Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-09-14 CVE-2017-1002003 Unrestricted Upload of File with Dangerous Type vulnerability in Wp2Android-Turn-Wp-Site-Into-Android-App Project Wp2Android-Turn-Wp-Site-Into-Android-App 1.1.4
Vulnerability in wordpress plugin wp2android-turn-wp-site-into-android-app v1.1.4, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
7.5
2017-09-14 CVE-2017-1002002 Unrestricted Upload of File with Dangerous Type vulnerability in Webapp-Builder Project Webapp-Builder 2.0
Vulnerability in wordpress plugin webapp-builder v2.0, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com/
network
low complexity
webapp-builder-project CWE-434
7.5
2017-09-14 CVE-2017-1002001 Unrestricted Upload of File with Dangerous Type vulnerability in Mobile-App-Builder-By-Wappress Project Mobile-App-Builder-By-Wappress 1.05
Vulnerability in wordpress plugin mobile-app-builder-by-wappress v1.05, The plugin includes unlicensed vulnerable CMS software from http://www.invedion.com.
7.5
2017-09-14 CVE-2017-1002000 Unrestricted Upload of File with Dangerous Type vulnerability in Mobile-Friendly-App-Builder-By-Easytouch Project Mobile-Friendly-App-Builder-By-Easytouch 3.0
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.
7.5
2017-09-14 CVE-2017-13779 Incorrect Permission Assignment for Critical Resource vulnerability in Gstn India Goods and Services TAX Network Offline Utility Tool 1.1
GSTN_offline_tool in India Goods and Services Tax Network (GSTN) Offline Utility tool before 1.2 executes winstart-server.vbs from the "C:\GST Offline Tool" directory, which has insecure permissions.
local
low complexity
gstn CWE-732
7.2
2017-09-14 CVE-2017-13725 Out-of-bounds Read vulnerability in multiple products
The IPv6 routing header parser in tcpdump before 4.9.2 has a buffer over-read in print-rt6.c:rt6_print().
network
low complexity
tcpdump debian CWE-125
7.5
2017-09-14 CVE-2017-13690 Out-of-bounds Read vulnerability in Tcpdump
The IKEv2 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c, several functions.
network
low complexity
tcpdump CWE-125
7.5
2017-09-14 CVE-2017-13689 Out-of-bounds Read vulnerability in Tcpdump
The IKEv1 parser in tcpdump before 4.9.2 has a buffer over-read in print-isakmp.c:ikev1_id_print().
network
low complexity
tcpdump CWE-125
7.5
2017-09-14 CVE-2017-13688 Out-of-bounds Read vulnerability in Tcpdump
The OLSR parser in tcpdump before 4.9.2 has a buffer over-read in print-olsr.c:olsr_print().
network
low complexity
tcpdump CWE-125
7.5
2017-09-14 CVE-2017-13687 Out-of-bounds Read vulnerability in multiple products
The Cisco HDLC parser in tcpdump before 4.9.2 has a buffer over-read in print-chdlc.c:chdlc_print().
network
low complexity
tcpdump debian CWE-125
7.5