CVE-2018-11000 to CVE-2018-11999
169 CVEs with public proof-of-concept exploits.
- CVE-2018-110131 PoCStack-based buffer overflow in the websRedirect function in GoAhead on D-Link DIR-816 A2 (CN) routers with firmware version 1.10B05 allows…
- CVE-2018-110171 PoCThe newVar_N function in decompile.c in libming through 0.4.8 mishandles cases where the header indicates a file size greater than the…
- CVE-2018-110181 PoCAn issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in…
- CVE-2018-110191 PoCkernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to…
- CVE-2018-110201 PoCkernel/omap/drivers/rpmsg/rpmsg_omx.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to inject a…
- CVE-2018-110211 PoCkernel/omap/drivers/video/omap2/dsscomp/device.c in the kernel component in Amazon Kindle Fire HD(3rd) Fire OS 4.5.5.3 allows attackers to…
- CVE-2018-110231 PoCkernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to…
- CVE-2018-110241 PoCkernel/omap/drivers/misc/gcx/gcioctl/gcif.c in the kernel component in Amazon Kindle Fire HD (3rd) Fire OS 4.5.5.3 allows attackers to…
- CVE-2018-110342 PoCsIn 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-110351 PoCIn 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-110371 PoCIn Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a…
- CVE-2018-110721 PoCDell Digital Delivery versions prior to 3.5.1 contain a DLL Injection Vulnerability. A local authenticated malicious user with advance…
- CVE-2018-110921 PoCAn issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an…
- CVE-2018-110931 PoCCross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web…
- CVE-2018-110942 PoCsAn issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and…
- CVE-2018-110961 PoCHorse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account…
- CVE-2018-111242 PoCsCross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers…
- CVE-2018-111261 PoCdg-user/?controller=users&action=add in doorGets 7.0 has CSRF that results in adding an administrator account.
- CVE-2018-111321 PoCIn order to perform actions that require higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue…
- CVE-2018-111332 PoCsThe 'fmt' parameter of the '/common/run_cross_report.php' script in the the Quest KACE System Management Appliance 8.0.318 is vulnerable…
- CVE-2018-111341 PoCIn order to perform actions that requires higher privileges, the Quest KACE System Management Appliance 8.0.318 relies on a message queue…
- CVE-2018-111351 PoCThe script '/adminui/error_details.php' in the Quest KACE System Management Appliance 8.0.318 allows authenticated users to conduct PHP…
- CVE-2018-111361 PoCThe 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318…
- CVE-2018-111371 PoCThe 'checksum' parameter of the '/common/download_attachment.php' script in the Quest KACE System Management Appliance 8.0.318 can be…
- CVE-2018-111384 PoCsKEVThe '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users…
- CVE-2018-111391 PoCThe '/common/ajax_email_connection_test.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by any…
- CVE-2018-111401 PoCThe 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not…
- CVE-2018-111411 PoCThe 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management…
- CVE-2018-111421 PoCThe 'systemui/settings_network.php' and 'systemui/settings_patching.php' scripts in the Quest KACE System Management Appliance 8.0.318 are…
- CVE-2018-111951 PoCMahara 17.04 before 17.04.8 and 17.10 before 17.10.5 and 18.04 before 18.04.1 are vulnerable to the browser "back and refresh" attack.…
- CVE-2018-112021 PoCA NULL pointer dereference was discovered in H5S_hyper_make_spans in H5Shyper.c in the HDF HDF5 1.10.2 library. It could allow a remote…
- CVE-2018-112031 PoCA division by zero was discovered in H5D__btree_decode_key in H5Dbtree.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of…
- CVE-2018-112041 PoCA NULL pointer dereference was discovered in H5O__chunk_deserialize in H5Ocache.c in the HDF HDF5 1.10.2 library. It could allow a remote…
- CVE-2018-112051 PoCA out of bounds read was discovered in H5VM_memcpyvv in H5VM.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of service…
- CVE-2018-112061 PoCAn out of bounds read was discovered in H5O_fill_new_decode and H5O_fill_old_decode in H5Ofill.c in the HDF HDF5 1.10.2 library. It could…
- CVE-2018-112071 PoCA division by zero was discovered in H5D__chunk_init in H5Dchunk.c in the HDF HDF5 1.10.2 library. It could allow a remote denial of…
- CVE-2018-112081 PoCAn issue was discovered in Z-BlogPHP 2.0.0. There is a persistent XSS that allows remote attackers to inject arbitrary web script or HTML…
- CVE-2018-112091 PoCAn issue was discovered in Z-BlogPHP 2.0.0. zb_system/cmd.php?act=verify relies on MD5 for the password parameter, which might make it…
- CVE-2018-112182 PoCsMemory Corruption was discovered in the cmsgpack library in the Lua subsystem in Redis before 3.2.12, 4.x before 4.0.10, and 5.x before…
- CVE-2018-112201 PoCBitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.
