Latest CVE Feed
-
5.3
MEDIUMCVE-2018-12073
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a new one within the web interface. Therefore, it is possible to exploit this issue (e.g., in combination with a successful XSS, or at a... Read more
Affected Products : em4544- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12072
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can complet... Read more
- Published: Jun. 17, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12070
The sell function of a smart contract implementation for SEC, a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amount and a manip... Read more
Affected Products : sec- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12068
The sell function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amou... Read more
Affected Products : target_coin- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12067
The sell function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amoun... Read more
Affected Products : substratum- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-12066
BIRD Internet Routing Daemon before 1.6.4 allows local users to cause a denial of service (stack consumption and daemon crash) via BGP mask expressions in birdc.... Read more
Affected Products : bird- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12065
A Local File Inclusion vulnerability in /system/WCore/WHelper.php in Creatiwity wityCMS 0.6.2 allows remote attackers to include local PHP files (execute PHP code) or read non-PHP files by replacing a helper.json file.... Read more
Affected Products : witycms- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12064
tinyexr 0.9.5 has a heap-based buffer over-read via tinyexr::ReadChannelInfo in tinyexr.h.... Read more
Affected Products : tinyexr- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12063
The sell function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argum... Read more
Affected Products : node_token- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12062
The sell function of a smart contract implementation for SwftCoin (SWFTC), a tradable Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the seller, because of overflow of the multiplication of its argument amoun... Read more
Affected Products : swftcoin- Published: Jun. 25, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12056
The maxRandom function of a smart contract implementation for All For One, an Ethereum gambling game, generates a random value with publicly readable variables because the _seed value can be retrieved with a getStorageAt call. Therefore, it allows attacke... Read more
Affected Products : all_for_one- Published: Aug. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12055
Multiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php, about.php, photo_gallery.php, privacy.php, and so on.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12054
Arbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12053
Arbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using directory traversal.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12052
SQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-12051
Arbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in /webmasterst/general.php, as demonstrated by a .php file with the image/jpeg content type.... Read more
Affected Products : schools_alert_management_script- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12049
A remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occur... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-12048
A remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs w... Read more
- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-12047
xfind/search in Ximdex 4.0 has XSS via the filter[n][value] parameters for non-negative values of n, as demonstrated by n equal to 0 through 12.... Read more
Affected Products : ximdex- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-12046
DedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request with name and str parameters, as demonstrated by writing to a new .php file.... Read more
Affected Products : dedecms- Published: Jun. 08, 2018
- Modified: Nov. 21, 2024