Latest CVE Feed
-
9.8
CRITICALCVE-2002-1820
register.php in Ultimate PHP Board (UPB) 1.0 and 1.0b uses an administrative account Admin with a capital "A," but allows a remote attacker to impersonate the administrator by registering an account name of admin with a lower case "a."... Read more
Affected Products : ultimate_php_board- Published: Dec. 31, 2002
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2018-13450
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13421
Fast C++ CSV Parser (aka fast-cpp-csv-parser) before 2018-07-06 has a heap-based buffer over-read in io::trim_chars in csv.h.... Read more
Affected Products : fast-cpp-csv-parser- Published: Jul. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-30845
ESPv2 is a service proxy that provides API management capabilities using Google Service Infrastructure. ESPv2 2.20.0 through 2.42.0 contains an authentication bypass vulnerability. API clients can craft a malicious `X-HTTP-Method-Override` header value to... Read more
Affected Products : espv2- Published: Apr. 26, 2023
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13385
There was an argument injection vulnerability in Sourcetree for macOS via filenames in Mercurial repositories. An attacker with permission to commit to a Mercurial repository linked in Sourcetree for macOS is able to exploit this issue to gain code execut... Read more
Affected Products : sourcetree- Published: Jul. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13315
Incorrect access control in formPasswordSetup in TOTOLINK A3002RU version 1.0.8 allows attackers to change the admin user's password via an unauthenticated POST request.... Read more
- Published: Nov. 26, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13116
/user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.... Read more
Affected Products : zzcms- Published: Jul. 03, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13052
In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin.... Read more
Affected Products : endpoint_privilege_manager- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13043
scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.... Read more
- Published: Jul. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13050
A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13026
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Type.... Read more
Affected Products : gpmf-parser- Published: Jun. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13006
An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.... Read more
- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13007
An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (not conditional on a buffer_size_longs check).... Read more
Affected Products : gpmf-parser- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12993
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.... Read more
Affected Products : onefilecms- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12972
An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.... Read more
Affected Products : opentsdb- Published: Jun. 29, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12916
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2002-1484
DB4Web server, when configured to use verbose debug messages, allows remote attackers to use DB4Web as a proxy and attempt TCP connections to other systems (port scan) via a request for a URL that specifies the target IP address and port, which produces a... Read more
Affected Products : db4web- Published: Apr. 22, 2003
- Modified: Apr. 03, 2025
-
9.8
CRITICALCVE-2018-12914
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .j... Read more
Affected Products : publiccms- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12910
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.... Read more
- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12889
An issue was discovered in CCN-lite 2.0.1. There is a heap-based buffer overflow in mkAddToRelayCacheRequest and in ccnl_populate_cache for an array lacking '\0' termination when reading a binary CCNx or NDN file. This can result in Heap Corruption. This ... Read more
Affected Products : ccn-lite- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024