CVE-2017-7991
Exponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
Read MoreExponent CMS 2.4.1 and earlier has SQL injection via a base64 serialized API key (apikey parameter) in the api function of framework/modules/eaas/controllers/eaasController.php.
Read MoreCraft CMS before 2.6.2974 allows XSS attacks.
Read MorePhotopt for Android before 2.0.1 does not verify SSL certificates.
Read MoreThe Broadcom Wi-Fi driver for Android, as used by BlackBerry smartphones before Build AAE570, allows remote attackers to execute arbitrary code in the context of the kernel.
Read MoreKintone mobile for Android 1.0.0 through 1.0.5 does not verify SSL server certificates.
Read More