Latest CVE Feed
-
6.1
MEDIUMCVE-2018-10128
An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php.... Read more
Affected Products : xyhcms- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10127
An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role.... Read more
Affected Products : xyhcms- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10126
ijg-libjpeg before 9d, as used in tiff2pdf (from LibTIFF) and other products, does not check for a NULL pointer at a certain place in jpeg_fdct_16x16 in jfdctint.c.... Read more
Affected Products : libtiff- Published: Apr. 21, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10125
Contao before 4.5.7 has XSS in the system log.... Read more
Affected Products : contao- Published: Mar. 16, 2020
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10124
The kill_something_info function in kernel/signal.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service via an INT_MIN argument.... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
9.0
HIGHCVE-2018-10123
p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100.... Read more
- Published: May. 16, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10122
QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) pro1.6 allows remote attackers to read arbitrary files via directory traversal sequences in the pathname parameter to www/file.php.... Read more
Affected Products : chanzhi- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10121
plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the title section of an admin/index.php?id=pages&action=edit_page&name=error404 (aka Edit 404 p... Read more
Affected Products : monstra- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10120
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to cause a denial of service (heap-based buffer overflow wi... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10119
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of service (use-after-free with write access) or possibly ha... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10118
Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.... Read more
Affected Products : monstra- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10117
An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP.... Read more
Affected Products : icms- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10115
Incorrect initialization logic of RAR decoder objects in 7-Zip 18.03 and before can lead to usage of uninitialized memory, allowing remote attackers to cause a denial of service (segmentation fault) or execute arbitrary code via a crafted RAR archive.... Read more
- Published: May. 02, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10114
An issue was discovered in GEGL through 0.3.32. The gegl_buffer_iterate_read_simple function in buffer/gegl-buffer-access.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malfo... Read more
Affected Products : gegl- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10113
An issue was discovered in GEGL through 0.3.32. The process function in operations/external/ppm-load.c has unbounded memory allocation, leading to a denial of service (application crash) upon allocation failure.... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10112
An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_swap_constructed function in buffer/gegl-tile-backend-swap.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via ... Read more
Affected Products : gegl- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-10111
An issue was discovered in GEGL through 0.3.32. The render_rectangle function in process/gegl-processor.c has unbounded memory allocation, leading to a denial of service (application crash) upon allocation failure.... Read more
Affected Products : gegl- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUM- Published: Apr. 18, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10109
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.... Read more
Affected Products : monstra- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10108
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.... Read more
- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024