Vulnerabilities (CVE)

Total 399069 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2017-14858 1 Exiv2 1 Exiv2 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
There is a heap-based buffer overflow in the Exiv2::l2Data function of types.cpp in Exiv2 0.26. A Crafted input will lead to a denial of service attack.
CVE-2017-14857 1 Exiv2 1 Exiv2 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In Exiv2 0.26, there is an invalid free in the Image class in image.cpp that leads to a Segmentation fault. A crafted input will lead to a denial of service attack.
CVE-2017-14855 1 Redlion 2 Hmi Panel, Hmi Panel Firmware 2026-06-17 7.8 HIGH 8.6 HIGH
Red Lion HMI panels allow remote attackers to cause a denial of service (software exception) via an HTTP POST request to a long URI that does not exist, as demonstrated by version HMI 2.41 PLC 2.42.
CVE-2017-14854 1 Orpak 1 Siteomat 2026-06-17 7.5 HIGH 9.1 CRITICAL
A stack buffer overflow exists in one of the Orpak SiteOmat CGI components, allowing for remote code execution. The vulnerability affects all versions prior to 2017-09-25.
CVE-2017-14853 1 Orpak 1 Siteomat 2026-06-17 10.0 HIGH 8.6 HIGH
The Orpak SiteOmat OrCU component is vulnerable to code injection, for all versions prior to 2017-09-25, due to a search query that uses a direct shell command. By tampering with the request, an attacker is able to run shell commands and receive valid output from the device.
CVE-2017-14852 1 Orpak 1 Siteomat 2026-06-17 5.0 MEDIUM 8.6 HIGH
An insecure communication was found between a user and the Orpak SiteOmat management console for all known versions, due to an invalid SSL certificate. The attack allows for an eavesdropper to capture the communication and decrypt the data.
CVE-2017-14851 1 Orpak 1 Siteomat 2026-06-17 7.5 HIGH 9.8 CRITICAL
A SQL injection vulnerability exists in all Orpak SiteOmat versions prior to 2017-09-25. The vulnerability is in the login page, where the authentication validation process contains an insecure SELECT query. The attack allows for authentication bypass.
CVE-2017-14850 1 Orpak 1 Siteomat 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
All known versions of the Orpak SiteOmat web management console is vulnerable to multiple instances of Stored Cross-site Scripting due to improper external user-input validation. An attacker with access to the web interface is able to hijack sessions or navigate victims outside of SiteOmat, to a malicious server owned by him.
CVE-2017-14849 1 Nodejs 1 Node.js 2026-06-17 5.0 MEDIUM 7.5 HIGH
Node.js 8.5.0 before 8.6.0 allows remote attackers to access unintended files, because a change to ".." handling was incompatible with the pathname validation used by unspecified community modules.
CVE-2017-14848 1 Dasinfomedia 1 Wphrm Human Resource Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
WPHRM Human Resource Management System for WordPress 1.0 allows SQL Injection via the employee_id parameter.
CVE-2017-14847 1 Dasinfomedia 1 Wpams Apartment Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPAMS Apartment Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14846 1 Dasinfomedia 1 Hospital Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla Hospital Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14845 1 Dasinfomedia 1 Wpchurch Church Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPCHURCH Church Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14844 1 Dasinfomedia 1 Wpgym Gym Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla WPGYM WordPress Gym Management System allows SQL Injection via the id parameter.
CVE-2017-14843 1 Dasinfomedia 1 School Management System 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla School Management System for WordPress allows SQL Injection via the id parameter.
CVE-2017-14842 1 Dasinfomedia 1 Smsmaster Multipurpose Sms Gateway 2026-06-17 6.5 MEDIUM 8.8 HIGH
Mojoomla SMSmaster Multipurpose SMS Gateway for WordPress allows SQL Injection via the id parameter.
CVE-2017-14841 1 Dasinfomedia 1 Annual Maintenance Contract Management System 2026-06-17 4.0 MEDIUM 6.5 MEDIUM
Mojoomla Annual Maintenance Contract (AMC) Management System allows Arbitrary File Upload in profilesetting image handling.
CVE-2017-14840 1 Teamworktec 1 Ticketplus 2026-06-17 6.5 MEDIUM 8.8 HIGH
TeamWork TicketPlus allows Arbitrary File Upload in updateProfile.
CVE-2017-14839 1 Teamworktec 1 Photo Fusion 2026-06-17 6.5 MEDIUM 8.8 HIGH
TeamWork Photo Fusion allows Arbitrary File Upload in changeAvatar and changeCover.
CVE-2017-14838 1 Teamworktec 1 Job Links 2026-06-17 6.5 MEDIUM 8.8 HIGH
TeamWork Job Links allows Arbitrary File Upload in profileChange and coverChange.