- CVE-2018-112221 PoCLocal File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the…
- CVE-2018-112272 PoCsMonstra CMS 3.0.4 and earlier has XSS via index.php.
- CVE-2018-112282 PoCsCrestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote…
- CVE-2018-112311 PoCIn the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
- CVE-2018-1123525 PoCsIn Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution…
- CVE-2018-112371 PoCAn AVX-512-optimized implementation of the mempcpy function in the GNU C Library (aka glibc or libc6) 2.27 and earlier may write data…
- CVE-2018-112421 PoCAn issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have…
- CVE-2018-112431 PoCPackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability…
- CVE-2018-112551 PoCAn issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to…
- CVE-2018-112561 PoCAn issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to…
- CVE-2018-113114 PoCsA hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the…
- CVE-2018-113322 PoCsStored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3…
- CVE-2018-113391 PoCAn XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.
- CVE-2018-113402 PoCsAn unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to…
- CVE-2018-113412 PoCsDirectory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename…
- CVE-2018-113421 PoCA path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a…
- CVE-2018-113432 PoCsA persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store…
- CVE-2018-113442 PoCsA path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a file on the…
- CVE-2018-113451 PoCAn unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the…
- CVE-2018-113462 PoCsAn insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the…
- CVE-2018-113471 PoCThe YunoHost 2.7.2 through 2.7.14 web application is affected by one HTTP Response Header Injection. This flaw allows an attacker to…
- CVE-2018-113481 PoCTwo XSS vulnerabilities are located in the profile edition page of the user panel of the YunoHost 2.7.2 through 2.7.14 web application. By…
- CVE-2018-113491 PoCThe administration panel of Jirafeau before 3.4.1 is vulnerable to three CSRF attacks on search functionalities: search_by_name,…
- CVE-2018-113501 PoCAn issue was discovered in Jirafeau before 3.4.1. The file "search by name" form is affected by one Cross-Site Scripting vulnerability via…
- CVE-2018-113511 PoCscript.php in Jirafeau before 3.4.1 is affected by two stored Cross-Site Scripting (XSS) vulnerabilities. These are stored within the…
- CVE-2018-113631 PoCjpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read.
- CVE-2018-113661 PoCinit.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging…
- CVE-2018-113711 PoCSkyCaiji 1.2 allows CSRF to add an Administrator user.
- CVE-2018-113721 PoCiScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
- CVE-2018-113731 PoCiScripts eSwap v2.4 has SQL injection via the "salelistdetailed.php" User Panel ToId parameter.
- CVE-2018-113961 PoCephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service…
- CVE-2018-114031 PoCDomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.
- CVE-2018-114041 PoCDomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.
- CVE-2018-114051 PoCKliqqi 2.0.2 has CSRF in admin/admin_users.php.
- CVE-2018-114093 PoCsSplunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as…
- CVE-2018-114101 PoCAn issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers…
- CVE-2018-114121 PoCIn the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in…
- CVE-2018-114131 PoCAn issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory…
- CVE-2018-114141 PoCAn issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php…
- CVE-2018-114151 PoCSAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has…
- CVE-2018-114301 PoCAn issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in…
- CVE-2018-114391 PoCThe TagLib::Ogg::FLAC::File::scan function in oggflacfile.cpp in TagLib 1.11.1 allows remote attackers to cause information disclosure…
- CVE-2018-114422 PoCsA CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as…
- CVE-2018-114431 PoCThe parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.
- CVE-2018-114442 PoCsA SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.
- CVE-2018-114452 PoCsA CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be…
- CVE-2018-114501 PoCA reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits…
- CVE-2018-114701 PoCiScripts eSwap v2.4 has SQL injection via the "search.php" 'Told' parameter in the User Panel.
- CVE-2018-114711 PoCCockpit 0.5.5 has XSS via a collection, form, or region.
- CVE-2018-114731 PoCMonstra CMS 3.0.4 has XSS in the registration Form (i.e., the login parameter to users/registration).
