Latest CVE Feed
-
7.5
HIGHCVE-2018-13463
The mintToken function of a smart contract implementation for T-Swap-Token (T-S-T), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.... Read more
Affected Products : t-swap-token- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-13462
The mintToken function of a smart contract implementation for MoonToken, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.... Read more
Affected Products : moontoken- Published: Jul. 09, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13458
qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.... Read more
Affected Products : nagios_core- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13457
qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.... Read more
Affected Products : nagios_core- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13450
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the status_batch parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13449
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut_buy parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13448
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the country_id parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-13447
SQL injection vulnerability in product/card.php in Dolibarr ERP/CRM version 7.0.3 allows remote attackers to execute arbitrary SQL commands via the statut parameter.... Read more
Affected Products : dolibarr_erp\/crm- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-13446
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate... Read more
Affected Products : line- Published: Aug. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-13445
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add a user account via adm1n/admin_manager.php?action=add.... Read more
Affected Products : seacms- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-13444
An issue was discovered in SeaCMS 6.61. There is a CSRF vulnerability that can add an admin account via adm1n/admin_manager.php?action=save&id=2.... Read more
Affected Products : seacms- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-13443
EOS.IO jit-wasm 4.1 has a heap-based buffer overflow via a crafted wast file.... Read more
Affected Products : jit-wasm- Published: Apr. 24, 2019
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-13442
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.... Read more
Affected Products : network_performance_monitor- Published: Jul. 16, 2019
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-13441
qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.... Read more
- Published: Jul. 12, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-13439
WXPayUtil in WeChat Pay Java SDK allows XXE attacks involving a merchant notification URL.... Read more
Affected Products : wechat_pay- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
7.0
HIGHCVE-2018-13435
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this ... Read more
Affected Products : line- Published: Aug. 16, 2018
- Modified: Nov. 21, 2024
-
6.3
MEDIUMCVE-2018-13434
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUse... Read more
Affected Products : line- Published: Aug. 16, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-13433
Boostnote v0.11.7 allows XSS during highlighting of Markdown text, as demonstrated by an onerror attribute of an IMG element.... Read more
- Published: Jul. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-13423
admin/themes/default/items/tag-form.php in Omeka before 2.6.1 allows XSS by adding or editing a tag.... Read more
Affected Products : omeka- Published: Jul. 07, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-13422
TCExam before 14.1.2 has XSS via an ff_ or xl_ field.... Read more
Affected Products : tcexam- Published: Jul. 07, 2018
- Modified: Nov. 21, 2024