Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2017-05-12 CVE-2016-10331 Path Traversal vulnerability in Synology Photo Station
Directory traversal vulnerability in download.php in Synology Photo Station before 6.5.3-3226 allows remote attackers to read arbitrary files via a full pathname in the id parameter.
network
low complexity
synology CWE-22
7.5
2017-05-12 CVE-2016-10330 Path Traversal vulnerability in Synology Photo Station
Directory traversal vulnerability in synophoto_dsm_user, a SUID program, as used in Synology Photo Station before 6.5.3-3226 allows local users to write to arbitrary files via unspecified vectors.
local
low complexity
synology CWE-22
7.1
2017-05-12 CVE-2017-8921 Path Traversal vulnerability in Flightgear
In FlightGear before 2017.2.1, the FGCommand interface allows overwriting any file the user has write access to, but not with arbitrary data: only with the contents of a FlightGear flightplan (XML).
network
low complexity
flightgear CWE-22
7.5
2017-05-12 CVE-2017-7486 Information Exposure vulnerability in Postgresql
PostgreSQL versions 8.4 - 9.6 are vulnerable to information leak in pg_user_mappings view which discloses foreign server passwords to any user having USAGE privilege on the associated foreign server.
network
low complexity
postgresql CWE-200
7.5
2017-05-12 CVE-2017-7484 Information Exposure vulnerability in Postgresql
It was found that some selectivity estimation functions in PostgreSQL before 9.2.21, 9.3.x before 9.3.17, 9.4.x before 9.4.12, 9.5.x before 9.5.7, and 9.6.x before 9.6.3 did not check user privileges before providing information from pg_statistic, possibly leaking information.
network
low complexity
postgresql CWE-200
7.5
2017-05-12 CVE-2017-2167 Untrusted Search Path vulnerability in Softbank Primedrive Desktop Application 1.4.3/1.4.4
Untrusted search path vulnerability in Installer for PrimeDrive Desktop Application version 1.4.4 and earlier allows remote attackers to execute arbitrary code via a specially crafted executable file in an unspecified directory.
local
low complexity
softbank CWE-426
7.8
2017-05-12 CVE-2017-2163 Path Traversal vulnerability in N-I-Agroinformatics SOY CMS
Directory traversal vulnerability in SOY CMS Ver.1.8.1 to Ver.1.8.12 allows authenticated attackers to read arbitrary files via shop_id.
network
low complexity
n-i-agroinformatics CWE-22
7.5
2017-05-12 CVE-2017-2157 Untrusted Search Path vulnerability in Jpki the Public Certification Service for Individuals 2.6/3.0.1/3.1
Untrusted search path vulnerability in installers for The Public Certification Service for Individuals "The JPKI user's software (for Windows 7 and later)" Ver3.1 and earlier, The Public Certification Service for Individuals "The JPKI user's software (for Windows Vista)", The Public Certification Service for Individuals "The JPKI user's software" Ver2.6 and earlier that were available until April 27, 2017 allows remote attackers to gain privileges via a Trojan horse DLL in an unspecified directory.
local
low complexity
jpki CWE-426
7.3
2017-05-12 CVE-2016-4887 Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Uploader version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
basercms CWE-352
8.8
2017-05-12 CVE-2016-4886 Cross-Site Request Forgery (CSRF) vulnerability in Basercms 3.0.10
Cross-site request forgery (CSRF) vulnerability in baserCMS plugin Mail version 3.0.10 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
network
low complexity
basercms CWE-352
8.8