|
257711
|
9.8 |
CRITICAL
Network
|
moxa
|
softcms_lab_view
|
A SQL Injection issue was discovered in Moxa SoftCMS Live Viewer through 1.6. An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability has been identified…
|
CWE-89
SQL Injection
|
CVE-2017-12729
|
2024-11-21 12:10 |
2018-01-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257712
|
5.9 |
MEDIUM
Network
|
gm
|
shanghai_onstar
|
A Man-in-the-Middle issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to intercept sensitiv…
|
CWE-200
Information Exposure
|
CVE-2017-12697
|
2024-11-21 12:10 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257713
|
8.8 |
HIGH
Network
|
gm
|
shanghai_onstar
|
An Improper Authentication issue was discovered in General Motors (GM) and Shanghai OnStar (SOS) SOS iOS Client 7.1. Successful exploitation of this vulnerability may allow an attacker to subvert sec…
|
CWE-287
Improper Authentication
|
CVE-2017-12695
|
2024-11-21 12:10 |
2018-01-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257714
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_file_sharing_script
|
PHPJabbers File Sharing Script 1.0 has stored XSS in the comments section.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12813
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257715
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_night_club_booking_software
|
PHPJabbers Night Club Booking Software has stored XSS in the name parameter in the reservations tab.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12812
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257716
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_star_rating_script
|
PHPJabbers Star Rating Script 4.0 has stored XSS via a rating item.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12811
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257717
|
6.1 |
MEDIUM
Network
|
stivasoft
|
phpjabbers_newsletter_script
|
PHPJabbers PHP Newsletter Script 4.2 has stored XSS in lists in the admin panel.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12810
|
2024-11-21 12:10 |
2017-12-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257718
|
7.8 |
HIGH
Local
|
tracker-software
|
pdf-xchange_viewer
|
The launchURL function in PDF-XChange Viewer 2.5 (Build 314.0) might allow remote attackers to execute arbitrary code via a crafted PDF file.
|
CWE-20
Improper Input Validation
|
CVE-2017-13056
|
2024-11-21 12:10 |
2017-12-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257719
|
7.5 |
HIGH
Network
|
siemens
|
simatic_s7-200_firmware simatic_s7-400pn_v6_firmware simatic_s7-400h_v6_firmware simatic_s7-400pn\/dp_v7_firmware simatic_s7-410_v8_firmware simatic_s7-300_firmware simatic_s7-1200_…
|
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
|
-
|
CVE-2017-12741
|
2024-11-21 12:10 |
2017-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257720
|
5.9 |
MEDIUM
Network
|
siemens
|
logo\!_soft_comfort
|
Siemens LOGO! Soft Comfort (All versions before V8.2) lacks integrity verification of software packages downloaded via an unprotected communication channel. This could allow a remote attacker to mani…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2017-12740
|
2024-11-21 12:10 |
2017-12-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|