Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-16 CVE-2018-0515 Untrusted Search Path vulnerability in Flets Azukeru Backup Tool 1.5.2.6
Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
flets CWE-426
7.8
2018-02-16 CVE-2017-18190 Authentication Bypass by Spoofing vulnerability in multiple products
A localhost.localdomain whitelist entry in valid_host() in scheduler/client.c in CUPS before 2.2.2 allows remote attackers to execute arbitrary IPP commands by sending POST requests to the CUPS daemon in conjunction with DNS rebinding.
network
low complexity
apple debian canonical CWE-290
7.5
2018-02-16 CVE-2018-7176 Cross-Site Request Forgery (CSRF) vulnerability in Frontaccounting 2.4.3
FrontAccounting 2.4.3 suffers from a CSRF flaw, which leads to adding a user account via admin/users.php (aka the "add user" feature of the User Permissions page).
network
low complexity
frontaccounting CWE-352
8.8
2018-02-16 CVE-2017-14535 OS Command Injection vulnerability in Netfortris Trixbox 2.8.0.4
trixbox 2.8.0.4 has OS command injection via shell metacharacters in the lang parameter to /maint/modules/home/index.php.
network
low complexity
netfortris CWE-78
8.8
2018-02-15 CVE-2018-6316 Incorrect Authorization vulnerability in Ivanti Endpoint Security 8.5
Ivanti Endpoint Security (formerly HEAT Endpoint Management and Security Suite) 8.5 Update 1 and earlier allows an authenticated user with low privileges and access to the local network to bypass application whitelisting when using the Application Control module on Ivanti Endpoint Security in lockdown mode.
network
high complexity
ivanti CWE-863
7.5
2018-02-15 CVE-2017-8984 Unspecified vulnerability in HP Intelligent Management Center 7.3
A remote code execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0506P03 was found.
network
low complexity
hp
8.8
2018-02-15 CVE-2017-8983 Improper Input Validation vulnerability in HP Intelligent Management Center 7.3
A Remote Code Execution vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
network
low complexity
hp CWE-20
8.8
2018-02-15 CVE-2017-8982 Unspecified vulnerability in HP Intelligent Management Center 7.3
A Remote Authentication Restriction Bypass vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P4 was found.
network
low complexity
hp
7.5
2018-02-15 CVE-2017-8980 Information Exposure vulnerability in HP Intelligent Management Center 7.3
A Remote Disclosure of Information vulnerability in HPE Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
network
low complexity
hp CWE-200
7.5
2018-02-15 CVE-2017-8967 Deserialization of Untrusted Data vulnerability in HP Intelligent Management Center 7.3
A Deserialization of Untrusted Data vulnerability in Hewlett Packard Enterprise Intelligent Management Center (iMC) PLAT version 7.3 E0504P2 was found.
network
low complexity
hp CWE-502
8.8