Latest CVE Feed
-
8.8
HIGHCVE-2018-10295
ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.... Read more
Affected Products : chemcms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10294
Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.... Read more
Affected Products : diskboss- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10289
In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.... Read more
- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10286
The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the cr... Read more
Affected Products : ipecs_nms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10285
The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.... Read more
Affected Products : ipecs_nms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10284
Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.... Read more
Affected Products : g-ticket- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10283
CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.... Read more
Affected Products : loja_virtual- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10268
An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.... Read more
Affected Products : fastadmin- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10267
WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.... Read more
Affected Products : wtcms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10266
BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.... Read more
Affected Products : beescms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10265
An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.... Read more
Affected Products : hongcms- Published: Apr. 22, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10260
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10259
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10258
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : shopy_point_of_sale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10257
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10256
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.... Read more
Affected Products : hrsale- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10255
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more
Affected Products : blog_master_pro- Published: May. 01, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10254
Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted EL... Read more
- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10253
Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.... Read more
Affected Products : prtg_network_monitor- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
8.1
HIGHCVE-2018-10252
An issue was discovered on Actiontec WCB6200Q before 1.1.10.20a devices. The admin login session cookie is insecurely generated making admin session hijacking possible. When an admin logs in, a session cookie is generated using the time of day rounded to ... Read more
- Published: May. 14, 2018
- Modified: Nov. 21, 2024