|
250391
|
8.8 |
HIGH
Adjacent
|
tenda
|
ac9_firmware ac15_firmware ac18_firmware
|
Command Injection vulnerability in app_data_center on Shenzhen Tenda Ac9 US_AC9V1.0BR_V15.03.05.14_multi_TD01, Ac9 ac9_kf_V15.03.05.19(6318_)_cn, Ac15 US_AC15V1.0BR_V15.03.05.18_multi_TD01, Ac15 US_A…
|
CWE-78
OS Command
|
CVE-2017-16923
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250392
|
9.8 |
CRITICAL
Network
|
finecms
|
finecms
|
v5/config/system.php in dayrui FineCms 5.2.0 has a default SYS_KEY value and does not require key regeneration for each installation, which allows remote attackers to upload arbitrary .php files via …
|
NVD-CWE-noinfo
|
CVE-2017-16920
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250393
|
5.4 |
MEDIUM
Network
|
mapos_project
|
mapos
|
MapOS 3.1.11 and earlier has a Stored Cross-site Scripting (XSS) vulnerability in /clientes/visualizar, which allows remote attackers to inject arbitrary web script or HTML via a crafted description …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16919
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250394
|
9.8 |
CRITICAL
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
The VC-2 Video Compression encoder in FFmpeg 3.0 and 3.4 allows remote attackers to cause a denial of service (out-of-bounds read) because of incorrect buffer padding for non-Haar wavelets, related t…
|
CWE-125
Out-of-bounds Read
|
CVE-2017-16840
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250395
|
5.4 |
MEDIUM
Network
|
horde
|
groupware
|
In Horde Groupware 5.2.19, there is XSS via the Name field during creation of a new Resource. This can be leveraged for remote code execution after compromising an administrator account, because the …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16908
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250396
|
5.4 |
MEDIUM
Network
|
horde
|
groupware
|
In Horde Groupware 5.2.19 and 5.2.21, there is XSS via the Color field in a Create Task List action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16907
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250397
|
5.4 |
MEDIUM
Network
|
horde
|
groupware
|
In Horde Groupware 5.2.19-5.2.22, there is XSS via the URL field in a "Calendar -> New Event" action.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16906
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250398
|
6.1 |
MEDIUM
Network
|
lvyecms_project
|
lvyecms
|
The Public tologin feature in admin.php in LvyeCMS through 3.1 allows XSS via a crafted username that is mishandled during later log viewing by an administrator.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16904
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250399
|
9.8 |
CRITICAL
Network
|
lvyecms_project
|
lvyecms
|
LvyeCMS through 3.1 allows remote attackers to upload and execute arbitrary PHP code via directory traversal sequences in the dir parameter, in conjunction with PHP code in the content parameter, wit…
|
CWE-22
Path Traversal
|
CVE-2017-16903
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250400
|
7.5 |
HIGH
Network
|
vonage
|
vdv-23_firmware
|
On the Vonage VDV-23 115 3.2.11-0.9.40 home router, sending a long string of characters in the loginPassword and/or loginUsername field to goform/login causes the router to reboot.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-16902
|
2024-11-21 12:17 |
2017-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|