Latest CVE Feed
-
9.8
CRITICALCVE-2018-10243
htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.... Read more
Affected Products : libhtp- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10242
Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.... Read more
- Published: Apr. 04, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10241
A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.... Read more
Affected Products : serv-u- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
7.3
HIGHCVE-2018-10240
SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attac... Read more
Affected Products : serv-u- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-10239
A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administrator to temporarily gain additional privileges on an affected device and perform actions within the super ... Read more
Affected Products : nios- Published: Jun. 17, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10238
bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_en... Read more
Affected Products : bacnet_protocol_stack- Published: Apr. 20, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-10237
Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray clas... Read more
Affected Products : enterprise_linux openstack weblogic_server openshift_container_platform satellite guava communications_ip_service_activator virtualization virtualization_host banking_payments +8 more products- Published: Apr. 26, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-10236
POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an attacker can control the value of $data['name'] with no restrictions, and this value is written to the FCP... Read more
Affected Products : poscms- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-10235
POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diy\module\member\models\Member_mode... Read more
Affected Products : poscms- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10234
Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options§ion=account page.... Read more
- Published: Apr. 23, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10233
The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.... Read more
Affected Products : user_profile_\&_membership- Published: Apr. 23, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10232
Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecifie... Read more
Affected Products : topdesk- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10231
Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more
Affected Products : topdesk- Published: Jul. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10230
Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.... Read more
Affected Products : zend_server- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
5.8
MEDIUMCVE-2018-10229
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.... Read more
- Published: May. 04, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10228
Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges... Read more
Affected Products : limesurvey- Published: Dec. 14, 2021
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10227
MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.... Read more
- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10225
thinkphp 3.1.3 has SQL Injection via the index.php s parameter.... Read more
Affected Products : thinkphp- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-10224
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.... Read more
Affected Products : yzmcms- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024
-
6.8
MEDIUMCVE-2018-10223
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.... Read more
Affected Products : yzmcms- Published: Apr. 19, 2018
- Modified: Nov. 21, 2024