Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 8.8

    HIGH
    CVE-2018-10233

    The User Profile & Membership plugin before 2.0.7 for WordPress has no mitigations implemented against cross site request forgery attacks. This is a structural finding throughout the entire plugin.... Read more

    Affected Products : user_profile_\&_membership
    • Published: Apr. 23, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-10232

    Cross-site request forgery (CSRF) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to hijack the authentication of authenticated users for requests that can obtain sensitive information via unspecifie... Read more

    Affected Products : topdesk
    • Published: Jul. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10231

    Cross-site scripting (XSS) vulnerability in TOPdesk before 8.05.017 (June 2018 version) and before 5.7.SR9 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.... Read more

    Affected Products : topdesk
    • Published: Jul. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10230

    Zend Debugger in Zend Server before 9.1.3 has XSS, aka ZSR-2455.... Read more

    Affected Products : zend_server
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.8

    MEDIUM
    CVE-2018-10229

    A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.... Read more

    Affected Products : firefox chrome nexus_5
    • Published: May. 04, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10228

    Cross-site scripting (XSS) vulnerability in /application/controller/admin/theme.php in LimeSurvey 3.6.2+180406 allows remote attackers to inject arbitrary web script or HTML via the changes_cp parameter to the index.php/admin/themes/sa/templatesavechanges... Read more

    Affected Products : limesurvey
    • Published: Dec. 14, 2021
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10227

    MiniCMS v1.10 has XSS via the mc-admin/conf.php site_link parameter.... Read more

    Affected Products : minicms minicms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10225

    thinkphp 3.1.3 has SQL Injection via the index.php s parameter.... Read more

    Affected Products : thinkphp
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2018-10224

    An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add a tag via /index.php/admin/tag/add.html.... Read more

    Affected Products : yzmcms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 6.8

    MEDIUM
    CVE-2018-10223

    An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.... Read more

    Affected Products : yzmcms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10222

    An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.... Read more

    Affected Products : icms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10221

    An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuzhicms URI. After a website editor (whose privilege is lo... Read more

    Affected Products : wuzhicms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10220

    Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/handlers/emulators/rfi.py supports Remote File Inclusion e... Read more

    Affected Products : glastopf
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2018-10219

    baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request.... Read more

    Affected Products : baijiacms
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 5.3

    MEDIUM
    CVE-2018-10205

    hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to runV 1.0.0 for Docker.... Read more

    Affected Products : hyperstart
    • Published: Apr. 19, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-10204

    PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN protocol, the "sevpnclient" service executes "openvpn.exe" using the OpenVPN config file located at %PROGRA... Read more

    Affected Products : purevpn
    • Published: Apr. 18, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-10201

    An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL wi... Read more

    Affected Products : vspace_pro
    • Published: Apr. 20, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10199

    In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to execute arbitrary code.... Read more

    Affected Products : mruby
    • Published: Apr. 18, 2018
    • Modified: Nov. 21, 2024
  • 4.3

    MEDIUM
    CVE-2018-10198

    An issue was discovered in OTRS 6.0.x before 6.0.7. An attacker who is logged into OTRS as a customer can use the ticket overview screen to disclose internal article information of their customer tickets.... Read more

    Affected Products : otrs
    • Published: Jun. 06, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10197

    There is a time-based blind SQL injection vulnerability in the Access Manager component before 9.18.040 and 10.x before 10.18.040 in ELO ELOenterprise 9 and 10 and ELOprofessional 9 and 10 that makes it possible to read all database content. The vulnerabi... Read more

    Affected Products : access_manager
    • Published: Jul. 11, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 293669 Results