Latest CVE Feed
-
8.8
HIGHCVE-2018-10030
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.... Read more
Affected Products : cms_made_simple- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10029
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.... Read more
Affected Products : cms_made_simple- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-10028
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.... Read more
Affected Products : joyplus-cms- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-10027
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: %PROGRAMFILES%\ESTsoft\ALZip\Formats, %PROGRAMFILES%\ESTsoft\ALZip\Coders, %PROGRAMFILES(X86)%\ESTsoft\AL... Read more
Affected Products : alzip- Published: May. 17, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-10026
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.... Read more
Affected Products : yzmcms- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-10024
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if... Read more
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.4
MEDIUMCVE-2018-10023
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).... Read more
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10021
drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata qc leak) by triggering certain failure conditions. NOTE: a third party disputes the relevance of this report because the failure can o... Read more
Affected Products : linux_kernel- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-10018
The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument.... Read more
Affected Products : total_security- Published: Jul. 13, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10017
soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with many nested pattern loops.... Read more
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-10016
Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the expr5 function in asm/eval.c via a malformed input file.... Read more
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-10001
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.... Read more
- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-10000
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.... Read more
Affected Products : video_downloader- Published: Apr. 11, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002209
QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : quazip- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002208
SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : sharpziplib- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002207
mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vul... Read more
- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002206
SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : sharpcompress- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002204
adm-zip npm library before 0.4.9 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : adm-zip- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002203
unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : unzipper- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1002202
zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.... Read more
Affected Products : zip4j- Published: Jul. 25, 2018
- Modified: Nov. 21, 2024