Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-1000412 1 Linaro 1 Op-tee 2018-01-17 5.0 MEDIUM 7.5 HIGH
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable to the bellcore attack in the LibTomCrypt code resulting in compromised private RSA key.
CVE-2017-1000477 1 Xmlbundle Project 1 Xmlbundle 2018-01-17 5.0 MEDIUM 7.5 HIGH
XMLBundle version 0.1.7 is vulnerable to XXE attacks which can result in denial of service attacks.
CVE-2018-5073 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-17 6.0 MEDIUM 6.8 MEDIUM
Online Ticket Booking has CSRF via admin/movieedit.php.
CVE-2017-1000459 1 Leanote 1 Leanote 2018-01-17 4.3 MEDIUM 6.1 MEDIUM
Leanote version <= 2.5 is vulnerable to XSS due to not sanitized input in markdown notes
CVE-2018-0766 1 Microsoft 3 Edge, Windows 10, Windows Server 2016 2018-01-17 4.3 MEDIUM 4.3 MEDIUM
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows an attacker to obtain information to further compromise the user's system, due to how the Microsoft Edge PDF Reader handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".
CVE-2017-1000457 1 Mojoportal 1 Mojoportal 2018-01-17 3.5 LOW 4.8 MEDIUM
Cross-site scripting (XSS) vulnerability in Help.aspx in mojoPortal version 2.5.0.0 allows remote attackers to inject arbitrary web script or HTML via the helpkey parameter. Exploitation requires authenticated reflected cross-site scripting for user accounts assigned either the "Administrators" or "Content Administrators" role.
CVE-2017-18015 1 Share This Image Project 1 Share This Image 2018-01-17 4.3 MEDIUM 6.1 MEDIUM
The ILLID Share This Image plugin before 1.04 for WordPress has XSS via the sharer.php url parameter.
CVE-2017-1000443 1 Openhacker Project 1 Openhacker 2018-01-17 4.3 MEDIUM 6.1 MEDIUM
Eleix Openhacker version 0.1.47 is vulnerable to a XSS vulnerability in the bank transactions component resulting in arbitrary code execution in the browser.
CVE-2017-18011 1 Clickbank 1 Affiliate Ads For Clickbank Products 2018-01-17 4.3 MEDIUM 6.1 MEDIUM
The MyCBGenie Affiliate Ads for Clickbank Products plugin through 1.6 for WordPress has XSS via the text_ads_ajax.php border_color parameter.
CVE-2017-18010 1 E-goi 1 Smart Marketing Sms And Newsletters Forms 2018-01-17 4.3 MEDIUM 6.1 MEDIUM
The E-goi Smart Marketing SMS and Newsletters Forms plugin before 2.0.0 for WordPress has XSS via the admin/partials/custom/egoi-for-wp-form_egoi.php url parameter.
CVE-2014-4914 2 Debian, Zend 2 Debian Linux, Zend Framework 2018-01-17 7.5 HIGH 9.8 CRITICAL
The Zend_Db_Select::order function in Zend Framework before 1.12.7 does not properly handle parentheses, which allows remote attackers to conduct SQL injection attacks via unspecified vectors.
CVE-2017-9608 1 Ffmpeg 1 Ffmpeg 2018-01-17 4.3 MEDIUM 6.5 MEDIUM
The dnxhd decoder in FFmpeg before 3.2.6, and 3.3.x before 3.3.3 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted mov file.
CVE-2017-17875 1 Jextn 1 Jextn Faq Pro 2018-01-17 7.5 HIGH 9.8 CRITICAL
The JEXTN FAQ Pro extension 4.0.0 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17872 1 Jextn 1 Jextn Video Gallery 2018-01-17 7.5 HIGH 9.8 CRITICAL
The JEXTN Video Gallery extension 3.0.5 for Joomla! has SQL Injection via the id parameter in a view=category action.
CVE-2017-17832 1 Serverscheck 1 Monitoring Software 2018-01-17 3.5 LOW 5.4 MEDIUM
ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is not validated/sanitized when passed in the settings_SMS_ALERT_TYPE parameter, and JavaScript can be executed on settings-save.html (the Settings - SMS Alerts page).
CVE-2017-1365 1 Ibm 7 Rational Collaborative Lifecycle Management, Rational Doors Next Generation, Rational Engineering Lifecycle Manager and 4 more 2018-01-17 3.5 LOW 5.4 MEDIUM
IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-force ID: 126858.
CVE-2017-1000413 1 Linaro 1 Op-tee 2018-01-17 4.3 MEDIUM 5.9 MEDIUM
Linaro's open source TEE solution called OP-TEE, version 2.4.0 (and older) is vulnerable a timing attack in the Montgomery parts of libMPA in OP-TEE resulting in a compromised private RSA key.
