|
250821
|
4.3 |
MEDIUM
Network
|
joomla
|
joomla\!
|
In Joomla! before 3.8.2, a logic bug in com_fields exposed read-only information about a site's custom fields to unauthorized users.
|
CWE-200
Information Exposure
|
CVE-2017-16633
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250822
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a radio URL.
|
CWE-79
Cross-site Scripting
|
CVE-2017-16568
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250823
|
5.4 |
MEDIUM
Network
|
logitech
|
media_server
|
Cross-site scripting (XSS) vulnerability in Logitech Media Server 7.9.0 allows remote attackers to inject arbitrary web script or HTML via a "favorite."
|
CWE-79
Cross-site Scripting
|
CVE-2017-16567
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250824
|
9.8 |
CRITICAL
Network
|
userproplugin
|
userpro
|
The UserPro plugin before 4.9.17.1 for WordPress, when used on a site with the "admin" username, allows remote attackers to bypass authentication and obtain administrative access via a "true" value f…
|
CWE-287
Improper Authentication
|
CVE-2017-16562
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250825
|
7.5 |
HIGH
Network
|
brother
|
dcp-j132w_firmware
|
The Debut embedded http server contains a remotely exploitable denial of service where a single malformed HTTP POST request can cause the server to hang until eventually replying (~300 seconds) with …
|
NVD-CWE-noinfo
|
CVE-2017-16249
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250826
|
5.9 |
MEDIUM
Network
|
librenms
|
librenms
|
The installation process in LibreNMS before 2017-08-18 allows remote attackers to read arbitrary files, related to html/install.php.
|
CWE-22
Path Traversal
|
CVE-2017-16759
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250827
|
4.8 |
MEDIUM
Network
|
ultimate_instagram_feed_project
|
ultimate_instagram_feed
|
Cross-site scripting (XSS) vulnerability in admin/partials/uif-access-token-display.php in the Ultimate Instagram Feed plugin before 1.3 for WordPress allows remote attackers to inject arbitrary web …
|
CWE-79
Cross-site Scripting
|
CVE-2017-16758
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250828
|
7.8 |
HIGH
Local
|
hola
|
vpn
|
Hola VPN 1.34 has weak permissions (Everyone:F) under %PROGRAMFILES%, which allows local users to gain privileges via a Trojan horse 7za.exe or hola.exe file.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-16757
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250829
|
5.5 |
MEDIUM
Local
|
swftools
|
swftools
|
The swf_DefineLosslessBitsTagToImage function in lib/modules/swfbits.c in SWFTools 0.9.2 mishandles an uncompress failure, which allows remote attackers to cause a denial of service (NULL pointer der…
|
CWE-476
NULL Pointer Dereference
|
CVE-2017-16711
|
2024-11-21 12:16 |
2017-11-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250830
|
8.0 |
HIGH
Adjacent
|
datto
|
windows_agent
|
Datto Windows Agent allows unauthenticated remote command execution via a modified command in conjunction with CVE-2017-16673 exploitation, aka an attack with a malformed primary whitelisted command …
|
NVD-CWE-noinfo
|
CVE-2017-16674
|
2024-11-21 12:16 |
2017-11-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|