Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    MEDIUM
    CVE-2018-12066

    BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.... Read more

    Affected Products : bird
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12065

    A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.... Read more

    Affected Products : witycms
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12064

    tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.... Read more

    Affected Products : tinyexr
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12063

    The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argum... Read more

    Affected Products : node_token
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12062

    The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amoun... Read more

    Affected Products : swftcoin
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12056

    The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows attacke... Read more

    Affected Products : all_for_one
    • Published: Aug. 15, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12055

    Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.... Read more

    Affected Products : schools_alert_management_script
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12054

    Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.... Read more

    Affected Products : schools_alert_management_script
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12053

    Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.... Read more

    Affected Products : schools_alert_management_script
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12052

    SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.... Read more

    Affected Products : schools_alert_management_script
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12051

    Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.... Read more

    Affected Products : schools_alert_management_script
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-12049

    A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occur... Read more

    Affected Products : lbp6030w_firmware lbp6030w
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 10.0

    HIGH
    CVE-2018-12048

    A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs w... Read more

    Affected Products : lbp7110cw_firmware lbp7110cw
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-12047

    xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.... Read more

    Affected Products : ximdex
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12046

    DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.... Read more

    Affected Products : dedecms
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12045

    DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.... Read more

    Affected Products : dedecms
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-12043

    content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.... Read more

    Affected Products : symphony symphony_cms
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12042

    Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.... Read more

    Affected Products : roxy_fileman
    • Published: Jun. 07, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12041

    An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny service by sending specially constructed 802.11 frames.... Read more

    Affected Products : awus036nh_firmware awus036nh
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-12040

    Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... Read more

    Affected Products : symfony
    • Published: Jun. 13, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 294116 Results