Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 10.0

    HIGH
    CVE-2018-10251

    A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could allow an unauthenticated remote attacker to execute arbitr... Read more

    Affected Products : aleos es440 es450 gx400 gx440 gx450 ls300 rv50 rv50x mp70 +1 more products
    • Published: May. 04, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10250

    iCMS V7.0.8 has XSS via the admincp.php keywords parameter in a weixin_category action, aka a WeChat Classified Management keyword search.... Read more

    Affected Products : icms
    • Published: Apr. 20, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10249

    baijiacms V3 has CSRF via index.php?mod=site&op=edituser&name=manager&do=user to add an administrator account.... Read more

    Affected Products : baijiacms
    • Published: Apr. 20, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2018-10245

    A Full Path Disclosure vulnerability in AWStats through 7.6 allows remote attackers to know where the config file is allocated, obtaining the full path of the server, a similar issue to CVE-2006-3682. The attack can, for example, use the awstats.pl framen... Read more

    Affected Products : awstats awstats
    • Published: Apr. 20, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10244

    Suricata version 4.0.4 incorrectly handles the parsing of an EtherNet/IP PDU. A malformed PDU can cause the parsing code to read beyond the allocated data because DecodeENIPPDU in app-layer-enip-commmon.c has an integer overflow during a length check.... Read more

    Affected Products : suricata suricata
    • Published: Apr. 04, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10243

    htp_parse_authorization_digest in htp_parsers.c in LibHTP 0.5.26 allows remote attackers to cause a heap-based buffer over-read via an authorization digest header.... Read more

    Affected Products : libhtp
    • Published: Apr. 04, 2019
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-10242

    Suricata version 4.0.4 incorrectly handles the parsing of the SSH banner. A malformed SSH banner can cause the parsing code to read beyond the allocated data because SSHParseBanner in app-layer-ssh.c lacks a length check.... Read more

    Affected Products : debian_linux suricata suricata
    • Published: Apr. 04, 2019
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-10241

    A denial of service vulnerability in SolarWinds Serv-U before 15.1.6 HFv1 allows an authenticated user to crash the application (with a NULL pointer dereference) via a specially crafted URL beginning with the /Web%20Client/ substring.... Read more

    Affected Products : serv-u
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 7.3

    HIGH
    CVE-2018-10240

    SolarWinds Serv-U MFT before 15.1.6 HFv1 assigns authenticated users a low-entropy session token that can be included in requests to the application as a URL parameter in lieu of a session cookie. This session token's value can be brute-forced by an attac... Read more

    Affected Products : serv-u
    • Published: May. 16, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-10239

    A privilege escalation vulnerability in the "support access" feature on Infoblox NIOS 6.8 through 8.4.1 could allow a locally authenticated administrator to temporarily gain additional privileges on an affected device and perform actions within the super ... Read more

    Affected Products : nios
    • Published: Jun. 17, 2019
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10238

    bvlc.c in skarg BACnet Protocol Stack bacserv 0.9.1 and 0.8.5 is affected by a Buffer Overflow because of a lack of packet-size validation. The affected component is bacserv BACnet/IP BVLC forwarded NPDU. The function bvlc_bdt_forward_npdu() calls bvlc_en... Read more

    Affected Products : bacnet_protocol_stack
    • Published: Apr. 20, 2018
    • Modified: Nov. 21, 2024
  • 5.9

    MEDIUM
    CVE-2018-10237

    Unbounded memory allocation in Google Guava 11.0 through 24.x before 24.1.1 allows remote attackers to conduct denial of service attacks against servers that depend on this library and deserialize attacker-provided data, because the AtomicDoubleArray clas... Read more

    • Published: Apr. 26, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-10236

    POSCMS 3.2.18 allows remote attackers to execute arbitrary PHP code via the diy\dayrui\controllers\admin\Syscontroller.php 'add' function because an attacker can control the value of $data['name'] with no restrictions, and this value is written to the FCP... Read more

    Affected Products : poscms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 7.2

    HIGH
    CVE-2018-10235

    POSCMS 3.2.10 allows remote attackers to execute arbitrary PHP code via the diy\module\member\controllers\admin\Setting.php 'index' function because an attacker can control the value of $cache['setting']['ucssocfg'] in diy\module\member\models\Member_mode... Read more

    Affected Products : poscms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 4.8

    MEDIUM
    CVE-2018-10234

    Authenticated Cross site Scripting exists in the User Profile & Membership plugin before 2.0.11 for WordPress via the "Account Deletion Custom Text" input field on the wp-admin/admin.php?page=um_options&section=account page.... Read more

    • Published: Apr. 23, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10233

    The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.... Read more

    Affected Products : user_profile_\&_membership
    • Published: Apr. 23, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-10232

    Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecifie... Read more

    Affected Products : topdesk
    • Published: Jul. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10231

    Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more

    Affected Products : topdesk
    • Published: Jul. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10230

    Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.... Read more

    Affected Products : zend_server
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.8

    MEDIUM
    CVE-2018-10229

    A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.... Read more

    Affected Products : firefox chrome nexus_5
    • Published: May. 04, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293664 Results