LiveActive security incident?Get immediate response
CVE archive

June 2017

Browse CVE records published in June 2017, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1499 matching CVEs · Page 3 of 30.

Medium · CVSS 6.3

CVE-2017-20073: Hindu Matrimonial Script cms.php privileges management

A vulnerability has been found in Hindu Matrimonial Script and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/cms.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20074: Hindu Matrimonial Script newsletter1.php privileges management

A vulnerability was found in Hindu Matrimonial Script and classified as critical. Affected by this issue is some unknown functionality of the file /admin/newsletter1.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20075: Hindu Matrimonial Script payment.php privileges management

A vulnerability was found in Hindu Matrimonial Script. It has been classified as critical. This affects an unknown part of the file /admin/payment.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20076: Hindu Matrimonial Script searchview.php privileges management

A vulnerability was found in Hindu Matrimonial Script. It has been declared as critical. This vulnerability affects unknown code of the file /admin/searchview.php. The manipulation leads to improper privilege management. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20077: Hindu Matrimonial Script success_story.php privileges management

A vulnerability was found in Hindu Matrimonial Script. It has been rated as critical. This issue affects some unknown processing of the file /admin/success_story.php. The manipulation leads to improper privilege management. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20078: Hindu Matrimonial Script featured.php privileges management

A vulnerability classified as critical has been found in Hindu Matrimonial Script. Affected is an unknown function of the file /admin/featured.php. The manipulation leads to improper privilege management. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20079: Hindu Matrimonial Script photo.php privileges management

A vulnerability classified as critical was found in Hindu Matrimonial Script. Affected by this vulnerability is an unknown functionality of the file /admin/photo.php. The manipulation leads to improper privilege management. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20080: Hindu Matrimonial Script googleads.php privileges management

A vulnerability, which was classified as critical, has been found in Hindu Matrimonial Script. Affected by this issue is some unknown functionality of the file /admin/googleads.php. The manipulation leads to improper privilege management. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20081: Hindu Matrimonial Script reports.php privileges management

A vulnerability, which was classified as critical, was found in Hindu Matrimonial Script. This affects an unknown part of the file /admin/reports.php. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 21, 2022 · Updated Apr 15, 2025

Medium · CVSS 5.5

CVE-2017-20082: JUNG Smart Visu Server backdoor

A vulnerability, which was classified as problematic, has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. This issue affects some unknown processing. The manipulation leads to backdoor. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 22, 2022 · Updated Apr 15, 2025

Medium · CVSS 5.3

CVE-2017-20083: JUNG Smart Visu Server SSH Server backdoor

A vulnerability, which was classified as critical, was found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832. Affected is an unknown function of the component SSH Server. The manipulation leads to backdoor. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 22, 2022 · Updated Apr 15, 2025

Medium · CVSS 5.3

CVE-2017-20084: JUNG Smart Visu Server KNX Group Address backdoor

A vulnerability has been found in JUNG Smart Visu Server 1.0.804/1.0.830/1.0.832 and classified as critical. Affected by this vulnerability is an unknown functionality of the component KNX Group Address. The manipulation leads to backdoor. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 1.0.900 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 22, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20085: Atahualpa Theme cross site scriting

A vulnerability has been found in Atahualpa Theme and classified as problematic. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20086: VaultPress Plugin code injection

A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20087: Alpine PhotoTile for Instagram Plugin cross site scriting

A vulnerability, which was classified as problematic, has been found in Alpine PhotoTile for Instagram Plugin 1.2.7.7. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20088: Atahualpa Theme cross-site request forgery

A vulnerability classified as problematic has been found in Atahualpa Theme. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20089: Gwolle Guestbook Plugin cross site scriting

A vulnerability was found in Gwolle Guestbook Plugin 1.7.4. It has been rated as problematic. This issue affects some unknown processing. The manipulation leads to basic cross site scripting. The attack may be initiated remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20090: Global Content Blocks Plugin cross-site request forgery

A vulnerability was found in Global Content Blocks Plugin 2.1.5. It has been declared as problematic. This vulnerability affects unknown code. The manipulation leads to cross-site request forgery. The attack can be initiated remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20091: File Manager Plugin cross-site request forgery

A vulnerability was found in File Manager Plugin 3.0.1. It has been classified as problematic. This affects an unknown part. The manipulation leads to cross-site request forgery. It is possible to initiate the attack remotely.

Published Jun 23, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20092: Google Analytics Dashboard Plugin cross site scriting

A vulnerability classified as problematic was found in Google Analytics Dashboard Plugin 2.1.1. Affected by this vulnerability is an unknown functionality. The manipulation leads to basic cross site scripting. The attack can be launched remotely.

