CVE-2018-12000 to CVE-2018-12999
168 CVEs with public proof-of-concept exploits.
- CVE-2018-120151 PoCIn Perl through 5.26.2, the Archive::Tar module allows remote attackers to bypass a directory-traversal protection mechanism, and…
- CVE-2018-120181 PoCThe GetBlockHeadersMsg handler in the LES protocol implementation in Go Ethereum (aka geth) before 1.8.11 may lead to an access violation…
- CVE-2018-120301 PoCChevereto Free before 1.0.13 has XSS.
- CVE-2018-120312 PoCsLocal file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory…
- CVE-2018-120342 PoCsIn YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds read vulnerability in yr_execute_code…
- CVE-2018-120352 PoCsIn YARA 3.7.1 and prior, parsing a specially crafted compiled rule file can cause an out of bounds write vulnerability in yr_execute_code…
- CVE-2018-120361 PoCOWASP Dependency-Check before 3.2.0 allows attackers to write to arbitrary files via a crafted archive that holds directory traversal…
- CVE-2018-120401 PoCReflected Cross-site scripting (XSS) vulnerability in the web profiler in SensioLabs Symfony 3.3.6 allows remote attackers to inject…
- CVE-2018-120451 PoCDedeCMS through V5.7SP2 allows arbitrary file upload in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=upload request…
- CVE-2018-120461 PoCDedeCMS through 5.7SP2 allows arbitrary file write in dede/file_manage_control.php via a dede/file_manage_view.php?fmdo=newfile request…
- CVE-2018-120481 PoCA remote attacker can bypass the Management Mode on the Canon LBP7110Cw web interface without a PIN for /checkLogin.cgi via vectors…
- CVE-2018-120491 PoCA remote attacker can bypass the System Manager Mode on the Canon LBP6030w web interface without a PIN for /checkLogin.cgi via vectors…
- CVE-2018-120511 PoCArbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script via $_FILE in…
- CVE-2018-120522 PoCsSQL Injection exists in PHP Scripts Mall Schools Alert Management Script via the q Parameter in get_sec.php.
- CVE-2018-120532 PoCsArbitrary File Deletion exists in PHP Scripts Mall Schools Alert Management Script via the img parameter in delete_img.php by using…
- CVE-2018-120543 PoCsArbitrary File Read exists in PHP Scripts Mall Schools Alert Management Script via the f parameter in img.php, aka absolute path traversal.
- CVE-2018-120552 PoCsMultiple SQL Injections exist in PHP Scripts Mall Schools Alert Management Script via crafted POST data in contact_us.php, faq.php,…
- CVE-2018-120861 PoCBuffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.
- CVE-2018-120901 PoCThere is unauthenticated reflected cross-site scripting (XSS) in LAMS before 3.1 that allows a remote attacker to introduce arbitrary…
- CVE-2018-120942 PoCsCross-site scripting (XSS) vulnerability in news.php in Dimofinf CMS Version 3.0.0 allows remote attackers to inject arbitrary web script…
- CVE-2018-120953 PoCsA Reflected Cross-Site Scripting web vulnerability has been discovered in the OEcms v3.1 web-application. The vulnerability is located in…
- CVE-2018-120991 PoCGrafana before 5.2.0-beta1 has XSS vulnerabilities in dashboard links.
- CVE-2018-121011 PoCCMS Clipper 1.3.3 has XSS in the Security tab search, User Groups, Resource Groups, and User/Resource Group Links fields.
- CVE-2018-121041 PoCCross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML…
- CVE-2018-121111 PoCCross-site scripting (XSS) vulnerability in the Canon PrintMe EFI webinterface allows remote attackers to inject arbitrary web script or…
- CVE-2018-121121 PoCmd_build_attribute in md4c.c in md4c 0.2.6 allows remote attackers to cause a denial of service (Segmentation fault and application crash)…
- CVE-2018-121133 PoCsCore FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a…
- CVE-2018-121141 PoCMaccms 10 allows CSRF via admin.php/admin/admin/info.html to add user accounts.
