Total
398740 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2017-1000065 | 1 Openmediavault | 1 Openmediavault | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Multiple Cross-site scripting (XSS) vulnerabilities in rpc.php in OpenMediaVault release 2.1 in Access Rights Management(Users) functionality allows attackers to inject arbitrary web scripts and execute malicious scripts within an authenticated client's browser. | |||||
| CVE-2017-1000064 | 1 Kitto Project | 1 Kitto | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| kittoframework kitto version 0.5.1 is vulnerable to memory exhaustion in the router resulting in DoS | |||||
| CVE-2017-1000063 | 1 Kitto Project | 1 Kitto | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| kittoframework kitto version 0.5.1 is vulnerable to an XSS in the 404 page resulting in information disclosure | |||||
| CVE-2017-1000062 | 1 Kitto Project | 1 Kitto | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| kittoframework kitto 0.5.1 is vulnerable to directory traversal in the router resulting in remote code execution | |||||
| CVE-2017-1000061 | 1 Xmlsec Project | 1 Xmlsec | 2026-06-17 | 5.8 MEDIUM | 7.1 HIGH |
| xmlsec 1.2.23 and before is vulnerable to XML External Entity Expansion when parsing crafted input documents, resulting in possible information disclosure or denial of service | |||||
| CVE-2017-1000060 | 1 Eyesofnetwork | 1 Eyesofnetwork | 2026-06-17 | 10.0 HIGH | 9.8 CRITICAL |
| EyesOfNetwork (EON) 5.1 Unauthenticated SQL Injection in eonweb leading to remote root | |||||
| CVE-2017-1000059 | 1 Livehelperchat | 1 Live Helper Chat | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Live Helper Chat version 2.06v and older is vulnerable to Cross-Site Scripting in the HTTP Header handling resulting in the execution of any user provided Javascript code in the session of other users. | |||||
| CVE-2017-1000058 | 1 Chevereto | 1 Chevereto | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Stored XSS vulnerabilities in chevereto CMS before version 3.8.11, one in the user profile and one in the Exif data parser. | |||||
| CVE-2017-1000056 | 1 Kubernetes | 1 Kubernetes | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| Kubernetes version 1.5.0-1.5.4 is vulnerable to a privilege escalation in the PodSecurityPolicy admission plugin resulting in the ability to make use of any existing PodSecurityPolicy object. | |||||
| CVE-2017-1000054 | 1 Rocketchat | 1 Rocket.chat | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Rocket.Chat version 0.8.0 and newer is vulnerable to XSS in the markdown link parsing code for messages. | |||||
| CVE-2017-1000053 | 1 Plug Project | 1 Plug | 2026-06-17 | 6.8 MEDIUM | 8.1 HIGH |
| Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to arbitrary code execution in the deserialization functions of Plug.Session. | |||||
| CVE-2017-1000052 | 1 Plug Project | 1 Plug | 2026-06-17 | 4.6 MEDIUM | 7.8 HIGH |
| Elixir Plug before v1.0.4, v1.1.7, v1.2.3 and v1.3.2 is vulnerable to null byte injection in the Plug.Static component, which may allow users to bypass filetype restrictions. | |||||
| CVE-2017-1000051 | 1 Xwiki | 1 Cryptpad | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Cross-site scripting (XSS) vulnerability in pad export in XWiki labs CryptPad before 1.1.1 allows remote attackers to inject arbitrary web script or HTML via the pad content | |||||
| CVE-2017-1000050 | 4 Canonical, Fedoraproject, Jasper Project and 1 more | 6 Ubuntu Linux, Fedora, Jasper and 3 more | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| JasPer 2.0.12 is vulnerable to a NULL pointer exception in the function jp2_encode which failed to check to see if the image contained at least one component resulting in a denial-of-service. | |||||
| CVE-2017-1000048 | 1 Qs Project | 1 Qs | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| the web framework using ljharb's qs module older than v6.3.2, v6.2.3, v6.1.2, and v6.0.4 is vulnerable to a DoS. A malicious user can send a evil request to cause the web framework crash. | |||||
| CVE-2017-1000047 | 1 Rbenv Project | 1 Rbenv | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| rbenv (all current versions) is vulnerable to Directory Traversal in the specification of Ruby version resulting in arbitrary code execution | |||||
| CVE-2017-1000046 | 1 Mautic | 1 Mautic | 2026-06-17 | 5.0 MEDIUM | 7.5 HIGH |
| Mautic 2.6.1 and earlier fails to set flags on session cookies | |||||
| CVE-2017-1000044 | 1 Gnome | 1 Gtk-vnc | 2026-06-17 | 7.5 HIGH | 9.8 CRITICAL |
| gtk-vnc 0.4.2 and older doesn't check framebuffer boundaries correctly when updating framebuffer which may lead to memory corruption when rendering | |||||
| CVE-2017-1000043 | 1 Mapbox | 1 Mapbox.js | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Mapbox.js versions 1.x prior to 1.6.6 and 2.x prior to 2.2.4 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON name and map share control | |||||
| CVE-2017-1000042 | 1 Mapbox Project | 1 Mapbox | 2026-06-17 | 4.3 MEDIUM | 6.1 MEDIUM |
| Mapbox.js versions 1.x prior to 1.6.5 and 2.x prior to 2.1.7 are vulnerable to a cross-site-scripting attack in certain uncommon usage scenarios via TileJSON Name. | |||||
