Latest CVE Feed
-
5.3
MEDIUMCVE-2018-1000068
An improper input validation vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to access plugin resource files in the META-INF and WEB-INF directories that should not be accessible, if the Jenk... Read more
- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-1000067
An improper authorization vulnerability exists in Jenkins versions 2.106 and earlier, and LTS 2.89.3 and earlier, that allows an attacker to have Jenkins submit HTTP GET requests and get limited information about the response.... Read more
- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
4.4
MEDIUMCVE-2018-1000062
WonderCMS version 2.4.0 contains a Stored Cross-Site Scripting on File Upload through SVG vulnerability in uploadFileAction(), 'svg' => 'image/svg+xml' that can result in An attacker can execute arbitrary script on an unsuspecting user's browser. This att... Read more
Affected Products : wondercms- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000060
Sensu, Inc. Sensu Core version Before 1.2.0 & before commit 46ff10023e8cbf1b6978838f47c51b20b98fe30b contains a CWE-522 vulnerability in Sensu::Utilities.redact_sensitive() that can result in sensitive configuration data (e.g. passwords) may be logged in ... Read more
Affected Products : sensu_core- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000059
ValidFormBuilder version 4.5.4 contains a PHP Object Injection vulnerability in Valid Form unserialize method that can result in Possible to execute unauthorised system commands remotely and disclose file contents in file system.... Read more
Affected Products : validform_builder- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000058
Jenkins Pipeline: Supporting APIs Plugin 2.17 and earlier have an arbitrary code execution due to incomplete sandbox protection: Methods related to Java deserialization like readResolve implemented in Pipeline scripts were not subject to sandbox protectio... Read more
Affected Products : pipeline_supporting_apis- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-1000057
Jenkins Credentials Binding Plugin 1.14 and earlier masks passwords it provides to build processes in their build logs. Jenkins however transforms provided password values, e.g. replacing environment variable references, which could result in values diffe... Read more
Affected Products : credentials_binding- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2018-1000056
Jenkins JUnit Plugin 1.23 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or ... Read more
Affected Products : junit- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2018-1000055
Jenkins Android Lint Plugin 2.5 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forger... Read more
Affected Products : android_lint- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.3
HIGHCVE-2018-1000054
Jenkins CCM Plugin 3.1 and earlier processes XML external entities in files it parses as part of the build process, allowing attackers with user permissions in Jenkins to extract secrets from the Jenkins master, perform server-side request forgery, or den... Read more
Affected Products : ccm- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000053
LimeSurvey version 3.0.0-beta.3+17110 contains a Cross ite Request Forgery (CSRF) vulnerability in Theme Uninstallation that can result in CSRF causing LimeSurvey admins to delete all their themes, rendering the website unusable. This attack appear to be ... Read more
Affected Products : limesurvey- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000052
fmtlib version prior to version 4.1.0 (before commit 0555cea5fc0bf890afe0071a558e44625a34ba85) contains a Memory corruption (SIGSEGV), CWE-134 vulnerability in fmt::print() library function that can result in Denial of Service. This attack appear to be ex... Read more
Affected Products : fmt- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000051
Artifex Mupdf version 1.12.0 contains a Use After Free vulnerability in fz_keep_key_storable that can result in DOS / Possible code execution. This attack appear to be exploitable via Victim opens a specially crafted PDF.... Read more
- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000050
Sean Barrett stb_vorbis version 1.12 and earlier contains a Buffer Overflow vulnerability in All vorbis decoding paths. that can result in memory corruption, denial of service, comprised execution of host program. This attack appear to be exploitable via ... Read more
Affected Products : stb_vorbis- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-1000049
Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled.... Read more
Affected Products : claymore_dual_miner- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000048
NASA RtRetrievalFramework version v1.0 contains a CWE-502 vulnerability in Data retrieval functionality of RtRetrieval framework that can result in remote code execution. This attack appear to be exploitable via Victim tries to retrieve and process a weat... Read more
Affected Products : rtretrievalframework- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-1000047
NASA Kodiak version v1.0 contains a CWE-502 vulnerability in Kodiak library's data processing function that can result in remote code execution. This attack appear to be exploitable via Victim opens an untrusted file for optimization using Kodiak library.... Read more
Affected Products : kodiak- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000046
NASA Pyblock version v1.0 - v1.3 contains a CWE-502 vulnerability in Radar data parsing library that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability appea... Read more
Affected Products : pyblock- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-1000045
NASA Singledop version v1.0 contains a CWE-502 vulnerability in NASA Singledop library (Weather data) that can result in remote code execution. This attack appear to be exploitable via Victim opening a specially crafted radar data file. This vulnerability... Read more
Affected Products : singledop- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024
-
9.8
CRITICALCVE-2018-1000044
Security Onion Solutions Squert version 1.1.1 through 1.6.7 contains a SQL Injection vulnerability in .inc/callback.php that can result in execution of SQL commands. This attack appear to be exploitable via Web request to .inc/callback.php with the payloa... Read more
Affected Products : squert- Published: Feb. 09, 2018
- Modified: Nov. 21, 2024