|
257161
|
7.5 |
HIGH
Network
|
snap7_project
|
snap7_server
|
The Snap7 Server version 1.4.1 can be crashed when the ItemCount field of the ReadVar or WriteVar functions of the S7 protocol implementation in Snap7 are provided with unexpected input, thus resulti…
|
CWE-20
Improper Input Validation
|
CVE-2017-1000230
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257162
|
5.4 |
MEDIUM
Network
|
parallelus
|
salutation
|
Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can
|
CWE-79
Cross-site Scripting
|
CVE-2017-1000227
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257163
|
9.1 |
CRITICAL
Network
|
simplexml_project
|
simplexml
|
SimpleXML (latest version 2.7.1) is vulnerable to an XXE vulnerability resulting SSRF, information disclosure, DoS and so on.
|
CWE-611
XXE
|
CVE-2017-1000190
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257164
|
6.1 |
MEDIUM
Network
|
phoenixframework
|
phoenix
|
The Phoenix Framework versions 1.0.0 through 1.0.4, 1.1.0 through 1.1.6, 1.2.0, 1.2.2 and 1.3.0-rc.0 are vulnerable to unvalidated URL redirection, which may result in phishing or social engineering …
|
CWE-601
Open Redirect
|
CVE-2017-1000163
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257165
|
9.8 |
CRITICAL
Network
|
xrootd
|
xrootd
|
ROOT xrootd version 4.6.0 and below is vulnerable to an unauthenticated shell command injection resulting in remote code execution
|
CWE-78
OS Command
|
CVE-2017-1000215
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257166
|
7.5 |
HIGH
Network
|
jqueryfiletree_project
|
jqueryfiletree
|
jqueryFileTree 2.1.5 and older Directory Traversal
|
CWE-22
Path Traversal
|
CVE-2017-1000170
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257167
|
9.8 |
CRITICAL
Network
|
quickerbb_project
|
quickerbb
|
QuickerBB version <= 0.7.2 is vulnerable to arbitrary file writes which can lead to remote code execution. This can lead to the complete takeover of the server hosting QuickerBB.
|
CWE-20
Improper Input Validation
|
CVE-2017-1000169
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257168
|
6.5 |
MEDIUM
Network
|
sodiumoxide_project
|
sodiumoxide
|
sodiumoxide 0.0.13 and older scalarmult() vulnerable to degenerate public keys
|
NVD-CWE-noinfo
|
CVE-2017-1000168
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257169
|
9.8 |
CRITICAL
Network
|
cygnux
|
syspass
|
Cygnux sysPass version 2.1.7 and older is vulnerable to a Local File Inclusion in the functionality of javascript files inclusion. The attacker can read the configuration files that contain the login…
|
NVD-CWE-noinfo
|
CVE-2017-1000192
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257170
|
7.5 |
HIGH
Network
|
jool
|
jool
|
Jool 3.5.0-3.5.1 is vulnerable to a kernel crashing packet resulting in a DOS.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2017-1000191
|
2024-11-21 12:04 |
2017-11-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|