Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-08-25 CVE-2017-12817 Missing Encryption of Sensitive Data vulnerability in Kaspersky Internet Security 11.12.4.1622
In Kaspersky Internet Security for Android 11.12.4.1622, some of the application trace files were not encrypted.
network
low complexity
kaspersky CWE-311
7.5
2017-08-25 CVE-2017-9650 Unrestricted Upload of File with Dangerous Type vulnerability in multiple products
An Unrestricted Upload of File with Dangerous Type issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior.
local
low complexity
automatedlogic carrier CWE-434
7.8
2017-08-25 CVE-2017-9644 Unquoted Search Path or Element vulnerability in multiple products
An Unquoted Search Path or Element issue was discovered in Automated Logic Corporation (ALC) ALC WebCTRL, i-Vu, SiteScan Web 6.5 and prior; ALC WebCTRL, SiteScan Web 6.1 and prior; ALC WebCTRL, i-Vu 6.0 and prior; ALC WebCTRL, i-Vu, SiteScan Web 5.5 and prior; and ALC WebCTRL, i-Vu, SiteScan Web 5.2 and prior.
local
high complexity
automatedlogic carrier CWE-428
7.0
2017-08-25 CVE-2017-7930 Improper Authentication vulnerability in Osisoft PI Data Archive
An Improper Authentication issue was discovered in OSIsoft PI Server 2017 PI Data Archive versions prior to 2017.
network
high complexity
osisoft CWE-287
7.4
2017-08-25 CVE-2017-7926 Cross-Site Request Forgery (CSRF) vulnerability in Osisoft PI web API 1.8
A Cross-Site Request Forgery issue was discovered in OSIsoft PI Web API versions prior to 2017 (1.9.0).
network
low complexity
osisoft CWE-352
8.8
2017-08-25 CVE-2017-12857 Information Exposure vulnerability in Polycom Unified Communications Software
Polycom SoundStation IP, VVX, and RealPresence Trio that are running software older than UCS 4.0.12, 5.4.5 rev AG, 5.4.7, 5.5.2, or 5.6.0 are affected by a vulnerability in their UCS web application.
network
low complexity
polycom CWE-200
8.8
2017-08-25 CVE-2017-12694 Path Traversal vulnerability in Spidercontrol Scada web Server
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server.
network
low complexity
spidercontrol CWE-22
7.5
2017-08-25 CVE-2015-4181 Path Traversal vulnerability in PHPmybackuppro
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.5 allows remote attackers to read arbitrary files via a ..
network
low complexity
phpmybackuppro CWE-22
7.5
2017-08-25 CVE-2015-4180 Path Traversal vulnerability in PHPmybackuppro
Directory traversal vulnerability in get_file.php in phpMyBackupPro 2.1 through 2.4 allows remote attackers to read arbitrary files via a ..
network
low complexity
phpmybackuppro CWE-22
7.5
2017-08-25 CVE-2015-4017 Improper Certificate Validation vulnerability in Saltstack Salt 2014.7.5
Salt before 2014.7.6 does not verify certificates when connecting via the aliyun, proxmox, and splunk modules.
network
low complexity
saltstack CWE-295
7.5