Skip to main content

Over 150 LLM Providers · Over 5,300 Models The most extensible AI-powered pentesting platform. Open source. Star on GitHub

5,695 of 14,642 · Page 90/114
5.4
CVE-2017-1600

IBM Security Guardium 10.0 Database Activity Monitor is vulnerable to cross-site scripting. This vulnerability allows us

5.4
CVE-2017-1751

IBM Robotic Process Automation with Automation Anywhere 10.0.0 is vulnerable to cross-site scripting. This vulnerability

5.4
CVE-2017-17745

Cross-site scripting (XSS) vulnerability in system_name_set.cgi in TP-Link TL-SG108E 1.0.0 allows authenticated remote a

5.4
CVE-2017-5256

In version 3.5 and prior of Cambium Networks ePMP firmware, all authenticated users have the ability to update the Devic

5.4
CVE-2017-5257

In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows (or guesses) the SNMP read/write (RW)

5.4
CVE-2017-5258

In version 3.5 and prior of Cambium Networks ePMP firmware, an attacker who knows or can guess the RW community string c

5.4
CVE-2017-0304

A SQL injection vulnerability exists in the BIG-IP AFM management UI on versions 12.0.0, 12.1.0, 12.1.1, 12.1.2 and 13.0

5.4
CVE-2017-15312

Huawei SmartCare V200R003C10 has a stored XSS (cross-site scripting) vulnerability in the dashboard module. A remote aut

5.4
CVE-2017-1365

IBM Team Concert (RTC including IBM Rational Collaborative Lifecycle Management 4.0, 5.0., and 6.0) is vulnerable to cro

5.4
CVE-2017-17832

ServersCheck Monitoring Software before 14.2.3 is prone to a cross-site scripting vulnerability as user supplied-data is

5.4
CVE-2017-17904

FS Lynda Clone has XSS via the keywords parameter to tutorial/ or the edit_profile_first_name parameter to user/edit_pro

5.4
CVE-2017-15892

Multiple cross-site scripting (XSS) vulnerabilities in Slash Command Creator in Synology Chat before 2.0.0-1124 allow re

5.4
CVE-2017-17981

PHP Scripts Mall Muslim Matrimonial Script has XSS via the admin/slider_edit.php edit_id parameter.

5.4
CVE-2017-17989

Biometric Shift Employee Management System has XSS via the index.php holiday_name parameter in an edit_holiday action.

5.4
CVE-2017-17991

Biometric Shift Employee Management System has XSS via the expense_name parameter in an index.php?user=expenses request.

5.4
CVE-2017-17993

Biometric Shift Employee Management System has XSS via the amount parameter in an index.php?user=addition_deduction requ

5.4
CVE-2017-17994

Biometric Shift Employee Management System has XSS via the criteria parameter in an index.php?user=competency_criteria r

5.4
CVE-2017-17995

Biometric Shift Employee Management System has XSS via the Last_Name parameter in an index.php?user=ajax request.

5.4
CVE-2017-18004

Zurmo 3.2.3 allows XSS via the latitude or longitude parameter to maps/default/mapAndPoint.

5.3
CVE-2016-10099

Borg (aka BorgBackup) before 1.0.9 has a flaw in the cryptographic protocol used to authenticate the manifest (list of a

5.3
CVE-2016-10100

Borg (aka BorgBackup) before 1.0.9 has a flaw in the way duplicate archive names were processed during manifest recovery

5.3
CVE-2016-1547

An off-path attacker can cause a preemptible client association to be demobilized in NTP 4.2.8p4 and earlier and NTPSec

5.3
CVE-2016-1550

An exploitable vulnerability exists in the message authentication functionality of libntp in ntp 4.2.8p4 and NTPSec a5fb

5.3
CVE-2016-2375

An exploitable out-of-bounds read exists in the handling of the MXIT protocol in Pidgin. Specially crafted MXIT contact

5.3
CVE-2016-6771

An elevation of privilege vulnerability in Telephony could enable a local malicious application to access system functio

5.3
CVE-2016-8605

The mkdir procedure of GNU Guile temporarily changed the process' umask to zero. During that time window, in a multithre

5.3
CVE-2016-7431

NTP before 4.2.8p9 allows remote attackers to bypass the origin timestamp protection mechanism via an origin timestamp o

5.3
CVE-2016-7433

NTP before 4.2.8p9 does not properly perform the initial sync calculations, which allows remote attackers to unspecified

5.3
CVE-2017-5487

wp-includes/rest-api/endpoints/class-wp-rest-users-controller.php in the REST API implementation in WordPress 4.7 before

5.3
CVE-2017-5491

wp-mail.php in WordPress before 4.7.1 might allow remote attackers to bypass intended posting restrictions via a spoofed

5.3
CVE-2016-9677

Citrix Provisioning Services before 7.12 allows attackers to obtain sensitive kernel address information via unspecified

5.3
CVE-2016-5012

In Moodle 3.x, glossary search displays entries without checking user permissions to view them.

5.3
CVE-2016-8642

In Moodle 2.x and 3.x, the question engine allows access to files that should not be available.

5.3
CVE-2016-8644

In Moodle 2.x and 3.x, the capability to view course notes is checked in the wrong context.

5.3
CVE-2017-2576

In Moodle 2.x and 3.x, there is incorrect sanitization of attributes in forums.

5.3
CVE-2017-5541

Directory traversal vulnerability in template/usererror.missing_extension.php in Symphony CMS before 2.6.10 allows remot

5.3
CVE-2015-8859

The send package before 0.11.1 for Node.js allows attackers to obtain the root path via unspecified vectors.

5.3
CVE-2016-9216

An IKE Packet Parsing Denial of Service Vulnerability in the ipsecmgr process of Cisco ASR 5000 Software could allow an

5.3
CVE-2017-3797

A vulnerability in Cisco WebEx Meetings Server could allow an unauthenticated, remote attacker to view the fully qualifi

5.3
CVE-2017-3805

A vulnerability in the web-based management interface of Cisco IOS and Cisco IOx Software could allow an unauthenticated

5.3
CVE-2016-5547

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Libraries). Supported

5.3
CVE-2016-5552

Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Networking). Supporte

5.3
CVE-2016-8300

Vulnerability in the Oracle FLEXCUBE Private Banking component of Oracle Financial Services Applications (subcomponent:

5.3
CVE-2016-8307

Vulnerability in the Oracle FLEXCUBE Universal Banking component of Oracle Financial Services Applications (subcomponent

5.3
CVE-2016-8317

Vulnerability in the Oracle FLEXCUBE Investor Servicing component of Oracle Financial Services Applications (subcomponen

5.3
CVE-2016-8324

Vulnerability in the Oracle FLEXCUBE Core Banking component of Oracle Financial Services Applications (subcomponent: Cor

5.3
CVE-2017-3262

Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Java Mission Control). The supported version tha

5.3
CVE-2017-3297

Vulnerability in the Oracle FLEXCUBE Direct Banking component of Oracle Financial Services Applications (subcomponent: F

5.3
CVE-2017-3311

Vulnerability in the Application Testing Suite component of Oracle Enterprise Manager Grid Control (subcomponent: Test M

5.3
CVE-2017-5610

wp-admin/includes/class-wp-press-this.php in Press This in WordPress before 4.7.2 does not properly restrict visibility

Scan for 2017 Vulnerabilities

CyberStrike detects these CVEs across your infrastructure automatically.

Get Started