Latest CVE Feed

Following is the list of latest published vulnerabilities. You can filter the list based on the severity of the vulnerability, whether it is actively exploited (also known as CISA KEV List) or remotely exploitable. You can also sort the list based on the published date, last updated date, or CVSS score.
  • 6.1

    MEDIUM
    CVE-2018-10366

    An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field.... Read more

    Affected Products : user
    • Published: Apr. 25, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10365

    An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.... Read more

    Affected Products : threads_to_link
    • Published: May. 01, 2018
    • Modified: Nov. 21, 2024
  • 5.4

    MEDIUM
    CVE-2018-10364

    BigTree before 4.2.22 has XSS in the Users management page via the name or company field.... Read more

    Affected Products : bigtree_cms
    • Published: Apr. 30, 2018
    • Modified: Nov. 21, 2024
  • 7.5

    HIGH
    CVE-2018-10363

    An issue was discovered in the WpDevArt "Booking calendar, Appointment Booking System" plugin 2.2.2 for WordPress. Multiple parameters allow remote attackers to manipulate the values to change data such as prices.... Read more

    Affected Products : booking_calendar
    • Published: Jun. 13, 2018
    • Modified: Nov. 21, 2024
  • 9.8

    CRITICAL
    CVE-2018-10362

    An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, it is possible to login with a simpler password if the password has the fo... Read more

    Affected Products : phpliteadmin
    • Published: Apr. 25, 2018
    • Modified: Nov. 21, 2024
  • 7.8

    HIGH
    CVE-2018-10361

    An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allow other unprivileged users on the local system to gain r... Read more

    Affected Products : ktexteditor
    • Published: Apr. 25, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-10360

    The do_core_note function in readelf.c in libmagic.a in file 5.33 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted ELF file.... Read more

    Affected Products : ubuntu_linux leap file
    • Published: Jun. 11, 2018
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2018-10359

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220078 in the TMWFP driver. An at... Read more

    Affected Products : officescan
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 6.3

    MEDIUM
    CVE-2018-10358

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x2200B4 in the TMWFP driver. An at... Read more

    Affected Products : officescan
    • Published: Jun. 08, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-10357

    A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulne... Read more

    Affected Products : endpoint_application_control
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-10356

    A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. Authentication is requir... Read more

    Affected Products : email_encryption_gateway
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 7.0

    HIGH
    CVE-2018-10355

    An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user databa... Read more

    Affected Products : email_encryption_gateway
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-10354

    A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to e... Read more

    Affected Products : email_encryption_gateway
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 6.5

    MEDIUM
    CVE-2018-10353

    A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to disclose sensitive information on vulnerable installations due to a flaw in the formChangePass class. Authentication is requi... Read more

    Affected Products : email_encryption_gateway
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 8.8

    HIGH
    CVE-2018-10352

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formConfiguration class. Authentication is required to exploit this vulnerabilit... Read more

    Affected Products : email_encryption_gateway
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-10351

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is required to exploit this vulnerabilit... Read more

    Affected Products : email_encryption_gateway
    • Published: May. 23, 2018
    • Modified: Nov. 21, 2024
  • 9.0

    HIGH
    CVE-2018-10350

    A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw within the handling of parameters provided to wcs... Read more

    • Published: May. 25, 2018
    • Modified: Nov. 21, 2024
  • 6.1

    MEDIUM
    CVE-2018-10329

    app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.... Read more

    Affected Products : phpipam
    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 7.4

    HIGH
    CVE-2018-10328

    Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream.... Read more

    • Published: Apr. 24, 2018
    • Modified: Nov. 21, 2024
  • 7.0

    HIGH
    CVE-2018-10327

    PrinterOn Enterprise 4.1.3 stores the Active Directory bind credentials using base64 encoding, which allows local users to obtain credentials for a domain user by reading the cps_config.xml file.... Read more

    Affected Products : printeron
    • Published: May. 17, 2018
    • Modified: Nov. 21, 2024
Showing 20 of 294125 Results