Total
168 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2017-17736 | 1 Kentico | 1 Kentico Cms | 2019-10-03 | 7.5 HIGH | 9.8 CRITICAL |
Kentico 9.0 before 9.0.51 and 10.0 before 10.0.48 allows remote attackers to obtain Global Administrator access by visiting CMSInstall/install.aspx and then navigating to the CMS Administration Dashboard. | |||||
CVE-2018-19620 | 1 Showdoc | 1 Showdoc | 2019-10-03 | 4.0 MEDIUM | 4.3 MEDIUM |
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id. | |||||
CVE-2017-2143 | 1 Frogman Office Inc | 2 Cs-cart Japanese Edition, Cs-cart Multivendor Japanese Edition | 2019-10-03 | 5.0 MEDIUM | 5.3 MEDIUM |
CS-Cart Japanese Edition v4.3.10-jp-1 and earlier, CS-Cart Multivendor Japanese Edition v4.3.10-jp-1 and earlier allows remote attackers to bypass access restriction to create a request to return a customer purchased item via rma.post.php. | |||||
CVE-2018-18862 | 1 Bmc | 2 Remedy Action Request System, Remedy Mid-tier | 2019-10-03 | 6.5 MEDIUM | 8.8 HIGH |
BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/. | |||||
CVE-2017-2161 | 1 Toshiba | 1 Flashair | 2019-10-03 | 2.7 LOW | 3.5 LOW |
FlashAirTM SDHC Memory Card (SD-WE Series <W-03>) V3.00.02 and earlier and FlashAirTM SDHC Memory Card (SD-WD/WC Series <W-02>) V2.00.04 and earlier allows authenticated attackers to bypass access restrictions to obtain unauthorized image data via unspecified vectors. | |||||
CVE-2017-2139 | 1 Frogman Office Inc | 1 Cs-cart | 2019-10-03 | 5.0 MEDIUM | 5.3 MEDIUM |
CS-Cart Japanese Edition v4.3.10 and earlier (excluding v2 and v3), CS-Cart Multivendor Japanese Edition v4.3.10 and earlier (excluding v2 and v3) allows remote attackers to bypass access restriction to obtain customer information via orders.pre.php. | |||||
CVE-2018-19207 | 1 Van-ons | 1 Wp-gdpr-compliance | 2019-10-03 | 7.5 HIGH | 9.8 CRITICAL |
The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018. | |||||
CVE-2017-10833 | 1 Nippon-antenna | 2 Scr02hd, Scr02hd Firmware | 2019-10-03 | 6.4 MEDIUM | 9.1 CRITICAL |
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows remote attackers to bypass access restriction to view information or modify configurations via unspecified vectors. |