|
252021
|
6.1 |
MEDIUM
Network
|
2kblater
|
2kb_amazon_affiliates_store
|
Multiple cross-site scripting (XSS) vulnerabilities in the 2kb Amazon Affiliates Store plugin before 2.1.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) page…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14622
|
2024-11-21 12:13 |
2017-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252022
|
8.8 |
HIGH
Network
|
ffmpeg
|
ffmpeg
|
The sdp_parse_fmtp_config_h264 function in libavformat/rtpdec_h264.c in FFmpeg before 3.3.4 mishandles empty sprop-parameter-sets values, which allows remote attackers to cause a denial of service (h…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14767
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252023
|
7.5 |
HIGH
Network
|
saadamin
|
simple_student_result
|
The Simple Student Result plugin before 1.6.4 for WordPress has an Authentication Bypass vulnerability because the fn_ssr_add_st_submit() function and fn_ssr_del_st_submit() function in functions.php…
|
CWE-287
Improper Authentication
|
CVE-2017-14766
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252024
|
6.1 |
MEDIUM
Network
|
genixcms
|
genixcms
|
In GeniXCMS 1.1.4, gxadmin/index.php has XSS via the Menu ID field in a page=menus request.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14765
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252025
|
8.8 |
HIGH
Network
|
genixcms
|
genixcms
|
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.
|
CWE-94
Code Injection
|
CVE-2017-14764
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252026
|
8.8 |
HIGH
Network
|
genixcms
|
genixcms
|
In the Install Themes page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a theme.
|
NVD-CWE-noinfo
|
CVE-2017-14763
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252027
|
6.1 |
MEDIUM
Network
|
genixcms
|
genixcms
|
In GeniXCMS 1.1.4, /inc/lib/Control/Backend/menus.control.php has XSS via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14762
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252028
|
6.1 |
MEDIUM
Network
|
genixcms
|
genixcms
|
In GeniXCMS 1.1.4, /inc/lib/backend/menus.control.php has XSS via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14761
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252029
|
9.8 |
CRITICAL
Network
|
eventespresso
|
event_espresso_lite
|
SQL Injection exists in /includes/event-management/index.php in the event-espresso-free (aka Event Espresso Lite) plugin v3.1.37.12.L for WordPress via the recurrence_id parameter to /wp-admin/admin.…
|
CWE-89
SQL Injection
|
CVE-2017-14760
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252030
|
5.4 |
MEDIUM
Network
|
eyesofnetwork
|
eyesofnetwork
|
Cross-site scripting (XSS) vulnerability in the EyesOfNetwork web interface (aka eonweb) 5.1-0 allows remote authenticated users to inject arbitrary web script or HTML via the filter parameter to mod…
|
CWE-79
Cross-site Scripting
|
CVE-2017-14753
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|