDIUM
A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0.0 that may allow a copy of the firewall rules to be tampered with and impact the Configuration Utility until there is a resync of the rules. Traffic processing and the live firewall rules in use are not affected.
CVE-2017-16534 1 Linux 1 Linux Kernel 2018-01-06 7.2 HIGH 6.6 MEDIUM
The cdc_parse_cdc_header function in drivers/usb/core/message.c in the Linux kernel before 4.13.6 allows local users to cause a denial of service (out-of-bounds read and system crash) or possibly have unspecified other impact via a crafted USB device.
CVE-2017-1751 1 Ibm 1 Robotic Process Automation With Automation Anywhere 2018-01-05 3.5 LOW 5.4 MEDIUM
IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 135546.
CVE-2011-4955 1 Bsuite Project 1 Bsuite 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in ui_stats.php in the bSuite plugin before 5 alpha 3 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) s or (2) p parameters to index.php.
CVE-2017-17745 1 Tp-link 2 Tl-sg108e, Tl-sg108e Firmware 2018-01-05 3.5 LOW 5.4 MEDIUM
Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote attackers to submit arbitrary java script via the 'sysName' parameter.
CVE-2017-1423 1 Ibm 1 Websphere Portal 2018-01-05 5.0 MEDIUM 5.3 MEDIUM
IBM WebSphere Portal 8.5 and 9.0 exposes backend server URLs that are configured for usage by the Web Application Bridge component. IBM X-Force ID: 127476.
CVE-2017-17775 1 Piwigo 1 Piwigo 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Piwigo 2.9.2 has XSS via the name parameter in an admin.php?page=album-3-properties request.
CVE-2017-17753 1 Csv-import-export Project 1 Csv-import-export 2018-01-05 4.3 MEDIUM 6.1 MEDIUM
Multiple cross-site scripting (XSS) vulnerabilities in the esb-csv-import-export plugin through 1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) cie_type, (2) cie_import, (3) cie_update, or (4) cie_ignore parameter to includes/admin/views/esb-cie-import-export-page.php.
CVE-2017-15532 1 Symantec 1 Messaging Gateway 2018-01-05 5.5 MEDIUM 5.7 MEDIUM
Prior to 10.6.4, Symantec Messaging Gateway may be susceptible to a path traversal attack (also known as directory traversal). These types of attacks aim to access files and directories that are stored outside the web root folder. By manipulating variables, it may be possible to access arbitrary files and directories stored on the file system including application source code or configuration and critical system files.
CVE-2017-17718 1 Net-ldap Project 1 Net-ldap 2018-01-05 4.3 MEDIUM 5.9 MEDIUM
The Net::LDAP (aka net-ldap) gem before 0.16.0 for Ruby has Missing SSL Certificate Validation.