Latest CVE Feed
-
9.8
CRITICALCVE-2018-12649
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login part, because this protection was only covering POST req... Read more
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12634
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.... Read more
- Published: Jun. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12630
NEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.... Read more
Affected Products : nmcms- Published: Jun. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12601
There is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.... Read more
- Published: Jun. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12596
Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (n... Read more
- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12575
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12578
There is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly unspecified other impact.... Read more
Affected Products : sam2p- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12557
An issue was discovered in Zuul 3.x before 3.1.0. If nodes become offline during the build, the no_log attribute of a task is ignored. If the unreachable error occurred in a task used with a loop variable (e.g., with_items), the contents of the loop items... Read more
Affected Products : zuul- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12531
An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271.... Read more
Affected Products : metinfo- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12532
JBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable mapper and execute arbitrary Java code via a MediaOutputResource's resource request, aka RF-14309.... Read more
Affected Products : richfaces- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12533
JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData obje... Read more
Affected Products : richfaces- Published: Jun. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12474
Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE... Read more
- Published: Oct. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12426
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/remote_upload request with a .php filename and the image/jp... Read more
- Published: Jul. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12421
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a st... Read more
Affected Products : ldap_tool_box_self_service_password- Published: Jun. 14, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12544
In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type vali... Read more
Affected Products : vert.x- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12410
The web server component of TIBCO Software Inc's Spotfire Statistics Services contains multiple vulnerabilities that may allow the remote execution of code. Without needing to authenticate, an attacker may be able to remotely execute code with the permiss... Read more
Affected Products : spotfire_statistics_services- Published: Oct. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12392
When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.... Read more
Affected Products : firefox firefox_esr thunderbird ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus +1 more products- Published: Feb. 28, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-28201
This issue was addressed with improved state management. This issue is fixed in macOS Ventura 13.3, Safari 16.4, iOS 16.4 and iPadOS 16.4, iOS 15.7.4 and iPadOS 15.7.4, tvOS 16.4. A remote user may be able to cause unexpected app termination or arbitrary ... Read more
- Published: May. 08, 2023
- Modified: Jan. 29, 2025
-
9.8
CRITICALCVE-2018-12378
A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Fire... Read more
Affected Products : firefox firefox_esr thunderbird ubuntu_linux debian_linux enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation enterprise_linux_server_aus enterprise_linux_server_eus +1 more products- Published: Oct. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2023-0918
A vulnerability has been found in codeprojects Pharmacy Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file add.php of the component Avatar Image Handler. The manipulation leads to unrestricted upload. The... Read more
Affected Products : pharmacy_management_system- Published: Feb. 19, 2023
- Modified: Nov. 21, 2024