Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2018-10296

    MiniCMS V1.10 has XSS via the mc-admin/post-edit.php title parameter.... Read more

    Affected Products : minicms minicms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10295

    ChemCMS v1.0.6 has CSRF by using public/admin/user/addpost.html to add an administrator account.... Read more

    Affected Products : chemcms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10294

    Flexense DiskBoss Enterprise v7.4.28 to v9.1.16 has XSS.... Read more

    Affected Products : diskboss
    • Published: May. 02, 2018
    • Modified: Nov. 21, 2024
  • 5.5

    MEDIUM
    CVE-2018-10289

    In MuPDF 1.13.0, there is an infinite loop in the fz_skip_space function of the pdf/pdf-xref.c file. A remote adversary could leverage this vulnerability to cause a denial of service via a crafted pdf file.... Read more

    Affected Products : debian_linux mupdf
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10286

    The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the cr... Read more

    Affected Products : ipecs_nms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10285

    The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.... Read more

    Affected Products : ipecs_nms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10284

    Adaltech G-Ticket v70 EME104 has SQL Injection via the mobile-loja/mensagem.asp eve_cod parameter.... Read more

    Affected Products : g-ticket
    • Published: Apr. 21, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10283

    CliqueMania loja virtual 14 has SQL Injection via the patch/remote.php id parameter in a recomendar action.... Read more

    Affected Products : loja_virtual
    • Published: Apr. 21, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10268

    An issue was discovered in FastAdmin V1.0.0.20180417_beta. There is XSS via the application\api\controller\User.php avatar parameter.... Read more

    Affected Products : fastadmin
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10267

    WTCMS 1.0 has a CSRF vulnerability to add an administrator account via the index.php?admin&m=user&a=add_post URI.... Read more

    Affected Products : wtcms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10266

    BEESCMS 4.0 has a CSRF vulnerability to add an administrator account via the admin/admin_admin.php?nav=list_admin_user&admin_p_nav=user URI.... Read more

    Affected Products : beescms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10265

    An issue was discovered in HongCMS v3.0.0. There is a CSRF vulnerability that can add an administrator account via the admin/index.php/users/save URI.... Read more

    Affected Products : hongcms
    • Published: Apr. 22, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10260

    A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more

    Affected Products : hrsale
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10259

    An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.... Read more

    Affected Products : hrsale
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10258

    A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more

    Affected Products : shopy_point_of_sale
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10257

    A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more

    Affected Products : hrsale
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10256

    A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.... Read more

    Affected Products : hrsale
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10255

    A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.... Read more

    Affected Products : blog_master_pro
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-10254

    Netwide Assembler (NASM) 2.13 has a stack-based buffer over-read in the disasm function of the disasm/disasm.c file. Remote attackers could leverage this vulnerability to cause a denial of service or possibly have unspecified other impact via a crafted EL... Read more

    Affected Products : netwide_assembler nasm
    • Published: Apr. 21, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-10253

    Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.... Read more

    Affected Products : prtg_network_monitor
    • Published: Apr. 21, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293685 Results