|
249661
|
9.8 |
CRITICAL
Network
|
bmc
|
remedy_mid-tier
|
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinti…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-17674
|
2024-11-21 12:18 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249662
|
6.1 |
MEDIUM
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17477
|
2024-11-21 12:18 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249663
|
7.2 |
HIGH
Network
|
fortinet
|
fortios
|
A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configuration…
|
CWE-269
Improper Privilege Management
|
CVE-2017-17544
|
2024-11-21 12:18 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249664
|
9.8 |
CRITICAL
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow,…
|
CWE-255
Credentials Management
|
CVE-2017-17836
|
2024-11-21 12:18 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249665
|
8.8 |
HIGH
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
|
CWE-352
Origin Validation Error
|
CVE-2017-17835
|
2024-11-21 12:18 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249666
|
8.8 |
HIGH
Network
|
zyxel
|
zywall_usg_100_firmware
|
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently…
|
CWE-352
Origin Validation Error
|
CVE-2017-17550
|
2024-11-21 12:18 |
2018-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249667
|
8.1 |
HIGH
Network
|
contronics
|
homeputer_cl_studio_fur_homematic
|
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitiv…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-17691
|
2024-11-21 12:18 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249668
|
7.5 |
HIGH
Network
|
episerver
|
episerver
|
XML external entity (XXE) vulnerability in Episerver 7 patch 4 and earlier allows remote attackers to read arbitrary files via a crafted DTD in an XML request involving util/xmlrpc/Handler.ashx.
|
CWE-611
XXE
|
CVE-2017-17762
|
2024-11-21 12:18 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249669
|
4.3 |
MEDIUM
Network
|
pleasantsolutions
|
pleasant_password_server
|
Because of insufficient authorization checks it is possible for any authenticated user to change profile data of other users in Pleasant Password Server before 7.8.3.
|
CWE-863
Incorrect Authorization
|
CVE-2017-17708
|
2024-11-21 12:18 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249670
|
8.1 |
HIGH
Network
|
pleasantsolutions
|
pleasant_password_server
|
Due to missing authorization checks, any authenticated user is able to list, upload, or delete attachments to password safe entries in Pleasant Password Server before 7.8.3. To perform those actions …
|
CWE-862
Missing Authorization
|
CVE-2017-17707
|
2024-11-21 12:18 |
2018-07-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|