Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.1

    HIGH
    CVE-2018-13054

    An issue was discovered in Cinnamon 1.9.2 through 3.8.6. The cinnamon-settings-users.py GUI runs as root and allows configuration of (for example) other users' icon files in _on_face_browse_menuitem_activated and _on_face_menuitem_activated. These icon fi... Read more

    Affected Products : debian_linux cinnamon
    • Published: Jul. 02, 2018
    • Modified: Nov. 21, 2024
  • 3.3

    LOW
    CVE-2018-13053

    The alarm_timer_nsleep function in kernel/time/alarmtimer.c in the Linux kernel through 4.17.3 has an integer overflow via a large relative timeout because ktime_add_safe is not used.... Read more

    Affected Products : linux_kernel ubuntu_linux debian_linux
    • Published: Jul. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13052

    In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin.... Read more

    Affected Products : endpoint_privilege_manager
    • Published: Jul. 05, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13050

    A SQL Injection vulnerability exists in Zoho ManageEngine Applications Manager 13.x before build 13800 via the j_username parameter in a /j_security_check POST request.... Read more

    • Published: Jul. 02, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-13049

    The constructSQL function in inc/search.class.php in GLPI 9.2.x through 9.3.0 allows SQL Injection, as demonstrated by triggering a crafted LIMIT clause to front/computer.php.... Read more

    Affected Products : glpi
    • Published: Jul. 02, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13045

    SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.... Read more

    Affected Products : cercopitheque
    • Published: Jan. 02, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13043

    scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing.... Read more

    Affected Products : ubuntu_linux devscripts
    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2018-13042

    The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity f... Read more

    Affected Products : 1password 1password
    • Published: Oct. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-13041

    The mint function of a smart contract implementation for Link Platform (LNK), an Ethereum ERC20 token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.... Read more

    Affected Products : linktoken
    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-13040

    OpenSID 18.06-pasca has a CSRF vulnerability. This vulnerability can add an account (at the admin level) via the index.php/man_user/insert URI.... Read more

    Affected Products : opensid opensid
    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-13039

    OpenSID 18.06-pasca has reflected Cross Site Scripting (XSS) via the cari parameter, aka an index.php/first?cari= URI.... Read more

    Affected Products : opensid opensid
    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13038

    OpenSID 18.06-pasca has an Unrestricted File Upload vulnerability via an Attachment Document in the article feature. This vulnerability leads to uploading arbitrary PHP code via a .php filename with the application/pdf Content-Type.... Read more

    Affected Products : opensid opensid
    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-13037

    An issue was discovered in jpeg-compressor 0.1. The bmp_load function in stb_image.c allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact.... Read more

    Affected Products : jpeg_compressor
    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2018-13034

    Directory traversal in Jester web framework 0.2.0 allows remote attackers to fetch files in arbitrary locations via "..%f" sequences.... Read more

    Affected Products : jester
    • Published: Jul. 09, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-13033

    The Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (excessive memory allocation and application crash) via a crafted ELF file, as demonstrated by _bfd_elf_parse_... Read more

    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-13032

    ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.... Read more

    • Published: Jul. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-13031

    DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.... Read more

    Affected Products : damicms
    • Published: Jul. 05, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-13030

    An issue was discovered in jpeg-compressor 0.1. The build_huffman function in stb_image.c allows remote attackers to cause a denial of service (stack-based buffer overflow and application crash) or possibly have unspecified other impact.... Read more

    Affected Products : jpeg_compressor
    • Published: Jun. 30, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-13026

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Type.... Read more

    Affected Products : gpmf-parser
    • Published: Jun. 30, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-13025

    protected/apps/admin/controller/photoController.php in YXcms 1.4.7 allows remote attackers to delete arbitrary files via the index.php?r=admin/photo/delpic picname parameter.... Read more

    Affected Products : yxcms
    • Published: Jun. 29, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 294423 Results