Latest CVE Feed
-
5.3
MEDIUMCVE-2018-11579
class-woo-banner-management.php in the MULTIDOTS WooCommerce Category Banner Management plugin 1.1.0 for WordPress has an Unauthenticated Settings Change Vulnerability, related to certain wp_ajax_nopriv_ usage. Anyone can change the plugin's setting by si... Read more
Affected Products : woocommerce_category_banner_management- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-11578
GifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault.... Read more
Affected Products : ngiflib- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGH- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11576
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.... Read more
Affected Products : ngiflib- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11575
ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.... Read more
Affected Products : ngiflib- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11574
Improper input validation together with an integer overflow in the EAP-TLS protocol implementation in PPPD may cause a crash, information disclosure, or authentication bypass. This implementation is distributed as a patch for PPPD 0.91, and includes the a... Read more
- Published: Jun. 14, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11572
ClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.... Read more
Affected Products : clippercms- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-11571
ClipperCMS 1.3.3 allows Session Fixation.... Read more
Affected Products : clippercms- Published: May. 31, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11569
Controller/ListController.php in Eventum 3.5.0 is vulnerable to Deserialization of Untrusted Data. Fixed in version 3.5.2.... Read more
Affected Products : eventum- Published: Sep. 05, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11568
Reflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated by the s parameter. In some (but not all) cases, the '<' and '>' characters have < and > representations.... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-11567
Prior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is designed so that if Alexa does not receive an input within 8 seconds, the device can speak a reprompt, then wait an addition... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-11565
Mahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to mentioning the usernames that are already taken by people registered in the system rather than masking that information.... Read more
Affected Products : mahara- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-11564
Stored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with elevated privileges could upload a photo to the system in an SVG format. This file will be uploaded to the system and it w... Read more
Affected Products : pagekit- Published: Jun. 02, 2018
- Modified: Nov. 21, 2024
-
4.9
MEDIUMCVE-2018-11563
An issue was discovered in Open Ticket Request System (OTRS) 6.0.x through 6.0.7. A carefully constructed email could be used to inject and execute arbitrary stylesheet or JavaScript code in a logged in customer's browser in the context of the OTRS custom... Read more
- Published: Jul. 08, 2019
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11562
An issue was discovered in MISP 2.4.91. A vulnerability in app/View/Elements/eventattribute.ctp allows reflected XSS if a user clicks on a malicious link for an event view and then clicks on the deleted attributes quick filter.... Read more
- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-11561
An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), an Ethereum ERC20 token, will lead to an unauthorized increase of an attacker's digital assets.... Read more
Affected Products : erc20token- Published: Aug. 08, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-11560
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.... Read more
- Published: Jun. 23, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11559
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.... Read more
Affected Products : domainmod- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-11558
DomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.... Read more
Affected Products : domainmod- Published: May. 30, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-11557
YIBAN Easy class education platform 2.0 has XSS via the articlelist.php k parameter.... Read more
Affected Products : easy_class_education_platform- Published: May. 30, 2018
- Modified: Nov. 21, 2024