Latest CVE Feed
-
9.8
CRITICALCVE-2023-22072
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). The supported version that is affected is 12.2.1.3.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via T3, IIOP to... Read more
Affected Products : weblogic_server- Published: Oct. 17, 2023
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2023-22069
Vulnerability in the Oracle WebLogic Server product of Oracle Fusion Middleware (component: Core). Supported versions that are affected are 12.2.1.4.0 and 14.1.1.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access v... Read more
Affected Products : weblogic_server- Published: Oct. 17, 2023
- Modified: Mar. 06, 2025
-
9.8
CRITICALCVE-2018-10968
On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable devices, aka a backdoor access vulnerability.... Read more
- Published: May. 18, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10942
modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.... Read more
- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2022-30809
elitecms 1.01 is vulnerable to SQL Injection via /admin/edit_page.php?page=.... Read more
Affected Products : elite_cms- Published: Jun. 02, 2022
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10870
redhat-certification does not properly sanitize paths in rhcertStore.py:__saveResultsFile. A remote attacker could use this flaw to overwrite any file, potentially gaining remote code execution.... Read more
- Published: Jul. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2019-18370
An issue was discovered on Xiaomi Mi WiFi R3G devices before 2.28.23-stable. The backup file is in tar.gz format. After uploading, the application uses the tar zxf command to decompress, so one can control the contents of the files in the decompressed dir... Read more
- Published: Oct. 23, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10770
download.rsp on ShenZhen Anni "5 in 1 XVR" devices allows remote attackers to download the configuration (without a login) to discover the password.... Read more
- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10771
Stack-based buffer overflow in the get_key function in parse.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
- Published: May. 07, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10759
PHP remote file inclusion vulnerability in public/patch/patch.php in Project Pier 0.8.8 and earlier allows remote attackers to execute arbitrary commands or SQL statements via the id parameter.... Read more
Affected Products : projectpier- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10753
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.... Read more
- Published: May. 05, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10683
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE: the Security Realms documentation in the product's Admi... Read more
Affected Products : wildfly- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10676
CeNova, Night OWL, Novo, Pulnix, QSee, Securus, and TBK Vision DVR devices allow remote attackers to download a file and obtain sensitive credential information via a direct request for the download.rsp URI.... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10648
There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.... Read more
Affected Products : xenmobile_server- Published: May. 23, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10627
Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and p... Read more
- Published: Jul. 24, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10633
Universal Robots Robot Controllers Version CB 3.1, SW Version 3.4.5-100 utilizes hard-coded credentials that may allow an attacker to reset passwords for the controller.... Read more
- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10611
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.... Read more
Affected Products : mds_pulsenet- Published: Jun. 04, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10618
Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.... Read more
- Published: Aug. 01, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-15691
Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.... Read more
- Published: Aug. 30, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10603
Martem TELEM GW6 and GWM devices with firmware 2018.04.18-linux_4-01-601cb47 and prior do not perform authentication of IEC-104 control commands, which may allow a rogue node a remote control of the industrial process.... Read more
- Published: Jul. 31, 2018
- Modified: Nov. 21, 2024