|
251271
|
6.1 |
MEDIUM
Network
|
bmc
|
remedy_mid-tier
|
BMC Remedy Mid Tier 9.1SP3 is affected by cross-site scripting (XSS). A DOM-based cross-site scripting vulnerability was discovered in a legacy utility.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17678
|
2024-11-21 12:18 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251272
|
8.8 |
HIGH
Network
|
bmc
|
remedy_mid-tier
|
BMC Remedy 9.1SP3 is affected by authenticated code execution. Authenticated users that have the right to create reports can use BIRT templates to run code.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2017-17677
|
2024-11-21 12:18 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251273
|
5.3 |
MEDIUM
Network
|
bmc
|
remedy_mid-tier
|
BMC Remedy Mid Tier 9.1SP3 is affected by log hijacking. Remote logging can be accessed by unauthenticated users, allowing for an attacker to hijack the system logs. This data can include user names …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2017-17675
|
2024-11-21 12:18 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251274
|
9.8 |
CRITICAL
Network
|
bmc
|
remedy_mid-tier
|
BMC Remedy Mid Tier 9.1SP3 is affected by remote and local file inclusion. Due to the lack of restrictions on what can be targeted, the system can be vulnerable to attacks such as system fingerprinti…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-17674
|
2024-11-21 12:18 |
2021-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251275
|
6.1 |
MEDIUM
Network
|
pexip
|
pexip_infinity
|
Pexip Infinity before 17 allows an unauthenticated remote attacker to achieve stored XSS via management web interface views.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17477
|
2024-11-21 12:18 |
2020-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251276
|
7.2 |
HIGH
Network
|
fortinet
|
fortios
|
A privilege escalation vulnerability in Fortinet FortiOS 6.0.0 to 6.0.6, 5.6.0 to 5.6.10, 5.4 and below allows admin users to elevate their profile to super_admin via restoring modified configuration…
|
CWE-269
Improper Privilege Management
|
CVE-2017-17544
|
2024-11-21 12:18 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251277
|
9.8 |
CRITICAL
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, an experimental Airflow feature displayed authenticated cookies, as well as passwords to databases used by Airflow. An attacker who has limited access to airflow,…
|
CWE-255
Credentials Management
|
CVE-2017-17836
|
2024-11-21 12:18 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251278
|
8.8 |
HIGH
Network
|
apache
|
airflow
|
In Apache Airflow 1.8.2 and earlier, a CSRF vulnerability allowed for a remote command injection on a default install of Airflow.
|
CWE-352
Origin Validation Error
|
CVE-2017-17835
|
2024-11-21 12:18 |
2019-01-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251279
|
8.8 |
HIGH
Network
|
zyxel
|
zywall_usg_100_firmware
|
ZyXEL ZyWALL USG 2.12 AQQ.2 and 3.30 AQQ.7 devices are affected by a CSRF vulnerability via a cgi-bin/zysh-cgi cmd action to add a user account. This account's access could, for example, subsequently…
|
CWE-352
Origin Validation Error
|
CVE-2017-17550
|
2024-11-21 12:18 |
2018-11-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251280
|
8.1 |
HIGH
Network
|
contronics
|
homeputer_cl_studio_fur_homematic
|
Homeputer CL Studio fur HomeMatic 4.0 Rel 160808 and earlier uses cleartext to exchange the username and password between server and client instances, which allows remote attackers to obtain sensitiv…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2017-17691
|
2024-11-21 12:18 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|