Unknown · CVSS Not scored
Open redirect vulnerability in WordPress Download Manager prior to version 2.9.51 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Douroshisetu Kihon Data Sakusei System Ver1.0.2 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in WordPress Download Manager prior to version 2.9.50 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of "Setup file of advance preparation" (jizen_setup.exe) (The version which was available on the website prior to 2017 June 12) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Directory traversal vulnerability in Shortcodes Ultimate prior to version 4.10.0 allows remote attackers to read arbitrary files via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of Shinseiyo Sogo Soft (4.8A) and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in The installer of Charamin OMP Version 1.1.7.4 and earlier, Version 1.2.0.0 Beta and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
SQL injection vulnerability in the AssetView for MacOS Ver.9.2.0 and earlier versions allows remote attackers to execute arbitrary SQL commands via "File Transfer Web Service".
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of Lhaz+ version 3.4.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 14, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via WebUI.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in Source code security studying tool iCodeChecker allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to bypass authentication to load malicious firmware via WebUI.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
HOME SPOT CUBE2 firmware V101 and earlier allows authenticated attackers to execute arbitrary OS commands via Clock Settings.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Buffer overflow in HOME SPOT CUBE2 firmware V101 and earlier allows an attacker to execute arbitrary code via WebUI.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cross-site scripting vulnerability in Cybozu KUNAI for Android 3.0.0 to 3.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Session fixation vulnerability in Cybozu Garoon 4.0.0 to 4.2.4 allows remote attackers to perform arbitrary operations via unspecified vectors.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Untrusted search path vulnerability in Installer of Denshinouhin Check System (for Ministry of Agriculture, Forestry and Fisheries Nouson Seibi Jigyou) 2014 March Edition (Ver.9.0.001.001) [Updated on 2017 June 9], (Ver.8.0.001.001) [Updated on 2016 May 31] and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Cybozu Garoon 3.0.0 to 4.2.4 may allow an attacker to lock another user's file through a specially crafted page.
Published Jul 7, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
WAPM-1166D firmware Ver.1.2.7 and earlier, WAPM-APG600H firmware Ver.1.16.1 and earlier allows remote attackers to bypass authentication and access the configuration interface via unspecified vectors.
Published Jul 22, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
"A vulnerability in the TLS protocol implementation of the Domino server could allow an unauthenticated, remote attacker to access sensitive information, aka a Return of Bleichenbacher's Oracle Threat (ROBOT) attack. An attacker could iteratively query a server running a vulnerable TLS stack implementation to perform cryptanalytic operations that may allow decryption of previously captured TLS sessions."
Published Jul 1, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
"HCL iNotes is susceptible to a Cross-Site Scripting (XSS) Vulnerability. An attacker could use this vulnerability to steal the victim's cookie-based authentication credentials."
Published Jul 1, 2020 · Updated Aug 5, 2024
Unknown · CVSS Not scored
IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125161.
Published Jul 3, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A information disclosure vulnerability in the HTC sensor hub driver. Product: Android. Versions: Android kernel. Android ID: A-35468048.
Published Jul 6, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Tor 0.3.x before 0.3.0.9 has a guard-selection algorithm that only considers the exit relay (not the exit relay's family), which might allow remote attackers to defeat intended anonymity properties by leveraging the existence of large families.
Published Jul 2, 2017 · Updated Aug 5, 2024
Unknown · CVSS Not scored
XSS exists in the login_form function in views/helpers.php in Phamm before 0.6.7, exploitable via the PATH_INFO to main.php.
Published Jul 20, 2017 · Updated Aug 5, 2024
Medium · CVSS 5.5
A vulnerability was reported in Lenovo PC Manager versions prior to 2.6.40.3154 that could allow an attacker to cause a system reboot.
Published Jul 31, 2024 · Updated Aug 1, 2024