Latest CVE Feed
-
9.8
CRITICALCVE-2018-10284
Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.... Read more
Affected Products : g-ticket- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10283
CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.... Read more
Affected Products : loja_virtual- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10268
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.... Read more
Affected Products : fastadmin- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10267
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.... Read more
Affected Products : wtcms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10266
BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.... Read more
Affected Products : beescms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10265
An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.... Read more
Affected Products : hongcms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10260
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10258
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : shopy_point_of_sale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10256
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10255
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : blog_master_pro- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10254
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted EL... Read more
- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10253
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.... Read more
Affected Products : prtg_network_monitor- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-10252
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely generated making admin session hijacking possible. When an admin logs in, a session cookie is generated using the time of day rounded to ... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-10251
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitr... Read more
- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10250
iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.... Read more
Affected Products : icms- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10249
baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.... Read more
Affected Products : baijiacms- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10245
A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framen... Read more
- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10244
Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.... Read more
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024