CVE-2017-18005 1 Exiv2 1 Exiv2 2018-01-17 4.3 MEDIUM 5.5 MEDIUM
Exiv2 0.26 has a Null Pointer Dereference in the Exiv2::DataValue::toLong function in value.cpp, related to crafted metadata in a TIFF file.
CVE-2016-9266 1 Libming 1 Libming 2018-01-17 4.3 MEDIUM 6.5 MEDIUM
listmp3.c in libming 0.4.7 allows remote attackers to unspecified impact via a crafted mp3 file, which triggers an invalid left shift.
CVE-2016-8493 1 Fortinet 1 Forticlient 2018-01-17 9.0 HIGH 8.8 HIGH
In FortiClientWindows 5.4.1 and 5.4.2, an attacker may escalate privilege via a FortiClientNamedPipe vulnerability.
CVE-2018-0800 1 Microsoft 3 Chakracore, Edge, Windows 10 2018-01-17 4.3 MEDIUM 5.3 MEDIUM
Microsoft Edge in Microsoft Windows 10 1709 allows an attacker to obtain information to further compromise the user's system, due to how the scripting engine handles objects in memory, aka "Scripting Engine Information Disclosure Vulnerability". This CVE ID is unique from CVE-2018-0767 and CVE-2018-0780.
CVE-2017-1000496 1 Commsy 1 Commsy 2018-01-17 6.8 MEDIUM 8.8 HIGH
Commsy version 9.0.0 is vulnerable to XXE attacks in the configuration import functionality resulting in denial of service and possibly remote execution of code.
CVE-2017-1000462 1 Bookstackapp 1 Bookstack 2018-01-17 3.5 LOW 5.4 MEDIUM
BookStack version 0.18.4 is vulnerable to stored cross-site scripting, within the page creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000469 1 Cobbler Project 1 Cobbler 2018-01-17 10.0 HIGH 9.8 CRITICAL
Cobbler version up to 2.8.2 is vulnerable to a command injection vulnerability in the "add repo" component resulting in arbitrary code execution as root user.
CVE-2017-1000471 1 Embedthis 1 Goahead 2018-01-17 7.5 HIGH 9.8 CRITICAL
EmbedThis GoAhead Webserver version 4.0.0 is vulnerable to a NULL pointer dereference in the CGI handler resulting in memory corruption or denial of service.
CVE-2017-1000452 1 Samlify Project 1 Samlify 2018-01-17 6.0 MEDIUM 7.5 HIGH
An XML Signature Wrapping vulnerability exists in Samlify 2.2.0 and earlier, and in predecessor Express-saml2 which could allow attackers to impersonate arbitrary users.
CVE-2017-1000482 1 Plone 1 Plone 2018-01-17 3.5 LOW 5.4 MEDIUM
A member of the Plone 2.5-5.1rc1 site could set javascript in the home_page property of his profile, and have this executed when a visitor click the home page link on the author page.
CVE-2017-1000430 1 Rust-base64 Project 1 Rust-base64 2018-01-17 7.5 HIGH 9.8 CRITICAL
rust-base64 version <= 0.5.1 is vulnerable to a buffer overflow when calculating the size of a buffer to use when encoding base64 using the 'encode_config_buf' and 'encode_config' functions
CVE-2017-1000467 1 Lavalite 1 Lavalite 2018-01-17 3.5 LOW 5.4 MEDIUM
LavaLite version 5.2.4 is vulnerable to stored cross-site scripting vulnerability, within the blog creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000495 1 Quickappscms 1 Quickapps Cms 2018-01-17 3.5 LOW 5.4 MEDIUM
QuickApps CMS version 2.0.0 is vulnerable to Stored Cross-site Scripting in the user's real name field resulting in denial of service and performing unauthorised actions with an administrator user's account
CVE-2017-1000478 1 Elabftw 1 Elabftw 2018-01-17 3.5 LOW 5.4 MEDIUM
ELabftw version 1.7.8 is vulnerable to stored cross-site scripting in the experiment infos component resulting in arbitrary execution of JavaScript and denial of service.
CVE-2018-5076 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-17 3.5 LOW 4.8 MEDIUM
Online Ticket Booking has XSS via the admin/newsedit.php newstitle parameter.
CVE-2018-5077 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-17 3.5 LOW 4.8 MEDIUM
Online Ticket Booking has XSS via the admin/movieedit.php moviename parameter.
CVE-2018-5249 1 Shaarli Project 1 Shaarli 2018-01-17 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in Shaarli before 0.8.5 and 0.9.x before 0.9.3 allows remote attackers to inject arbitrary code via the login form's username field (aka the login parameter to the ban_canLogin function in index.php).
