Latest CVE Feed
-
6.1
MEDIUMCVE-2018-12104
Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.... Read more
Affected Products : knowledge_repo- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-12103
An issue was discovered on D-Link DIR-890L with firmware 1.21B02beta01 and earlier, DIR-885L/R with firmware 1.21B03beta01 and earlier, and DIR-895L/R with firmware 1.21B04beta04 and earlier devices (all hardware revisions). Due to the predictability of t... Read more
Affected Products : dir-890l_firmware dir-885l\/r_firmware dir-895l\/r_firmware dir-890l dir-885\/r dir-895\/r- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12102
md4c 0.2.6 has a NULL pointer dereference in the function md_process_line in md4c.c, related to ctx->current_block.... Read more
Affected Products : md4c- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-12101
CMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.... Read more
Affected Products : clippercms- Published: Aug. 15, 2019
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-12100
Sonatype Nexus Repository Manager versions 3.x before 3.12.0 has XSS in multiple areas in the Administration UI.... Read more
Affected Products : nexus_repository_manager- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12099
Grafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.... Read more
Affected Products : grafana active_iq_performance_analytics_services storagegrid_webscale_nas_bridge- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12098
The liblnk_data_block_read function in liblnk_data_block.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this as described in lib... Read more
Affected Products : liblnk- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12097
The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed... Read more
Affected Products : liblnk- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12096
The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this a... Read more
Affected Products : liblnk- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-12095
A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.... Read more
Affected Products : oecms- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-12094
Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more
Affected Products : dimofinf_cms- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12093
tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.... Read more
Affected Products : tinyexr- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12092
tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.... Read more
Affected Products : tinyexr- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12090
There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.... Read more
Affected Products : lams- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12089
In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with O... Read more
- Published: Jun. 11, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12088
S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or ... Read more
Affected Products : s3ql- Published: Jun. 10, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-12087
Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.... Read more
- Published: Oct. 03, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12086
Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.... Read more
- Published: Sep. 14, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-12085
Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.... Read more
- Published: Jun. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12084
The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "... Read more
Affected Products : bitasean- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024