| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2017-17699 | — | Cri | 0.64 | 9.8 | 0.00 | Dec 15, 2017 | K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request. | |
| CVE-2017-14101 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2017 | A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP… | ||
| CVE-2017-17672 | Cri | 0.68 | 9.8 | 0.15 | Dec 14, 2017 | In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which… | ||
| CVE-2017-17671 | Cri | 0.64 | 9.8 | 0.05 | Dec 14, 2017 | vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ traversal is… | ||
| CVE-2017-17648 | — | Cri | 0.67 | 9.8 | 0.01 | Dec 13, 2017 | Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter. | |
| CVE-2017-14590 | Cri | 0.59 | 9.1 | 0.00 | Dec 13, 2017 | Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least… | ||
| CVE-2017-14589 | Cri | 0.62 | 9.6 | 0.00 | Dec 13, 2017 | It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute… | ||
| CVE-2017-17642 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job. | |
| CVE-2017-17641 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter. | ||
| CVE-2017-17640 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter. | |
| CVE-2017-17639 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter. | |
| CVE-2017-17638 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter. | ||
| CVE-2017-17637 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter. | |
| CVE-2017-17636 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter. | |
| CVE-2017-17635 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter. | |
| CVE-2017-17634 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | ||
| CVE-2017-17633 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter. | |
| CVE-2017-17632 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter. | ||
| CVE-2017-17631 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter. | |
| CVE-2017-17630 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Yoga Class Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17629 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter. | |
| CVE-2017-17628 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter. | ||
| CVE-2017-17627 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter. | ||
| CVE-2017-17626 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter. | ||
| CVE-2017-17625 | Cri | 0.67 | 9.8 | 0.02 | Dec 13, 2017 | Professional Service Script 1.0 has SQL Injection via the service-list city parameter. | ||
| CVE-2017-17624 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter. | ||
| CVE-2017-17623 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter. | |
| CVE-2017-17622 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter. | ||
| CVE-2017-17621 | — | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI. | |
| CVE-2017-17620 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter. | |
| CVE-2017-17619 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Laundry Booking Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17618 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter. | |
| CVE-2017-17617 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter. | |
| CVE-2017-17616 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Event Search Script 1.0 has SQL Injection via the /event-list city parameter. | |
| CVE-2017-17614 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Food Order Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17613 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter. | ||
| CVE-2017-17612 | Cri | 0.67 | 9.8 | 0.04 | Dec 13, 2017 | Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter. | ||
| CVE-2017-17611 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Doctor Search Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17610 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter. | ||
| CVE-2017-17609 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter. | ||
| CVE-2017-17608 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Child Care Script 1.0 has SQL Injection via the /list city parameter. | ||
| CVE-2017-17607 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail. | ||
| CVE-2017-17606 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter. | |
| CVE-2017-17605 | — | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter. | |
| CVE-2017-17604 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter. | ||
| CVE-2017-17603 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter. | ||
| CVE-2017-17602 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter. | ||
| CVE-2017-17601 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter. | ||
| CVE-2017-17600 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter. | ||
| CVE-2017-17599 | Cri | 0.67 | 9.8 | 0.03 | Dec 13, 2017 | Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter. |
- risk 0.64cvss 9.8epss 0.00
K7Sentry.sys 15.1.0.59 in K7 Antivirus 15.1.0309 has a NULL pointer dereference via a 0x950025ac DeviceIoControl request.
- risk 0.64cvss 9.8epss 0.01
A security researcher found an XML External Entity (XXE) vulnerability on the Conserus Image Repository archive solution version 2.1.1.105 by McKesson Medical Imaging Company, which is now a Change Healthcare company. An unauthenticated user supplying a modified HTTP SOAP…
- risk 0.68cvss 9.8epss 0.15
In vBulletin through 5.3.x, there is an unauthenticated deserialization vulnerability that leads to arbitrary file deletion and, under certain circumstances, code execution, because of unsafe usage of PHP's unserialize() in vB_Library_Template's cacheTemplates() function, which…
- risk 0.64cvss 9.8epss 0.05
vBulletin through 5.3.x on Windows allows remote PHP code execution because a require_once call is reachable with an unauthenticated request that can include directory traversal sequences to specify an arbitrary pathname, and because ../ traversal is blocked but ..\ traversal is…
- risk 0.67cvss 9.8epss 0.01
Entrepreneur Dating Script 2.0.1 has SQL Injection via the search_result.php marital, gender, country, or profileid parameter.
- risk 0.59cvss 9.1epss 0.00
Bamboo did not check that the name of a branch in a Mercurial repository contained argument parameters. An attacker who has permission to create a repository in Bamboo, edit an existing plan that has a non-linked Mercurialrepository, create or edit a plan when there is at least…
- risk 0.62cvss 9.6epss 0.00
It was possible for double OGNL evaluation in FreeMarker templates through Struts FreeMarker tags to occur. An attacker who has restricted administration rights to Bamboo or who hosts a website that a Bamboo administrator visits, is able to exploit this vulnerability to execute…
- risk 0.67cvss 9.8epss 0.03
Basic Job Site Script 2.0.5 has SQL Injection via the keyword parameter to /job.