CVE-2017-15324 1 Huawei 4 S5700, S5700 Firmware, S6700 and 1 more 2018-01-17 7.8 HIGH 7.5 HIGH
Huawei S5700 and S6700 with software of V200R005C00 have a DoS vulnerability due to insufficient validation of the Network Quality Analysis (NQA) packets. A remote attacker could exploit this vulnerability by sending malformed NQA packets to the target device. Successful exploitation could make the device restart.
CVE-2017-17901 1 Zyxel 2 P-660hw, P-660hw Firmware 2018-01-17 7.8 HIGH 7.5 HIGH
ZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (CPU consumption) via a flood of IP packets with a TTL of 1.
CVE-2018-5078 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-16 3.5 LOW 4.8 MEDIUM
Online Ticket Booking has XSS via the admin/eventlist.php cast parameter.
CVE-2018-3811 1 Oturia 1 Smart Google Code Inserter 2018-01-16 7.5 HIGH 9.8 CRITICAL
SQL Injection vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to execute SQL queries in the context of the web server. The saveGoogleAdWords() function in smartgooglecode.php did not use prepared statements and did not sanitize the $_POST["oId"] variable before passing it as input into the SQL query.
CVE-2017-1000420 1 Syncthing 1 Syncthing 2018-01-16 6.4 MEDIUM 7.5 HIGH
Syncthing version 0.14.33 and older is vulnerable to symlink traversal resulting in arbitrary file overwrite
CVE-2018-3810 1 Oturia 1 Smart Google Code Inserter 2018-01-16 7.5 HIGH 9.8 CRITICAL
Authentication Bypass vulnerability in the Oturia Smart Google Code Inserter plugin before 3.5 for WordPress allows unauthenticated attackers to insert arbitrary JavaScript or HTML code (via the sgcgoogleanalytic parameter) that runs on all pages served by WordPress. The saveGoogleCode() function in smartgooglecode.php does not check if the current request is made by an authorized user, thus allowing any unauthenticated user to successfully update the inserted code.
CVE-2017-1000466 1 Invoiceninja 1 Invoice Ninja 2018-01-16 3.5 LOW 5.4 MEDIUM
Invoice Ninja version 3.8.1 is vulnerable to stored cross-site scripting vulnerability, within the invoice creation page, which can result in disruption of service and execution of javascript code.
CVE-2017-1000491 1 Shiba Project 1 Shiba 2018-01-16 4.3 MEDIUM 6.1 MEDIUM
Shiba markdown live preview app version 1.1.0 is vulnerable to XSS which leads to code execution due to enabled node integration.
CVE-2017-1000454 1 Cmsmadesimple 1 Cms Made Simple 2018-01-16 4.6 MEDIUM 7.8 HIGH
CMS Made Simple 2.1.6, 2.2, 2.2.1 are vulnerable to Smarty Template Injection in some core components, resulting in local file read before 2.2, and local file inclusion since 2.2.1
CVE-2017-1000453 1 Cmsmadesimple 1 Cms Made Simple 2018-01-16 7.5 HIGH 9.8 CRITICAL
CMS Made Simple version 2.1.6 and 2.2 are vulnerable to Smarty templating injection in some core modules, resulting in unauthenticated PHP code execution.
CVE-2017-18006 1 Extensis 1 Portfolio Netpublish 2018-01-16 4.3 MEDIUM 6.1 MEDIUM
netpub/server.np in Extensis Portfolio NetPublish has XSS in the quickfind parameter, aka Open Bug Bounty ID OBB-290447.
CVE-2017-1000448 1 Structured-data 1 Structured Data Linter 2018-01-16 5.0 MEDIUM 7.5 HIGH
Structured Data Linter versions 2.4.1 and older are vulnerable to a directory traversal attack in the URL input field resulting in the possibility of disclosing information about the remote host.
CVE-2017-1000458 1 Bro 1 Bro 2018-01-16 7.5 HIGH 9.8 CRITICAL
Bro before Bro v2.5.2 is vulnerable to an out of bounds write in the ContentLine analyzer allowing remote attackers to cause a denial of service (crash) and possibly other exploitation.
CVE-2017-1000419 1 Phpbb 1 Phpbb 2018-01-16 5.0 MEDIUM 7.5 HIGH
phpBB version 3.2.0 is vulnerable to SSRF in the Remote Avatar function resulting allowing an attacker to perform port scanning, requesting internal content and potentially attacking such internal services via the web application.
CVE-2018-5072 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-16 3.5 LOW 4.8 MEDIUM
Online Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.
CVE-2018-5074 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-01-16 3.5 LOW 4.8 MEDIUM
Online Ticket Booking has XSS via the admin/manageownerlist.php contact parameter.