Latest CVE Feed
-
5.5
MEDIUMCVE-2018-12066
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.... Read more
Affected Products : bird- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12065
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.... Read more
Affected Products : witycms- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12064
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.... Read more
Affected Products : tinyexr- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12063
The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argum... Read more
Affected Products : node_token- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12062
The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amoun... Read more
Affected Products : swftcoin- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12056
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows attacke... Read more
Affected Products : all_for_one- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12055
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12054
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12053
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12052
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12051
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12049
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occur... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12048
A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs w... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12047
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.... Read more
Affected Products : ximdex- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12046
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.... Read more
Affected Products : dedecms- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12045
DedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request with an upfile1 parameter, as demonstrated by uploading a .php file.... Read more
Affected Products : dedecms- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12043
content/content.blueprintspages.php in Symphony 2.7.6 has XSS via the pages content page.... Read more
- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12042
Roxy Fileman through v1.4.5 has Directory traversal via the php/download.php f parameter.... Read more
Affected Products : roxy_fileman- Published: Jun. 07, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12041
An issue was discovered on the MediaTek AWUS036NH wireless USB adapter through 5.1.25.0. Attackers can remotely deny service by sending specially constructed 802.11 frames.... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12040
Reflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject arbitrary web script or HTML via the "file" parameter, aka an _profiler/open?file= URI. NOTE: The vendor states "The XSS ... Read more
Affected Products : symfony- Published: Jun. 13, 2018
- Modified: Nov. 21, 2024