Latest CVE Feed
-
9.8
CRITICALCVE-2018-12829
Adobe Creative Cloud Desktop Application before 4.6.1 has an improper certificate validation vulnerability. Successful exploitation could lead to privilege escalation.... Read more
Affected Products : creative_cloud- EPSS Score: %2.10
- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12808
Adobe Acrobat and Reader versions 2018.011.20055 and earlier, 2017.011.30096 and earlier, and 2015.006.30434 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.... Read more
- EPSS Score: %2.25
- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12810
Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Successful exploitation could lead to remote code execution.... Read more
- EPSS Score: %19.40
- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12811
Adobe Photoshop CC 2018 before 19.1.6 and Photoshop CC 2017 before 18.1.6 have a memory corruption vulnerability. Successful exploitation could lead to remote code execution.... Read more
- EPSS Score: %19.40
- Published: Aug. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-38539
Archery v1.7.5 to v1.8.5 was discovered to contain a SQL injection vulnerability via the where parameter at /archive/apply.... Read more
Affected Products : archery- EPSS Score: %0.09
- Published: Sep. 13, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12785
Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.... Read more
- EPSS Score: %15.50
- Published: Jul. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12706
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.... Read more
- EPSS Score: %19.91
- Published: Jun. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12678
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass intended access restrictions or conduct SSRF attacks.... Read more
Affected Products : portainer- EPSS Score: %0.40
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12689
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.... Read more
- EPSS Score: %0.45
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12640
The webService binary on Insteon HD IP Camera White 2864-222 devices has a Buffer Overflow via a crafted pid, pwd, or usr key in a GET request on port 34100.... Read more
- EPSS Score: %0.46
- Published: Jun. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12666
SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel c... Read more
Affected Products : h.264_poe_ip_camera_firmware sv-b01poe-1080p-l sv-b11vpoe-1080p-l sv-d02poe-1080p-l- EPSS Score: %1.10
- Published: Oct. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12649
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only covering POST req... Read more
- EPSS Score: %0.30
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12634
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.... Read more
- EPSS Score: %90.22
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12630
NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.... Read more
Affected Products : nmcms- EPSS Score: %0.25
- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12601
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.... Read more
- EPSS Score: %0.57
- Published: Jun. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12596
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (n... Read more
- EPSS Score: %55.08
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12575
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.... Read more
- EPSS Score: %0.76
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12578
There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.... Read more
Affected Products : sam2p- EPSS Score: %0.39
- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12557
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items... Read more
Affected Products : zuul- EPSS Score: %0.45
- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12531
An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.... Read more
Affected Products : metinfo- EPSS Score: %0.99
- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024