- CVE-2018-114792 PoCsThe VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that…
- CVE-2018-114882 PoCsA stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of…
- CVE-2018-114921 PoCASUS HG100 devices allow denial of service via an IPv4 packet flood.
- CVE-2018-114931 PoCAn issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add a friendship link via index.php?m=link&f=index&v=add.
- CVE-2018-114961 PoCIn Long Range Zip (aka lrzip) 0.631, there is a use-after-free in read_stream in stream.c, because decompress_file in lrzip.c lacks…
- CVE-2018-115001 PoCAn issue was discovered in PublicCMS V4.0.20180210. There is a CSRF vulnerability in…
- CVE-2018-115011 PoCPHP Scripts Mall Website Seller Script 2.0.3 has CSRF via user_submit.php?upd=2, with resultant XSS.
- CVE-2018-115022 PoCsAn issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in…
- CVE-2018-115052 PoCsThe Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.
- CVE-2018-115081 PoCThe compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from…
- CVE-2018-115092 PoCsASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are…
- CVE-2018-115105 PoCsThe ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the…
- CVE-2018-115113 PoCsThe tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the…
- CVE-2018-115121 PoCStored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in…
- CVE-2018-115152 PoCsThe wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
- CVE-2018-115161 PoCThe vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a…
- CVE-2018-115222 PoCsYosoro 1.0.4 has stored XSS.
- CVE-2018-115231 PoCupload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
- CVE-2018-115251 PoCThe plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.
- CVE-2018-115261 PoCThe plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.
- CVE-2018-115271 PoCAn issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php allows remote…
- CVE-2018-115281 PoCWUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
- CVE-2018-115293 PoCsVideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via…
- CVE-2018-115321 PoCAn issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject…
- CVE-2018-115352 PoCsAn issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable…
- CVE-2018-115383 PoCsservlet/UserServlet in SearchBlox 8.6.6 has CSRF via the u_name, u_passwd1, u_passwd2, role, and X-XSRF-TOKEN POST parameters because of…
- CVE-2018-115442 PoCsThe Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the…
- CVE-2018-115581 PoCDomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_first_name parameter.
- CVE-2018-115591 PoCDomainMod 4.10.0 has Stored XSS in the "/settings/profile/index.php" new_last_name parameter.
- CVE-2018-115644 PoCsStored XSS in YOOtheme Pagekit 1.0.13 and earlier allows a user to upload malicious code via the picture upload feature. A user with…
- CVE-2018-115671 PoCPrior to 2018-04-27, the reprompt feature in Amazon Echo devices could be misused by a custom Alexa skill. The reprompt feature is…
- CVE-2018-115681 PoCReflected XSS is possible in the GamePlan theme through 1.5.13.2 for WordPress because of insufficient input sanitization, as demonstrated…
- CVE-2018-115721 PoCClipperCMS 1.3.3 has XSS in the "Module name" field in a "Modules -> Manage modules -> edit" action to the manager/ URI.
- CVE-2018-115772 PoCsLiblouis 3.5.0 has a Segmentation fault in lou_logPrint in logging.c.
- CVE-2018-115782 PoCsGifIndexToTrueColor in ngiflib.c in MiniUPnP ngiflib 0.4 has a Segmentation fault.
- CVE-2018-115811 PoCCross-site scripting (XSS) vulnerability on Brother HL series printers allows remote attackers to inject arbitrary web script or HTML via…
- CVE-2018-115863 PoCsXML external entity (XXE) vulnerability in api/rest/status in SearchBlox 8.6.7 allows remote unauthenticated users to read arbitrary files…
- CVE-2018-116151 PoCThis vulnerability allows remote attackers to deny service on vulnerable installations of npm mosca 2.8.1. Authentication is not required…
- CVE-2018-116251 PoCIn ImageMagick 7.0.7-37 Q16, SetGrayscaleImage in the quantize.c file allows attackers to cause a heap-based buffer over-read via a…
- CVE-2018-116281 PoCData input into EMS Master Calendar before 8.0.0.201805210 via URL parameters is not properly sanitized, allowing malicious attackers to…
- CVE-2018-116311 PoCRondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notifications via crafted…
- CVE-2018-116464 PoCswebkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in…
- CVE-2018-116491 PoCHue 3.12 has XSS via the /pig/save/ name and script parameters.
