Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 5.5

    MEDIUM
    CVE-2018-12097

    The liblnk_location_information_read_data function in liblnk_location_information.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed... Read more

    Affected Products : liblnk
    • Published: Jun. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-12096

    The liblnk_data_string_get_utf8_string_size function in liblnk_data_string.c in liblnk through 2018-04-19 allows remote attackers to cause an information disclosure (heap-based buffer over-read) via a crafted lnk file. NOTE: the vendor has disputed this a... Read more

    Affected Products : liblnk
    • Published: Jun. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-12095

    A Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in the mod parameter of info.php.... Read more

    Affected Products : oecms
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-12094

    Cross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script or HTML via the id parameter.... Read more

    Affected Products : dimofinf_cms
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12093

    tinyexr 0.9.5 has a memory leak in ParseEXRHeaderFromMemory in tinyexr.h.... Read more

    Affected Products : tinyexr
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-12092

    tinyexr 0.9.5 has a heap-based buffer over-read in tinyexr::DecodePixelData in tinyexr.h, related to OpenEXR code.... Read more

    Affected Products : tinyexr
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-12090

    There is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary JavaScript via manipulation of an unsanitized GET parameter during a forgotPasswordChange.jsp?key= password change.... Read more

    Affected Products : lams
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12089

    In Octopus Deploy version 2018.5.1 to 2018.5.7, a user with Task View is able to view a password for a Service Fabric Cluster, when the Service Fabric Cluster target is configured in Azure Active Directory security mode and a deployment is executed with O... Read more

    Affected Products : octopus_deploy octopus_server
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12088

    S3QL before 2.27 mishandles checksumming, and consequently allows replay attacks in which an attacker who controls the backend can present old versions of the filesystem metadata database as up-to-date, temporarily inject zero-valued bytes into files, or ... Read more

    Affected Products : s3ql
    • Published: Jun. 10, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2018-12087

    Failure to validate certificates in OPC Foundation UA Client Applications communicating without security allows attackers with control over a piece of network infrastructure to decrypt passwords.... Read more

    Affected Products : ua-.net-legacy ua-.netstandard
    • Published: Oct. 03, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12086

    Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.... Read more

    • Published: Sep. 14, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-12085

    Liblouis 3.6.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c, a different vulnerability than CVE-2018-11440.... Read more

    Affected Products : ubuntu_linux leap liblouis
    • Published: Jun. 09, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12084

    The mintToken function of a smart contract implementation for BitAsean (BAS), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "... Read more

    Affected Products : bitasean
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12083

    The mintToken function of a smart contract implementation for GOAL Bonanza (GOAL), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka ... Read more

    Affected Products : goal_bonanza
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12082

    The mintToken function of a smart contract implementation for Fujinto (NTO), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "t... Read more

    Affected Products : fujinto
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12081

    The mintToken function of a smart contract implementation for Target Coin (TGT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka th... Read more

    Affected Products : target_coin
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12080

    The mintToken function of a smart contract implementation for Internet Node Token (INT), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits... Read more

    Affected Products : node_token
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12079

    The mintToken function of a smart contract implementation for Substratum (SUB), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the... Read more

    Affected Products : substratum
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-12078

    The mintToken function of a smart contract implementation for PolyAI (AI), a tradable Ethereum ERC20 token, has no period constraint, which allows the owner to increase the total supply of the digital assets arbitrarily so as to make profits, aka the "tra... Read more

    Affected Products : polyai
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 4.2

    MEDIUM
    CVE-2018-12076

    A vulnerability in the UPC bar code of the Avanti Markets MarketCard could allow an unauthenticated, local attacker to access funds within the customer's MarketCard balance, and also could lead to Customer Information Disclosure. The vulnerability is due ... Read more

    Affected Products : market_card
    • Published: Dec. 13, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 294335 Results