|
250781
|
7.5 |
HIGH
Network
|
sly07_project
|
sly07
|
sly07 is an API for censoring text. sly07 is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
|
CWE-22
Path Traversal
|
CVE-2017-16189
|
2024-11-21 12:16 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250782
|
9.8 |
CRITICAL
Network
|
tp-shop
|
tpshop
|
SSRF (Server Side Request Forgery) in tpshop 2.0.5 and 2.0.6 allows remote attackers to obtain sensitive information, attack intranet hosts, or possibly trigger remote command execution via the plugi…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-16614
|
2024-11-21 12:16 |
2018-03-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250783
|
7.8 |
HIGH
Local
|
hashicorp
|
vagrant_vmware_fusion
|
The vagrant update process in Hashicorp vagrant-vmware-fusion 5.0.2 through 5.0.4 allows local users to steal root privileges via a crafted update request when no updates are available.
|
CWE-362
Race Condition
|
CVE-2017-16512
|
2024-11-21 12:16 |
2018-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250784
|
6.8 |
MEDIUM
Physics
|
meco
|
usb_memory_stick_with_fingerprint_firwmare
|
An issue was discovered on MECO USB Memory Stick with Fingerprint MECOZiolsamDE601 devices. The fingerprint authentication requirement for data access can be bypassed. An attacker with physical acces…
|
CWE-287
Improper Authentication
|
CVE-2017-16242
|
2024-11-21 12:16 |
2018-03-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250785
|
8.8 |
HIGH
Network
|
synology
|
photo_station
|
Improper input validation vulnerability in SYNOPHOTO_Flickr_MultiUpload in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote authenticated users to execute arbitrary codes vi…
|
CWE-20
Improper Input Validation
|
CVE-2017-16772
|
2024-11-21 12:16 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250786
|
6.1 |
MEDIUM
Network
|
synology
|
photo_station
|
Cross-site scripting (XSS) vulnerability in Log Viewer in Synology Photo Station before 6.8.3-3463 and before 6.3-2971 allows remote attackers to inject arbitrary web script or HTML via the username …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16771
|
2024-11-21 12:16 |
2018-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250787
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
A Stack-based Buffer Overflow issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Stack-based buffer overflow vulnerabilities caused by p…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16751
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250788
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
A Use-after-Free issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files could exploit a use-after-free vulnerab…
|
CWE-416
Use After Free
|
CVE-2017-16749
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250789
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
An Out-of-bounds Write issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. Specially crafted .dpb files may cause the system to write out…
|
CWE-787
Out-of-bounds Write
|
CVE-2017-16747
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250790
|
7.8 |
HIGH
Local
|
deltaww
|
delta_industrial_automation_screen_editor
|
A Type Confusion issue was discovered in Delta Electronics Delta Industrial Automation Screen Editor, Version 2.00.23.00 or prior. An access of resource using incompatible type ('type confusion') vul…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2017-16745
|
2024-11-21 12:16 |
2018-03-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|