Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-02-06 CVE-2016-3952 Credentials Management vulnerability in Web2Py
web2py before 2.14.1, when using the standalone version, allows remote attackers to obtain environment variable values via a direct request to examples/template_examples/beautify.
local
low complexity
web2py CWE-255
7.8
2018-02-06 CVE-2018-6389 Resource Exhaustion vulnerability in Wordpress
In WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of registered .js files (from wp-includes/script-loader.php) to construct a series of requests to load every file many times.
network
low complexity
wordpress CWE-400
7.5
2018-02-06 CVE-2017-6201 Server-Side Request Forgery (SSRF) vulnerability in Sandstorm
A Server Side Request Forgery vulnerability exists in the install app process in Sandstorm before build 0.203.
network
low complexity
sandstorm CWE-918
8.1
2018-02-06 CVE-2017-17996 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Flexense Syncbreeze
A buffer overflow vulnerability in "Add command" functionality exists in Flexense SyncBreeze Enterprise <= 10.3.14.
network
low complexity
flexense CWE-119
8.8
2018-02-06 CVE-2014-5282 Improper Input Validation vulnerability in Docker
Docker before 1.3 does not properly validate image IDs, which allows remote attackers to redirect to another image through the loading of untrusted images via 'docker load'.
network
low complexity
docker CWE-20
8.1
2018-02-06 CVE-2014-5280 Cross-Site Request Forgery (CSRF) vulnerability in Boot2Docker
boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication.
network
low complexity
boot2docker CWE-352
8.8
2018-02-06 CVE-2014-5279 Improper Access Control vulnerability in Boot2Docker
The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers.
network
low complexity
boot2docker CWE-284
8.8
2018-02-06 CVE-2018-6290 Unspecified vulnerability in Kaspersky Secure Mail Gateway 1.1
Local Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
local
low complexity
kaspersky
7.8
2018-02-06 CVE-2018-6288 Cross-Site Request Forgery (CSRF) vulnerability in Kaspersky Secure Mail Gateway 1.1
Cross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
network
low complexity
kaspersky CWE-352
8.8
2018-02-06 CVE-2018-6467 Cross-Site Request Forgery (CSRF) vulnerability in Flickrrss Project Flickrrss 5.3.1
The flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.
network
low complexity
flickrrss-project CWE-352
8.8