Latest CVE Feed
-
8.8
HIGHCVE-2018-0530
SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.... Read more
Affected Products : garoon- Published: Apr. 16, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0529
Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.... Read more
Affected Products : office- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0528
Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.... Read more
Affected Products : office- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0527
Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : office- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
4.3
MEDIUMCVE-2018-0526
Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified vectors.... Read more
Affected Products : office- Published: Jun. 26, 2018
- Modified: Nov. 21, 2024
-
5.3
MEDIUMCVE-2018-0525
Directory traversal vulnerability in Jubatus 1.0.2 and earlier allows remote attackers to read arbitrary files via unspecified vectors.... Read more
Affected Products : jubatus- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
7.5
HIGHCVE-2018-0524
Jubatus 1.0.2 and earlier allows remote code execution via unspecified vectors.... Read more
Affected Products : jubatus- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0523
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.... Read more
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0522
Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a specially crafted file.... Read more
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0521
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.... Read more
- Published: Mar. 09, 2018
- Modified: Nov. 21, 2024
-
8.8
HIGHCVE-2018-0520
Cross-site request forgery (CSRF) vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to hijack the authentication of administrators via unspecified vectors.... Read more
- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
4.8
MEDIUMCVE-2018-0519
Cross-site scripting vulnerability in FS010W firmware FS010W_00_V1.3.0 and earlier allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
5.9
MEDIUMCVE-2018-0518
LINE for iOS version 7.1.3 to 7.1.5 does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.... Read more
Affected Products : line- Published: Feb. 23, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0517
Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : anshin_net_security- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0516
Untrusted search path vulnerability in FLET'S v4 / v6 address selection tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : address_selection_tool- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
7.8
HIGHCVE-2018-0515
Untrusted search path vulnerability in "FLET'S Azukeru Backup Tool" version 1.5.2.6 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.... Read more
Affected Products : azukeru_backup_tool- Published: Feb. 16, 2018
- Modified: Nov. 21, 2024
-
10.0
HIGHCVE-2018-0514
MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : mp_form_mail_cgi- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0513
Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : simple_booking- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
7.7
HIGHCVE-2018-0512
Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.... Read more
Affected Products : wn-g300r3_firmware wn-g300r_firmware hdl2-ah hdl2-a_firmware hdl-ah hdl-a_firmware hdl-xr_firmware hdl-xrw_firmware hdl-xr2u_firmware hdl-xr2uw_firmware +80 more products- Published: Feb. 08, 2018
- Modified: Nov. 21, 2024
-
6.1
MEDIUMCVE-2018-0511
Cross-site scripting vulnerability in WP Retina 2x prior to version 5.2.2 allows an attacker to inject arbitrary web script or HTML via unspecified vectors.... Read more
Affected Products : wp_retina_2x- Published: Feb. 01, 2018
- Modified: Nov. 21, 2024