- risk 0.67cvss 9.8epss 0.03
Resume Clone Script 2.0.5 has SQL Injection via the preview.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Advanced World Database 2.0.5 has SQL Injection via the city.php country or state parameter, or the state.php country parameter.
- risk 0.67cvss 9.8epss 0.03
Muslim Matrimonial Script 3.02 has SQL Injection via the success-story.php succid parameter.
- risk 0.67cvss 9.8epss 0.03
Groupon Clone Script 3.01 has SQL Injection via the city_ajax.php state_id parameter.
- risk 0.67cvss 9.8epss 0.03
Car Rental Script 2.0.4 has SQL Injection via the countrycode1.php val parameter.
- risk 0.67cvss 9.8epss 0.03
MLM Forced Matrix 2.0.9 has SQL Injection via the news-detail.php newid parameter.
- risk 0.67cvss 9.8epss 0.03
MLM Forex Market Plan Script 2.0.4 has SQL Injection via the news_detail.php newid parameter or the event_detail.php eventid parameter.
- risk 0.67cvss 9.8epss 0.03
Single Theater Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Multiplex Movie Theater Booking Script 3.1.5 has SQL Injection via the trailer-detail.php moid parameter, show-time.php moid parameter, or event-detail.php eid parameter.
- risk 0.67cvss 9.8epss 0.03
Responsive Events And Movie Ticket Booking Script 3.2.1 has SQL Injection via the findcity.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Multireligion Responsive Matrimonial 4.7.2 has SQL Injection via the success-story.php succid parameter.
- risk 0.67cvss 9.8epss 0.03
Yoga Class Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Secure E-commerce Script 2.0.1 has SQL Injection via the category.php searchmain or searchcat parameter, or the single_detail.php sid parameter.
- risk 0.67cvss 9.8epss 0.03
Responsive Realestate Script 3.2 has SQL Injection via the property-list tbud parameter.
- risk 0.67cvss 9.8epss 0.03
Readymade Video Sharing Script 3.2 has SQL Injection via the single-video-detail.php report_videos array parameter.
- risk 0.67cvss 9.8epss 0.03
Readymade PHP Classified Script 3.3 has SQL Injection via the /categories subctid or mctid parameter.
- risk 0.67cvss 9.8epss 0.02
Professional Service Script 1.0 has SQL Injection via the service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
PHP Multivendor Ecommerce 1.0 has SQL Injection via the single_detail.php sid parameter, or the category.php searchcat or chid1 parameter.
- risk 0.67cvss 9.8epss 0.03
Opensource Classified Ads Script 3.2 has SQL Injection via the advance_result.php keyword parameter.
- risk 0.67cvss 9.8epss 0.04
Online Exam Test Application Script 1.6 has SQL Injection via the exams.php sort parameter.
- risk 0.67cvss 9.8epss 0.04
Multivendor Penny Auction Clone Script 1.0 has SQL Injection via the PATH_INFO to the /detail URI.
- risk 0.67cvss 9.8epss 0.03
Lawyer Search Script 1.1 has SQL Injection via the /lawyer-list city parameter.
- risk 0.67cvss 9.8epss 0.04
Laundry Booking Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
- risk 0.67cvss 9.8epss 0.03
Foodspotting Clone Script 1.0 has SQL Injection via the quicksearch.php q parameter.
- risk 0.67cvss 9.8epss 0.03
Event Search Script 1.0 has SQL Injection via the /event-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Food Order Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Freelance Website Script 2.0.6 has SQL Injection via the jobdetails.php pr_id parameter or the searchbycat_list.php catid parameter.
- risk 0.67cvss 9.8epss 0.04
Hot Scripts Clone 3.1 has SQL Injection via the /categories subctid or mctid parameter.
- risk 0.67cvss 9.8epss 0.03
Doctor Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
E-commerce MLM Software 1.0 has SQL Injection via the service_detail.php pid parameter, event_detail.php eventid parameter, or news_detail.php newid parameter.
- risk 0.67cvss 9.8epss 0.03
Chartered Accountant Booking Script 1.0 has SQL Injection via the /service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Child Care Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
CMS Auditor Website 1.0 has SQL Injection via the PATH_INFO to /news-detail.
- risk 0.67cvss 9.8epss 0.03
Co-work Space Search Script 1.0 has SQL Injection via the /list city parameter.
- risk 0.67cvss 9.8epss 0.03
Consumer Complaints Clone Script 1.0 has SQL Injection via the other-user-profile.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Entrepreneur Bus Booking Script 3.0.4 has SQL Injection via the booker_details.php sourcebus parameter.
- risk 0.67cvss 9.8epss 0.03
Advanced Real Estate Script 4.0.7 has SQL Injection via the search-results.php Projectmain, proj_type, searchtext, sell_price, or maxprice parameter.
- risk 0.67cvss 9.8epss 0.03
Advance B2B Script 2.1.3 has SQL Injection via the tradeshow-list-detail.php show_id or view-product.php pid parameter.
- risk 0.67cvss 9.8epss 0.03
Cab Booking Script 1.0 has SQL Injection via the /service-list city parameter.
- risk 0.67cvss 9.8epss 0.03
Basic B2B Script 2.0.8 has SQL Injection via the product_details.php id parameter.
- risk 0.67cvss 9.8epss 0.03
Advance Online Learning Management Script 3.1 has SQL Injection via the courselist.php subcatid or popcourseid parameter.