cve,link,title,description,vendor,products,score,severity,epss,cisa,cisa_published,article,ransomware,exploited,exploited_date,poc,trended,trended_no_1,trended_no_1_date,published,trended_score CVE-2017-15329,https://securityvulnerability.io/vulnerability/CVE-2017-15329,,"Huawei UMA V200R001C00 has a SQL injection vulnerability in the operation and maintenance module. An attacker logs in to the system as a common user and sends crafted HTTP requests that contain malicious SQL statements to the affected system. Due to a lack of input validation on HTTP requests that contain user-supplied input, successful exploitation may allow the attacker to execute arbitrary SQL queries.",McAfee,Uma,8.8,HIGH,0.0008699999889358878,false,,false,false,false,,,false,false,,2018-02-15T16:00:00.000Z,0 CVE-2017-8117,https://securityvulnerability.io/vulnerability/CVE-2017-8117,,The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8120,https://securityvulnerability.io/vulnerability/CVE-2017-8120,,The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8121,https://securityvulnerability.io/vulnerability/CVE-2017-8121,,"The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.",McAfee,Uma,5.3,MEDIUM,0.0009599999757483602,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8122,https://securityvulnerability.io/vulnerability/CVE-2017-8122,,The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.002240000059828162,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8123,https://securityvulnerability.io/vulnerability/CVE-2017-8123,,The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8126,https://securityvulnerability.io/vulnerability/CVE-2017-8126,,The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8118,https://securityvulnerability.io/vulnerability/CVE-2017-8118,,"The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.",McAfee,Uma,2.3,LOW,0.0004400000034365803,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8125,https://securityvulnerability.io/vulnerability/CVE-2017-8125,,The UMA product with software V200R001 and V300R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.,McAfee,Uma,6.1,MEDIUM,0.0008900000248104334,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8127,https://securityvulnerability.io/vulnerability/CVE-2017-8127,,The UMA product with software V200R001 has a cross-site scripting (XSS) vulnerability due to insufficient input validation. An attacker could craft malicious links or scripts to launch XSS attacks.,McAfee,Uma,6.1,MEDIUM,0.0008900000248104334,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8129,https://securityvulnerability.io/vulnerability/CVE-2017-8129,,The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8130,https://securityvulnerability.io/vulnerability/CVE-2017-8130,,"The UMA product with software V200R001 and V300R001 has an information leak vulnerability. An attacker could exploit them to obtain some sensitive information, causing information leak.",McAfee,Uma,6.5,MEDIUM,0.0006500000017695129,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8119,https://securityvulnerability.io/vulnerability/CVE-2017-8119,,The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-22T19:29:00.000Z,0 CVE-2017-8124,https://securityvulnerability.io/vulnerability/CVE-2017-8124,,The UMA product with software V200R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-15T00:00:00.000Z,0 CVE-2017-8128,https://securityvulnerability.io/vulnerability/CVE-2017-8128,,The UMA product with software V200R001 and V300R001 has a privilege elevation vulnerability due to insufficient validation or improper processing of parameters. An attacker could craft specific packets to exploit these vulnerabilities to gain elevated privileges.,McAfee,Uma,9.8,CRITICAL,0.0024500000290572643,false,,false,false,false,,,false,false,,2017-11-15T00:00:00.000Z,0