|
249831
|
7.2 |
HIGH
Network
|
fortinet
|
fortios
|
A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configuration…
|
CWE-269
Improper Privilege Management
|
CVE-2017-17544
|
2024-11-21 12:18 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249832
|
9.8 |
CRITICAL
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow,…
|
CWE-255
Credentials Management
|
CVE-2017-17836
|
2024-11-21 12:18 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249833
|
8.8 |
HIGH
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
|
CWE-352
Origin Validation Error
|
CVE-2017-17835
|
2024-11-21 12:18 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249834
|
8.8 |
HIGH
Network
|
zyxel
|
zywall_usg_100_firmware
|
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently…
|
CWE-352
Origin Validation Error
|
CVE-2017-17550
|
2024-11-21 12:18 |
2018-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249835
|
8.1 |
HIGH
Network
|
contronics
|
homeputer_cl_studio_fur_homematic
|
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitiv…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-17691
|
2024-11-21 12:18 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249836
|
7.5 |
HIGH
Network
|
episerver
|
episerver
|
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
|
CWE-611
XXE
|
CVE-2017-17762
|
2024-11-21 12:18 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249837
|
4.3 |
MEDIUM
Network
|
pleasantsolutions
|
pleasant_password_server
|
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.
|
CWE-863
Incorrect Authorization
|
CVE-2017-17708
|
2024-11-21 12:18 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249838
|
8.1 |
HIGH
Network
|
pleasantsolutions
|
pleasant_password_server
|
Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions …
|
CWE-862
Missing Authorization
|
CVE-2017-17707
|
2024-11-21 12:18 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249839
|
6.1 |
MEDIUM
Network
|
fortinet
|
fortianalyzer_firmware fortimanager_firmware
|
A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.4 and below versions, FortiAnalyzer 6.0.0, 5.6.4 and below versions allows inject Javascript code and HTML tags through …
|
CWE-79
Cross-site Scripting
|
CVE-2017-17541
|
2024-11-21 12:18 |
2018-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249840
|
5.9 |
MEDIUM
Network
|
microsoft horde google 9folders flipdogsolutions r2mail2 apple bloop freron kde gnome mozilla ibm emclient postbox-inc ritlabs
|
outlook horde_imp gmail nine maildroid r2mail2 mail airmail mailmate kmail trojita evolution thunderbird notes emclient postbox the_bat
|
The S/MIME specification allows a Cipher Block Chaining (CBC) malleability-gadget attack that can indirectly lead to plaintext exfiltration, aka EFAIL.
|
NVD-CWE-noinfo
|
CVE-2017-17689
|
2024-11-21 12:18 |
2018-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|