Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 9.8

    CRITICAL
    CVE-2018-11221

    Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.... Read more

    Affected Products : pandora_fms
    • Published: Jun. 16, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-11220

    Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.... Read more

    • Published: May. 31, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11219

    An Integer Overflow issue was discovered in the struct library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2, leading to a failure of bounds checking.... Read more

    • Published: Jun. 17, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11218

    Memory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before 5.0 RC2 because of stack-based buffer overflows.... Read more

    • Published: Jun. 17, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11215

    Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.... Read more

    Affected Products : data_science_workbench
    • Published: Jul. 03, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11214

    An issue was discovered in libjpeg 9a. The get_text_rgb_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.... Read more

    Affected Products : ubuntu_linux debian_linux libjpeg
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11213

    An issue was discovered in libjpeg 9a. The get_text_gray_row function in rdppm.c allows remote attackers to cause a denial of service (Segmentation fault) via a crafted file.... Read more

    Affected Products : ubuntu_linux debian_linux libjpeg
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11212

    An issue was discovered in libjpeg 9a and 9d. The alloc_sarray function in jmemmgr.c allows remote attackers to cause a denial of service (divide-by-zero error) via a crafted file.... Read more

    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11210

    TinyXML2 6.2.0 has a heap-based buffer over-read in the XMLDocument::Parse function in libtinyxml2.so. NOTE: The tinyxml2 developers have determined that the reported overflow is due to improper use of the library and not a vulnerability in tinyxml2... Read more

    Affected Products : tinyxml2
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-11209

    An issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it easier for attackers to bypass intended access restrictions via a dictionary or rainbow-table attack. NOTE: the vendor d... Read more

    Affected Products : z-blogphp
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2018-11208

    An issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML into background web site settings via the "copyright information office" field. NOTE: the vendor indicates that the p... Read more

    Affected Products : z-blogphp
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11207

    A division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more

    Affected Products : hdf5
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2018-11206

    An out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.... Read more

    Affected Products : hdf5
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 8.1

    HIGH
    CVE-2018-11205

    A out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service or information disclosure attack.... Read more

    Affected Products : hdf5
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11204

    A NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more

    Affected Products : hdf5
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11203

    A division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more

    Affected Products : hdf5
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11202

    A NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service attack.... Read more

    Affected Products : hdf5
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-11200

    An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.... Read more

    Affected Products : mautic
    • Published: Sep. 20, 2019
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-11198

    An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.... Read more

    Affected Products : mautic
    • Published: Sep. 06, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11196

    Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 can be used as medium to transmit viruses by placing infected files into a Leap2A archive and uploading that to Mahara. In contrast to other ZIP files that are uploaded, ClamAV ... Read more

    Affected Products : mahara
    • Published: Jun. 01, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293698 Results