Published Jun 24, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20093: Download Manager Plugin cross-site request forgery

A vulnerability, which was classified as problematic, was found in Download Manager Plugin 2.8.99. Affected is an unknown function. The manipulation leads to cross-site request forgery. It is possible to launch the attack remotely.

Published Jun 24, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20094: NewStatPress Plugin Persistent cross site scriting

A vulnerability, which was classified as problematic, has been found in NewStatPress Plugin 1.2.4. This issue affects some unknown processing. The manipulation leads to basic cross site scripting (Persistent). The attack may be initiated remotely. Upgrading to version 1.2.5 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 24, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20095: Simple Ads Manager Plugin code injection

A vulnerability classified as critical was found in Simple Ads Manager Plugin. This vulnerability affects unknown code. The manipulation leads to code injection. The attack can be initiated remotely.

Published Jun 24, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20096: WP-SpamFree Anti-Spam Plugin cross site scriting

A vulnerability classified as problematic has been found in WP-SpamFree Anti-Spam Plugin 2.1.1.4. This affects an unknown part. The manipulation leads to basic cross site scripting. It is possible to initiate the attack remotely.

Published Jun 24, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20097: WP-Filebase Download Manager Plugin cross site scriting

A vulnerability was found in WP-Filebase Download Manager Plugin 3.4.4. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely.

Published Jun 24, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20100: Air Transfer cross site scripting

A vulnerability was found in Air Transfer 1.0.14/1.2.1. It has been rated as problematic. Affected by this issue is some unknown functionality. The manipulation leads to basic cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 27, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20101: ProjectSend information disclosure

A vulnerability, which was classified as problematic, was found in ProjectSend r754. This affects an unknown part of the file process.php?do=zip_download. The manipulation of the argument client/file leads to information disclosure. It is possible to initiate the attack remotely.

Published Jun 27, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.4

CVE-2017-20102: Album Lock getImage path traversal

A vulnerability was found in Album Lock 4.0 and classified as critical. Affected by this issue is some unknown functionality of the file /getImage. The manipulation of the argument filePaht leads to path traversal. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used.

Published Jun 27, 2022 · Updated Apr 15, 2025

High · CVSS 7.3

CVE-2017-20099: Analytics Stats Counter Statistics Plugin code injection

A vulnerability was found in Analytics Stats Counter Statistics Plugin 1.2.2.5 and classified as critical. This issue affects some unknown processing. The manipulation leads to code injection. The attack may be initiated remotely.

Published Jun 27, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20098: Admin Custom Login Plugin Persistent cross site scripting

A vulnerability was found in Admin Custom Login Plugin 2.4.5.2. It has been classified as problematic. Affected is an unknown function. The manipulation leads to basic cross site scripting (Persistent). It is possible to launch the attack remotely.

Published Jun 27, 2022 · Updated Apr 15, 2025

Medium · CVSS 6.3

CVE-2017-20103: Kama Click Counter Plugin admin.php Blind sql injection

A vulnerability classified as critical has been found in Kama Click Counter Plugin up to 3.4.8. This affects an unknown part of the file wp-admin/admin.php. The manipulation of the argument order_by/order with the input ASC%2c(select*from(select(sleep(2)))a) leads to sql injection (Blind). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.4.9 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 27, 2022 · Updated Apr 15, 2025

High · CVSS 7.3

CVE-2017-20104: Simplessus Cookie Time sql injection

A vulnerability was found in Simplessus 3.7.7. It has been declared as critical. This vulnerability affects unknown code of the component Cookie Handler. The manipulation of the argument UWA_SID leads to sql injection (Time). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.8.3 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 28, 2022 · Updated Apr 15, 2025

Medium · CVSS 5.4

CVE-2017-20105: Simplessus path traversal

A vulnerability was found in Simplessus 3.7.7. It has been rated as critical. This issue affects some unknown processing. The manipulation of the argument path with the input ..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2f..%2fetc%2fpasswd leads to path traversal. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 3.8.3 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 28, 2022 · Updated Apr 15, 2025

Medium · CVSS 5.3

CVE-2017-20106: Lithium Forum Compose Message server-side request forgery

A vulnerability, which was classified as critical, has been found in Lithium Forum 2017 Q1. This issue affects some unknown processing of the component Compose Message Handler. The manipulation of the argument upload_url leads to server-side request forgery. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used.

Published Jun 28, 2022 · Updated Apr 15, 2025

Medium · CVSS 5.3

CVE-2017-20107: ShadeYouVPN.com Client privileges management

A vulnerability, which was classified as problematic, was found in ShadeYouVPN.com Client 2.0.1.11. Affected is an unknown function. The manipulation leads to improper privilege management. Local access is required to approach this attack. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.1.12 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 28, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20108: Easy Table Plugin options-general.php cross site scripting

A vulnerability classified as problematic has been found in Easy Table Plugin 1.6. This affects an unknown part of the file /wordpress/wp-admin/options-general.php. The manipulation with the input "><script>alert(1)</script> leads to basic cross site scripting. It is possible to initiate the attack remotely.