- CVE-2018-116521 PoCCSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an…
- CVE-2018-116541 PoCInformation disclosure in Netwave IP camera at get_status.cgi (via HTTP on port 8000) allows an unauthenticated attacker to exfiltrate…
- CVE-2018-116701 PoCAn issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that allows attackers to execute arbitrary PHP code via the…
- CVE-2018-116711 PoCAn issue was discovered in GreenCMS v2.3.0603. There is a CSRF vulnerability that can add an admin account via…
- CVE-2018-116865 PoCsThe Publish Service in FlexPaper (later renamed FlowPaper) 2.3.6 allows remote code execution via setup.php and change_config.php.
- CVE-2018-116882 PoCsIgnite Realtime Openfire before 3.9.2 is vulnerable to cross-site scripting, caused by improper validation of user-supplied input. A…
- CVE-2018-116892 PoCsWeb Viewer for Hanwha DVR 2.17 and Smart Viewer in Samsung Web Viewer for Samsung DVR are vulnerable to XSS via the…
- CVE-2018-116902 PoCsThe Balbooa Gridbox extension version 2.4.0 and previous versions for Joomla! is vulnerable to cross-site scripting, caused by improper…
- CVE-2018-116921 PoCAn issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode…
- CVE-2018-116931 PoCAn issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function…
- CVE-2018-116941 PoCAn issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Functions::selector_append…
- CVE-2018-116951 PoCAn issue was discovered in LibSass <3.5.3. A NULL pointer dereference was found in the function Sass::Expand::operator which could be…
- CVE-2018-116961 PoCAn issue was discovered in LibSass through 3.5.4. A NULL pointer dereference was found in the function Sass::Inspect::operator which could…
- CVE-2018-116971 PoCAn issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function…
- CVE-2018-116981 PoCAn issue was discovered in LibSass through 3.5.4. An out-of-bounds read of a memory region was found in the function Sass::handle_error…
- CVE-2018-117092 PoCswpforo_get_request_uri in wpf-includes/functions.php in the wpForo Forum plugin before 1.4.12 for WordPress allows Unauthenticated…
- CVE-2018-117111 PoCA remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html…
- CVE-2018-117143 PoCsAn issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16…
- CVE-2018-117151 PoCThe Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
- CVE-2018-117161 PoCAn issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a…
- CVE-2018-117171 PoCAn issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent…
- CVE-2018-117221 PoCWUZHI CMS 4.1.0 has a SQL Injection in api/uc.php via the 'code' parameter, because 'UC_KEY' is hard coded.
- CVE-2018-117362 PoCsAn issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code…
- CVE-2018-117371 PoCAn issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory…
- CVE-2018-117381 PoCAn issue was discovered in libtskfs.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory…
- CVE-2018-117391 PoCAn issue was discovered in libtskimg.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory…
- CVE-2018-117401 PoCAn issue was discovered in libtskbase.a in The Sleuth Kit (TSK) from release 4.0.2 through to 4.6.1. An out-of-bounds read of a memory…
- CVE-2018-117414 PoCsNEC Univerge Sv9100 WebPro 6.00.00 devices have Predictable Session IDs that result in Account Information Disclosure via…
- CVE-2018-117424 PoCsNEC Univerge Sv9100 WebPro 6.00.00 devices have Cleartext Password Storage in the Web UI.
- CVE-2018-117596 PoCsThe Apache Web Server (httpd) specific code that normalised the requested path before matching it to the URI-worker map in Apache Tomcat…
- CVE-2018-117611 PoCIn Apache Tika 0.1 to 1.18, the XML parsers were not configured to limit entity expansion. They were therefore vulnerable to an entity…
- CVE-2018-117702 PoCsFrom version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism…
- CVE-2018-1177636 PoCsKEVApache Struts versions 2.3 to 2.3.34 and 2.5 to 2.5.16 suffer from possible Remote Code Execution when alwaysSelectFullNamespace is true…
- CVE-2018-117843 PoCsWhen the default servlet in Apache Tomcat versions 9.0.0.M1 to 9.0.11, 8.5.0 to 8.5.33 and 7.0.23 to 7.0.90 returned a redirect to a…
- CVE-2018-117881 PoCApache Karaf provides a features deployer, which allows users to "hot deploy" a features XML by dropping the file directly in the deploy…
- CVE-2018-117981 PoCThe Apache Thrift Node.js static web server in versions 0.9.2 through 0.11.0 have been determined to contain a security vulnerability in…