|
253891
|
9.8 |
CRITICAL
Network
|
web-gooroo
|
cms_web-gooroo
|
SQL injection vulnerability in /wbg/core/_includes/authorization.inc.php in CMS Web-Gooroo through 2013-01-19 allows remote attackers to execute arbitrary SQL commands via the wbg_login parameter.
|
CWE-89
SQL Injection
|
CVE-2017-18346
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253892
|
6.1 |
MEDIUM
Network
|
archon_project
|
archon
|
packages/subjects/pub/subjects.php in Archon 3.21 rev-1 has XSS in the referer parameter in an index.php?subjecttypeid=xxx request, aka Open Bug Bounty ID OBB-466362.
|
CWE-79
Cross-site Scripting
|
CVE-2017-17972
|
2024-11-21 12:19 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253893
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS HiVivo aspplication before 5.6.27 for ASUS Watch has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17945
|
2024-11-21 12:19 |
2019-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253894
|
9.1 |
CRITICAL
Network
|
asus
|
vivobaby hivivo
|
The ASUS Vivobaby application before 1.1.09 for Android has Missing SSL Certificate Validation.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-17944
|
2024-11-21 12:19 |
2019-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253895
|
9.8 |
CRITICAL
Network
|
netgear
|
readynas_surveillance_firmware
|
In NETGEAR ReadyNAS Surveillance before 1.4.3-17 x86 and before 1.1.4-7 ARM, $_GET['uploaddir'] is not escaped and is passed to system() through $tmp_upload_dir, leading to upgrade_handle.php?cmd=wri…
|
CWE-77
Command Injection
|
CVE-2017-18378
|
2024-11-21 12:19 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253896
|
9.8 |
CRITICAL
Network
|
goahead
|
wireless_ip_camera_wificam_firmware
|
An issue was discovered on Wireless IP Camera (P2P) WIFICAM cameras. There is Command Injection in the set_ftp.cgi script via shell metacharacters in the pwd variable, as demonstrated by a set_ftp.cg…
|
CWE-77
Command Injection
|
CVE-2017-18377
|
2024-11-21 12:19 |
2019-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253897
|
8.8 |
HIGH
Network
|
strangebee
|
thehive
|
An improper authorization check in the User API in TheHive before 2.13.4 and 3.x before 3.3.1 allows users with read-only or read/write access to escalate their privileges to the administrator's priv…
|
CWE-264
Permissions, Privileges, and Access Controls
|
CVE-2017-18376
|
2024-11-21 12:19 |
2019-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253898
|
8.8 |
HIGH
Network
|
ampache
|
ampache
|
Ampache 3.8.3 allows PHP Object Instantiation via democratic.ajax.php and democratic.class.php.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2017-18375
|
2024-11-21 12:19 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253899
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware sd_210_firmware sd_835_firmware sd_845_firmware sd_850_firmware sd_212_firmware sd_205_firmware
|
Secure camera logic allows display/secure camera controllers to access HLOS memory during secure display or camera session in Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, SD 210/S…
|
NVD-CWE-noinfo
|
CVE-2017-18276
|
2024-11-21 12:19 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253900
|
7.8 |
HIGH
Local
|
qualcomm
|
mdm9206_firmware mdm9607_firmware mdm9650_firmware msm8996au_firmware sd_210_firmware sd_212_firmware sd_205_firmware sd_625_firmware sd_820_firmware sd_820a_firmware sd…
|
While processing camera buffers in camera driver, a use after free condition can occur in Snapdragon Automobile, Snapdragon Mobile, Snapdragon Wear in MDM9206, MDM9607, MDM9650, MSM8996AU, SD 210/SD …
|
CWE-416
Use After Free
|
CVE-2017-18156
|
2024-11-21 12:19 |
2019-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|