Published Jun 29, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20109: Teleopti WFM Administration GetOneTenant Credentials information disclosure

A vulnerability classified as problematic was found in Teleopti WFM up to 7.1.0. Affected by this vulnerability is an unknown functionality of the file /TeleoptiWFM/Administration/GetOneTenant of the component Administration. The manipulation leads to information disclosure (Credentials). The attack can be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

Published Jun 29, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20110: Teleopti WFM Administration Credentials information disclosure

A vulnerability, which was classified as problematic, has been found in Teleopti WFM up to 7.1.0. Affected by this issue is some unknown functionality of the component Administration. The manipulation as part of JSON leads to information disclosure (Credentials). The attack may be launched remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

Published Jun 29, 2022 · Updated Apr 15, 2025

High · CVSS 7.3

CVE-2017-20111: Teleopti WFM Administration privileges management

A vulnerability, which was classified as critical, was found in Teleopti WFM 7.1.0. This affects an unknown part of the component Administration. The manipulation leads to improper privilege management. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. It is recommended to apply a patch to fix this issue.

Published Jun 29, 2022 · Updated Apr 15, 2025

High · CVSS 7.8

CVE-2017-20112: IVPN Client privileges management

A vulnerability has been found in IVPN Client 2.6.6120.33863 and classified as critical. Affected by this vulnerability is an unknown functionality. The manipulation of the argument --up cmd leads to improper privilege management. The attack needs to be approached locally. The exploit has been disclosed to the public and may be used. Upgrading to version 2.6.2 is able to address this issue. It is recommended to upgrade the affected component.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20113: TrueConf Server Stored cross site scripting

A vulnerability, which was classified as problematic, was found in TrueConf Server 4.3.7. This affects an unknown part. The manipulation leads to basic cross site scripting (Stored). It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20114: TrueConf Server Reflected cross site scripting

A vulnerability has been found in TrueConf Server 4.3.7 and classified as problematic. This vulnerability affects unknown code of the file /admin/conferences/get-all-status/. The manipulation of the argument keys[] leads to basic cross site scripting (Reflected). The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20115: TrueConf Server Reflected cross site scripting

A vulnerability was found in TrueConf Server 4.3.7 and classified as problematic. This issue affects some unknown processing of the file /admin/conferences/list/. The manipulation of the argument sort leads to basic cross site scripting (Reflected). The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20116: TrueConf Server Reflected cross site scripting

A vulnerability was found in TrueConf Server 4.3.7. It has been classified as problematic. Affected is an unknown function of the file /admin/group/list/. The manipulation of the argument checked_group_id leads to basic cross site scripting (Reflected). It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20117: TrueConf Server group DOM cross site scripting

A vulnerability was found in TrueConf Server 4.3.7. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/group. The manipulation leads to basic cross site scripting (DOM). The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20118: TrueConf Server DOM cross site scripting

A vulnerability was found in TrueConf Server 4.3.7. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/conferences/list/. The manipulation of the argument domxss leads to basic cross site scripting (DOM). The attack may be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20119: TrueConf Server change-lang redirect

A vulnerability classified as problematic has been found in TrueConf Server 4.3.7. This affects an unknown part of the file /admin/general/change-lang. The manipulation of the argument redirect_url leads to open redirect. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

Medium · CVSS 4.3

CVE-2017-20120: TrueConf Server cross-site request forgery

A vulnerability classified as problematic was found in TrueConf Server 4.3.7. This vulnerability affects unknown code of the file /admin/service/stop/. The manipulation leads to cross-site request forgery. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

Published Jun 29, 2022 · Updated Apr 15, 2025

High · CVSS 7.8

CVE-2017-20121: Teradici Management Console Database Management privileges management

A vulnerability was found in Teradici Management Console 2.2.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Database Management. The manipulation leads to improper privilege management. It is possible to launch the attack on the local host. The exploit has been disclosed to the public and may be used.

Published Jun 30, 2022 · Updated Apr 15, 2025

Low · CVSS 3.5

CVE-2017-20122: Bitrix Site Manager Contact Form cross site scripting

A vulnerability classified as problematic was found in Bitrix Site Manager 12.06.2015. Affected by this vulnerability is an unknown functionality of the component Contact Form. The manipulation of the argument text with the input <img src="http://1"; on onerror="$(’p').text(’Hacked’)" /> leads to basic cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

Published Jun 30, 2022 · Updated Apr 15, 2025