Latest CVE Feed
-
9.8
CRITICALCVE-2018-17246
Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an att... Read more
- Published: Dec. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39808
N.V.K.INTER CO., LTD. (NVK) iBSG v3.5 was discovered to contain a hardcoded root password which allows attackers to login with root privileges via the SSH service.... Read more
Affected Products : intelligent_broadband_subscriber_gateway- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-17141
HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.... Read more
- Published: Sep. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-16947
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RPCs. Handling those RPCs results in operations being perf... Read more
- Published: Sep. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2017-12652
libpng before 1.6.32 does not properly check the length of chunks against the user limit.... Read more
- Published: Jul. 10, 2019
- Modified: Jun. 09, 2025
-
9.8
CRITICALCVE-2023-39776
A File Upload vulnerability in PHPJabbers Ticket Support Script v3.2 allows attackers to execute arbitrary code via uploading a crafted file.... Read more
Affected Products : ticket_support_script- Published: Aug. 10, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7667
Adminer through 4.3.1 has SSRF via the server parameter.... Read more
Affected Products : adminer- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7648
An issue was discovered in mj2/opj_mj2_extract.c in OpenJPEG 2.3.0. The output prefix was not checked for length, which could overflow a buffer, when providing a prefix with 50 or more characters on the command line.... Read more
Affected Products : openjpeg- Published: Mar. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39751
TP-Link TL-WR941ND V6 were discovered to contain a buffer overflow via the pSize parameter at /userRpm/PingIframeRpm.... Read more
- Published: Aug. 21, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7633
Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request.... Read more
Affected Products : epicentro- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-8826
ASUS RT-AC51U, RT-AC58U, RT-AC66U, RT-AC1750, RT-ACRH13, and RT-N12 D1 routers with firmware before 3.0.0.4.380.8228; RT-AC52U B1, RT-AC1200 and RT-N600 routers with firmware before 3.0.0.4.380.10446; RT-AC55U and RT-AC55UHP routers with firmware before 3... Read more
Affected Products : rt-ac86u_firmware rt-ac66u_firmware rt-ac51u_firmware rt-ac2900_firmware rt-ac58u_firmware rt-ac1750_firmware rt-n12_d1_firmware rt-ac52u_b1_firmware rt-ac1200_firmware rt-n600_firmware +16 more products- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7584
In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subse... Read more
- Published: Mar. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7575
Google TensorFlow 1.7.x and earlier is affected by a Buffer Overflow vulnerability. The type of exploitation is context-dependent.... Read more
Affected Products : tensorflow- Published: Apr. 24, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7548
In subst.c in zsh through 5.4.2, there is a NULL pointer dereference when using ${(PA)...} on an empty array result.... Read more
- Published: Feb. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7539
On Appear TV XC5000 and XC5100 devices with firmware 3.26.217, it is possible to read OS files with a specially crafted HTTP request (such as GET /../../../../../../../../../../../../etc/passwd) to the web server (fuzzd/0.1.1) running the Maintenance Cent... Read more
- Published: Apr. 17, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7532
Unauthentication vulnerabilities have been identified in Geutebruck G-Cam/EFD-2250 Version 1.12.0.4 and Topline TopFD-2125 Version 3.15.1 IP cameras, which may allow remote code execution.... Read more
- Published: Mar. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7518
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, an attacker with network access to the integrated web server could retrieve default or user defined credentials stored and transmitted in an insecure manner.... Read more
- Published: May. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-39699
IceWarp Mail Server v10.4.5 was discovered to contain a local file inclusion (LFI) vulnerability via the component /calendar/minimizer/index.php. This vulnerability allows attackers to include or execute files from the local file system of the targeted se... Read more
Affected Products : mail_server- Published: Aug. 25, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7666
An issue was discovered in ClipBucket before 4.0.0 Release 4902. SQL injection vulnerabilities exist in the actions/vote_channel.php channelId parameter, the ajax/commonAjax.php email parameter, and the ajax/commonAjax.php username parameter.... Read more
Affected Products : clipbucket- Published: Mar. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-7489
FasterXML jackson-databind before 2.7.9.3, 2.8.x before 2.8.11.1 and 2.9.x before 2.9.5 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 deserialization flaw. This is exploitable by sending maliciously crafte... Read more
- Published: Feb. 26, 2018
- Modified: Nov. 21, 2024