|
250881
|
7.5 |
HIGH
Network
|
edx
|
edx-platform
|
edx-platform before 2017-08-03 allows attackers to trigger password-reset e-mail messages in which the reset link has an attacker-controlled domain name.
|
CWE-284
Improper Access Control
|
CVE-2017-18380
|
2024-11-21 12:19 |
2019-07-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250882
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel before 4.14, an out of boundary access happened in drivers/nvme/target/fc.c.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-18379
|
2024-11-21 12:19 |
2019-07-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250883
|
9.8 |
CRITICAL
Network
|
web-gooroo
|
cms_web-gooroo
|
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18346
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250884
|
6.1 |
MEDIUM
Network
|
archon_project
|
archon
|
packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17972
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250885
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17945
|
2024-11-21 12:19 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250886
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17944
|
2024-11-21 12:19 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250887
|
9.8 |
CRITICAL
Network
|
netgear
|
readynas_surveillance_firmware
|
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=wri…
|
CWE-77
Command Injection
|
CVE-2017-18378
|
2024-11-21 12:19 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250888
|
9.8 |
CRITICAL
Network
|
goahead
|
wireless_ip_camera_wificam_firmware
|
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cg…
|
CWE-77
Command Injection
|
CVE-2017-18377
|
2024-11-21 12:19 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250889
|
8.8 |
HIGH
Network
|
strangebee
|
thehive
|
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's priv…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18376
|
2024-11-21 12:19 |
2019-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250890
|
8.8 |
HIGH
Network
|
ampache
|
ampache
|
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-18375
|
2024-11-21 12:19 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|