Latest CVE Feed
-
7.5
HIGHCVE-2018-10827
LiteCart before 2.1.2 allows remote attackers to cause a denial of service (memory consumption) via URIs that do not exist, because public_html/logs/not_found.log grows without bound, and is loaded into memory for each request.... Read more
Affected Products : litecart- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10825
Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofin... Read more
- Published: May. 15, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10824
An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. The administrative password is ... Read more
Affected Products : dwr-116_firmware dir-140l_firmware dir-640l_firmware dwr-512_firmware dwr-712_firmware dwr-912_firmware dwr-921_firmware dwr-111_firmware dwr-921 dwr-116 +5 more products- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-10823
An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell c... Read more
Affected Products : dwr-116_firmware dwr-512_firmware dwr-912_firmware dwr-111_firmware dwr-921 dwr-116 dwr-512 dwr-111- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10822
Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices a... Read more
Affected Products : dwr-116_firmware dir-140l_firmware dir-640l_firmware dwr-512_firmware dwr-712_firmware dwr-912_firmware dwr-921_firmware dwr-111_firmware dwr-921 dwr-116 +5 more products- Published: Oct. 17, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10821
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.... Read more
Affected Products : blackcat_cms- Published: Jun. 14, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10817
Severalnines ClusterControl before 1.6.0-4699 allows XSS.... Read more
Affected Products : clustercontrol- Published: May. 09, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10815
An issue was discovered in Cloudera Manager before 5.13.4, 5.14.x before 5.14.4, and 5.15.x before 5.15.1. A read-only user can access sensitive cluster information.... Read more
Affected Products : cloudera_manager- Published: May. 24, 2019
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10814
Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.... Read more
Affected Products : synaman- Published: Sep. 14, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10813
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of the session cookie and re-sign it using the hardcoded s... Read more
Affected Products : dedos-web- Published: Jun. 05, 2018
- Modified: Nov. 21, 2024
-
4.1
MEDIUMCVE-2018-10812
The Bitpie application through 3.2.4 for Android and iOS uses cleartext storage for digital currency initial keys, which allows local users to steal currency by leveraging root access to read /com.biepie/shared_prefs/com.bitpie_preferences.xml (on Android... Read more
Affected Products : bitcoin_wallet- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10811
strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.... Read more
- Published: Jun. 19, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10810
chat/mobile/index.php in LiveZilla Live Chat 7.0.9.5 and prior is affected by Cross-Site Scripting via the Accept-Language HTTP header.... Read more
Affected Products : livezilla- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10809
In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040. NOTE: this vulnerability exist... Read more
Affected Products : 2345_security_guard- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10806
An issue was discovered in Frog CMS 0.9.5. There is a reflected Cross Site Scripting Vulnerability via the file[current_name] parameter to the admin/?/plugin/file_manager/rename URI. This can be used in conjunction with CSRF.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10805
ImageMagick version 7.0.7-28 contains a memory leak in ReadYCBCRImage in coders/ycbcr.c.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10804
ImageMagick version 7.0.7-28 contains a memory leak in WriteTIFFImage in coders/tiff.c.... Read more
- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10803
Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This c... Read more
Affected Products : manageengine_netflow_analyzer- Published: May. 10, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10801
TIFFClientOpen in tif_unix.c in LibTIFF 3.8.2 has memory leaks, as demonstrated by bmp2tiff.... Read more
Affected Products : libtiff- Published: May. 08, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10799
A hang issue was discovered in Brave before 0.14.0 (on, for example, Linux). This vulnerability is caused by the mishandling of a long URL formed by window.location+='?\u202a\uFEFF\u202b'; concatenation in a SCRIPT element.... Read more
Affected Products : brave- Published: May. 08, 2018
- Modified: Nov. 21, 2024