|
198001
|
6.1 |
MEDIUM
Network
|
moodle
|
moodle
|
Moodle 3.x has XSS in the contact form on the "non-respondents" page in non-anonymous feedback.
|
CWE-79
Cross-site Scripting
|
CVE-2017-12156
|
2024-11-21 12:08 |
2017-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198002
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that Microsoft E…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11766
|
2024-11-21 12:08 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198003
|
5.3 |
MEDIUM
Network
|
microsoft
|
exchange_server
|
Microsoft Exchange Server 2013 and Microsoft Exchange Server 2016 allow an input sanitization issue with Microsoft Exchange that could potentially result in unintended Information Disclosure, aka "Mi…
|
CWE-200
Information Exposure
|
CVE-2017-11761
|
2024-11-21 12:08 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198004
|
7.5 |
HIGH
Network
|
microsoft
|
edge
|
Microsoft Edge in Microsoft Windows 10 1607, 1703, and Windows Server 2016 allows an attacker to execute arbitrary code in the context of the current user, due to the way that the Microsoft Edge scri…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2017-11764
|
2024-11-21 12:08 |
2017-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198005
|
7.0 |
HIGH
Local
|
linux
|
linux_kernel
|
The driver_override implementation in drivers/base/platform.c in the Linux kernel before 4.12.1 allows local users to gain privileges by leveraging a race condition between a read operation and a sto…
|
CWE-362
Race Condition
|
CVE-2017-12146
|
2024-11-21 12:08 |
2017-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198006
|
6.5 |
MEDIUM
Network
|
synology
|
photo_station
|
Server-side request forgery (SSRF) vulnerability in file_upload.php in Synology Photo Station before 6.7.4-3433 and 6.3-2968 allows remote authenticated users to download arbitrary local files via th…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2017-12071
|
2024-11-21 12:08 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198007
|
5.4 |
MEDIUM
Network
|
wolfcms
|
wolf_cms
|
Wolf CMS 0.8.3.1 allows Cross-Site Scripting (XSS) attacks. The vulnerability exists due to insufficient sanitization of the file name in a "create-file-popup" action, and the directory name in a "cr…
|
CWE-79
Cross-site Scripting
|
CVE-2017-11611
|
2024-11-21 12:08 |
2017-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198008
|
5.9 |
MEDIUM
Network
|
gnu
|
glibc
|
Use-after-free vulnerability in the clntudp_call function in sunrpc/clnt_udp.c in the GNU C Library (aka glibc or libc6) before 2.26 allows remote attackers to have unspecified impact via vectors rel…
|
CWE-416
Use After Free
|
CVE-2017-12133
|
2024-11-21 12:08 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198009
|
8.8 |
HIGH
Network
|
cesanta
|
mongoose_embedded_web_server_library
|
Cross-site request forgery (CSRF) vulnerability in Mongoose Web Server before 6.9 allows remote attackers to hijack the authentication of users for requests that modify Mongoose.conf via a request to…
|
CWE-352
Origin Validation Error
|
CVE-2017-11567
|
2024-11-21 12:08 |
2017-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198010
|
8.2 |
HIGH
Network
|
siemens ocpfoundation
|
simatic_pcs7 wincc ua_.net local_discovery_server
|
An XXE vulnerability has been identified in OPC Foundation UA .NET Sample Code before 2017-03-21 and Local Discovery Server (LDS) before 1.03.367. Among the affected products are Siemens SIMATIC PCS7…
|
CWE-611
XXE
|
CVE-2017-12069
|
2024-11-21 12:08 |
2017-08-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|