Latest CVE Feed
-
7.5
HIGHCVE-2018-12927
Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.... Read more
Affected Products : northern_electric_\&_power_inverter_firmware northern_electric_\&_power_inverter- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12926
Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12925
Baseon Lantronix MSS devices do not require a password for TELNET access.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12924
Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.... Read more
Affected Products : cie-h10_firmware cie-h12_firmware cie-h14_firmware cse-m53n_firmware cse-m32_firmware cse-m24_firmware cse-m73_firmware cse-b63n2_firmware cie-h10 cie-h12 +6 more products- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12923
BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.... Read more
Affected Products : ha_bridge- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12922
Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelnet.htm URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12921
Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12920
Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.... Read more
- Published: Jun. 28, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12919
In CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.... Read more
Affected Products : craftedweb- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12918
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcB_register_fields in bootstrap.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12917
In libpbc.a in PBC through 2017-03-02, there is a heap-based buffer over-read in _pbcM_ip_new in map.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12916
In libpbc.a in PBC through 2017-03-02, there is a Segmentation fault in _pbcP_message_default in proto.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12915
In libpbc.a in PBC through 2017-03-02, there is a buffer over-read in calc_hash in map.c.... Read more
Affected Products : pbc- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12914
A remote code execution issue was discovered in PublicCMS V4.0.20180210. An attacker can upload a ZIP archive that contains a .jsp file with a directory traversal pathname. After an unzip operation, the attacker can execute arbitrary code by visiting a .j... Read more
Affected Products : publiccms- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12913
In Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.... Read more
Affected Products : miniz- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-12912
An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.... Read more
Affected Products : hongcms- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12911
WebKitGTK+ 2.20.3 has an off-by-one error, with a resultant out-of-bounds write, in the get_simple_globs functions in ThirdParty/xdgmime/src/xdgmimecache.c and ThirdParty/xdgmime/src/xdgmimeglob.c.... Read more
- Published: Jul. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12910
The get_cookies function in soup-cookie-jar.c in libsoup 2.63.2 allows attackers to have unspecified impact via an empty hostname.... Read more
- Published: Jul. 05, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-12909
Webgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has access to) via an index.php?op=fileviewer&file= URI. NOTE: the vendor indicates that the product is not intended for a... Read more
- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12908
Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.... Read more
Affected Products : brynamics- Published: Jun. 27, 2018
- Modified: Nov. 21, 2024