|
252031
|
6.1 |
MEDIUM
Network
|
intensewp
|
wp_jobs
|
The Intense WP "WP Jobs" plugin 1.5 for WordPress has XSS, related to the Job Qualification field.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14751
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252032
|
7.8 |
HIGH
Local
|
jerryscript
|
jerryscript
|
JerryScript 1.0 allows remote attackers to cause a denial of service (jmem_heap_alloc_block_internal heap memory corruption) or possibly execute arbitrary code via a crafted .js file, because unrecog…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-14749
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252033
|
5.3 |
MEDIUM
Network
|
blizzard
|
overwatch
|
Race condition in Blizzard Overwatch 1.15.0.2 allows remote authenticated users to cause a denial of service (season bans and SR losses for other users) by leaving a competitive match at a specific t…
|
CWE-362
Race Condition
|
CVE-2017-14748
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252034
|
7.8 |
HIGH
Local
|
gnu
|
binutils
|
The *_get_synthetic_symtab functions in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29, interpret a -1 value as a sorting count instead of an error flag, w…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2017-14745
|
2024-11-21 12:13 |
2017-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252035
|
8.8 |
HIGH
Network
|
claydip
|
airbnb_clone
|
Multiple unrestricted file upload vulnerabilities in the (1) imageSubmit and (2) proof_submit functions in Claydip Laravel Airbnb Clone 1.0 allow remote authenticated users to execute arbitrary code …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-14704
|
2024-11-21 12:13 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252036
|
7.2 |
HIGH
Network
|
citrix
|
netscaler_gateway_firmware application_delivery_controller_firmware
|
A vulnerability has been identified in the management interface of Citrix NetScaler Application Delivery Controller (ADC) and NetScaler Gateway 10.1 before build 135.18, 10.5 before build 66.9, 10.5e…
|
CWE-287
Improper Authentication
|
CVE-2017-14602
|
2024-11-21 12:13 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252037
|
9.8 |
CRITICAL
Network
|
cashbackcomparisonscript
|
cash_back_comparison
|
SQL injection vulnerability in Cash Back Comparison Script 1.0 allows remote attackers to execute arbitrary SQL commands via the PATH_INFO to search/.
|
CWE-89
SQL Injection
|
CVE-2017-14703
|
2024-11-21 12:13 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252038
|
6.1 |
MEDIUM
Network
|
baidu
|
ueditor
|
UEditor 1.4.3.3 has XSS via the SRC attribute of an IFRAME element.
|
CWE-79
Cross-site Scripting
|
CVE-2017-14744
|
2024-11-21 12:13 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252039
|
8.1 |
HIGH
Network
|
faleemi
|
fsc-880_firmware
|
Faleemi FSC-880 00.01.01.0048P2 devices allow unauthenticated SQL injection via the Username element in an XML document to /onvif/device_service, as demonstrated by reading the admin password.
|
CWE-89
SQL Injection
|
CVE-2017-14743
|
2024-11-21 12:13 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252040
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
The ReadCAPTIONImage function in coders/caption.c in ImageMagick 7.0.7-3 allows remote attackers to cause a denial of service (infinite loop) via a crafted font file.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2017-14741
|
2024-11-21 12:13 |
2017-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|