Latest CVE Feed
-
8.8
HIGHCVE-2018-1002103
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebinding to indirectly make requests to the Kubernetes Dashboa... Read more
Affected Products : minikube- Published: Dec. 05, 2018
- Modified: Nov. 21, 2024
-
2.6
LOWCVE-2018-1002102
Improper validation of URL redirection in the Kubernetes API server in versions prior to v1.14.0 allows an attacker-controlled Kubelet to redirect API server requests from streaming endpoints to arbitrary hosts. Impacted API servers will follow the redire... Read more
- Published: Dec. 05, 2019
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1002101
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument injection.... Read more
Affected Products : kubernetes- Published: Dec. 05, 2018
- Modified: Nov. 21, 2024
-
5.5
MEDIUMCVE-2018-1002100
In Kubernetes versions 1.5.x, 1.6.x, 1.7.x, 1.8.x, and prior to version 1.9.6, the kubectl cp command insecurely handles tar data returned from the container, and can be caused to overwrite arbitrary local files.... Read more
Affected Products : kubernetes- Published: Jun. 02, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002009
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email vari... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002008
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002007
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request va... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002006
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002005
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002004
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002003
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002002
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-1002001
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
7.2
HIGHCVE-2018-1002000
There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.... Read more
Affected Products : arigato_autoresponder_and_newsletter- Published: Dec. 03, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-1000998
FreeBSD CVSweb version 2.x contains a Cross Site Scripting (XSS) vulnerability in all pages that can result in limited impact--CVSweb is anonymous & read-only. It might impact other sites on same domain. This attack appears to be exploitable via victim mu... Read more
Affected Products : cvsweb- Published: Feb. 04, 2019
- Modified: Nov. 21, 2024
-
6.5
MEDIUMCVE-2018-1000997
A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jel... Read more
Affected Products : jenkins- Published: Jan. 23, 2019
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000893
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.... Read more
Affected Products : bitcoin_sv- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000892
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving sendheaders messages.... Read more
Affected Products : bitcoin_sv- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000891
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when receiving messages with invalid checksums.... Read more
Affected Products : bitcoin_sv- Published: Dec. 23, 2020
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000890
FrontAccounting 2.4.5 contains a Time Based Blind SQL Injection vulnerability in the parameter "filterType" in /attachments.php that can allow the attacker to grab the entire database of the application.... Read more
Affected Products : frontaccounting- Published: Dec. 28, 2018
- Modified: Nov. 21, 2024