|
247011
|
6.1 |
MEDIUM
Network
|
markdown_on_save_improved_project
|
markdown_on_save_improved
|
The Markdown on Save Improved plugin 2.5 for WordPress has a stored XSS vulnerability in the content of a post.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9337
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247012
|
6.1 |
MEDIUM
Network
|
wp_editor.md_project
|
wp_editor.md
|
The WP Editor.MD plugin 1.6 for WordPress has a stored XSS vulnerability in the content of a post.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9336
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247013
|
7.5 |
HIGH
Network
|
call-cc
|
chicken
|
An incorrect "pair?" check in the Scheme "length" procedure results in an unsafe pointer dereference in all CHICKEN Scheme versions prior to 4.13, which allows an attacker to cause a denial of servic…
|
CWE-20
Improper Input Validation
|
CVE-2017-9334
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247014
|
5.4 |
MEDIUM
Network
|
epesi
|
epesi
|
The Agenda component in Telaxus EPESI 1.8.2 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in modules/Utils/RecordBrowser/RecordBrowserCommon_0.php, which allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9331
|
2024-11-21 12:35 |
2017-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247015
|
6.5 |
MEDIUM
Network
|
allen_disk_project
|
allen_disk
|
SSRF vulnerability in remotedownload.php in Allen Disk 1.6 allows remote authenticated users to conduct port scans and access intranet servers via a crafted file parameter.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-9307
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247016
|
6.1 |
MEDIUM
Network
|
syspass
|
syspass
|
inc/SP/Html/Html.class.php in sysPass 2.1.9 allows remote attackers to bypass the XSS filter, as demonstrated by use of an "<svg/onload=" substring instead of an "<svg onload=" substring.
|
CWE-79
Cross-site Scripting
|
CVE-2017-9306
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247017
|
6.1 |
MEDIUM
Network
|
tiki
|
tikiwiki_cms\/groupware
|
lib/core/TikiFilter/PreventXss.php in Tiki Wiki CMS Groupware 16.2 allows remote attackers to bypass the XSS filter via padded zero characters, as demonstrated by an attack on tiki-batch_send_newslet…
|
CWE-79
Cross-site Scripting
|
CVE-2017-9305
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247018
|
7.5 |
HIGH
Network
|
virustotal
|
yara
|
libyara/re.c in the regexp module in YARA 3.5.0 allows remote attackers to cause a denial of service (stack consumption) via a crafted rule that is mishandled in the _yr_re_emit function.
|
CWE-674
Uncontrolled Recursion
|
CVE-2017-9304
|
2024-11-21 12:35 |
2017-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247019
|
6.1 |
MEDIUM
Network
|
laravel
|
laravel
|
Laravel 5.4.x before 5.4.22 does not properly constrain the host portion of a password-reset URL, which makes it easier for remote attackers to conduct phishing attacks by specifying an attacker-cont…
|
CWE-20
Improper Input Validation
|
CVE-2017-9303
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247020
|
5.5 |
MEDIUM
Local
|
realnetworks
|
realplayer
|
RealPlayer 16.0.2.32 allows remote attackers to cause a denial of service (divide-by-zero error and application crash) via a crafted mp4 file.
|
CWE-369
Divide By Zero
|
CVE-2017-9302
|
2024-11-21 12:35 |
2017-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|