Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 4.8

    MEDIUM
    CVE-2018-11448

    A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a stored Cross-Site Scripting (XSS) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requi... Read more

    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-11447

    A vulnerability has been identified in SCALANCE M875 (All versions). The web interface on port 443/tcp could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user is tricked into accessing a malicious link. Successful exploitation requi... Read more

    • Published: Jun. 26, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11446

    The buy function of a smart contract implementation for Gold Reward (GRX), an Ethereum ERC20 token, allows a potential trap that could be used to cause financial damage to the buyer because of overflow of the multiplication of its argument amount and a ma... Read more

    Affected Products : gold_reward
    • Published: Jun. 25, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-11445

    A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.... Read more

    Affected Products : easyservice_billing
    • Published: May. 25, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11444

    A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.... Read more

    Affected Products : easyservice_billing
    • Published: May. 25, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-11443

    The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.... Read more

    Affected Products : easyservice_billing
    • Published: May. 25, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-11442

    A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.... Read more

    Affected Products : easyservice_billing
    • Published: May. 25, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-11440

    Liblouis 3.5.0 has a stack-based Buffer Overflow in the function parseChars in compileTranslationTable.c.... Read more

    Affected Products : ubuntu_linux leap liblouis
    • Published: May. 25, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11439

    The TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted audio file.... Read more

    Affected Products : debian_linux taglib
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-11438

    The mobi_decompress_lz77 function in compression.c in Libmobi 0.3 allows remote attackers to cause remote code execution (heap-based buffer overflow) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11437

    The mobi_reconstruct_parts function in parse_rawml.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11436

    The buffer_addraw function in buffer.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11435

    The mobi_decompress_huffman_internal function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (read access violation) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11434

    The buffer_fill64 function in compression.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11433

    The mobi_get_kf8boundary_seqnumber function in util.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-11432

    The mobi_parse_mobiheader function in read.c in Libmobi 0.3 allows remote attackers to cause information disclosure (heap-based buffer over-read) via a crafted mobi file.... Read more

    Affected Products : libmobi
    • Published: May. 30, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-11430

    An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.... Read more

    Affected Products : moderator_log_notes
    • Published: May. 28, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-11429

    ATLANT (ATL) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.... Read more

    Affected Products : atlant
    • Published: Jul. 04, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-11427

    CSRF tokens are not used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior, which makes it possible to perform CSRF attacks on the device administrator.... Read more

    • Published: Jul. 03, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-11426

    A weak Cookie parameter is used in the web application of Moxa OnCell G3100-HSPA Series version 1.4 Build 16062919 and prior. An attacker can brute force parameters required to bypass authentication and access the web interface to use all its functions ex... Read more

    • Published: Jul. 03, 2019
    • Modified: Nov. 21, 2024
Showing 20 of 293927 Results