- CVE-2018-121161 PoCNode.js: All versions prior to Node.js 6.15.0 and 8.14.0: HTTP request splitting: If Node.js can be convinced to use unsanitized…
- CVE-2018-122341 PoCA Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing…
- CVE-2018-122501 PoCAn issue was discovered in Elite CMS Pro 2.01. In /admin/add_sidebar.php, the ?page= parameter is vulnerable to SQL injection.
- CVE-2018-122541 PoCrouter.php in the Harmis Ek rishta (aka ek-rishta) 2.10 component for Joomla! allows SQL Injection via the PATH_INFO to a…
- CVE-2018-122571 PoCAn issue was discovered on Momentum Axel 720P 5.1.8 devices. There is Authenticated Custom Firmware Upgrade via DNS Hijacking. An…
- CVE-2018-122642 PoCsExiv2 0.26 has integer overflows in LoaderTiff::getData() in preview.cpp, leading to an out-of-bounds read in…
- CVE-2018-122652 PoCsExiv2 0.26 has an integer overflow in the LoaderExifJpeg class in preview.cpp, leading to an out-of-bounds read in Exiv2::MemIo::read in…
- CVE-2018-122661 PoCsystem\errors\404.php in HongCMS 3.0.0 has XSS via crafted input that triggers a 404 HTTP status code.
- CVE-2018-122921 PoCA use-after-free vulnerability exists in DOMProxyHandler::EnsureExpandoObject in Pale Moon before 27.9.3.
- CVE-2018-122931 PoCThe getImageData function in the ImageBufferCairo class in WebCore/platform/graphics/cairo/ImageBufferCairo.cpp in WebKit, as used in…
- CVE-2018-122951 PoCSQL injection in folderViewSpecific.psp in Seagate NAS OS version 4.3.15.1 allows attackers to execute arbitrary SQL commands via the…
- CVE-2018-122962 PoCsInsufficient access control in /api/external/7.0/system.System.get_infos in Seagate NAS OS version 4.3.15.1 allows attackers to obtain…
- CVE-2018-122971 PoCCross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.
- CVE-2018-122981 PoCDirectory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL…
- CVE-2018-122991 PoCCross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
- CVE-2018-123002 PoCsArbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header…
- CVE-2018-123031 PoCCross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
- CVE-2018-123041 PoCCross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple…
- CVE-2018-123051 PoCCross-site scripting in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript by uploading SVG images with…
- CVE-2018-123061 PoCDirectory Traversal in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to view arbitrary files by modifying the "file1" URL…
- CVE-2018-123071 PoCOS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "name" POST…
- CVE-2018-123081 PoCEncryption key disclosure in share.cgi in ASUSTOR ADM version 3.1.1 allows attackers to obtain the encryption key via the "encrypt_key"…
- CVE-2018-123091 PoCDirectory Traversal in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to upload files to arbitrary locations by modifying the…
- CVE-2018-123101 PoCCross-site scripting in the Login page in ASUSTOR ADM version 3.1.1 allows attackers to execute JavaScript via the System Announcement…
- CVE-2018-123111 PoCCross-site scripting vulnerability in File Explorer in ASUSTOR ADM version 3.1.1 allows attackers to execute arbitrary JavaScript when a…
- CVE-2018-123121 PoCOS command injection in user.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root via the "secret_key" URL…
- CVE-2018-123131 PoCOS command injection in snmp.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands without authentication via the…
- CVE-2018-123141 PoCDirectory Traversal in downloadwallpaper.cgi in ASUSTOR ADM version 3.1.1 allows attackers to download arbitrary files by manipulating the…
- CVE-2018-123151 PoCMissing verification of a password in ASUSTOR ADM version 3.1.1 allows attackers to change account passwords without entering the current…
- CVE-2018-123161 PoCOS Command Injection in upload.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands by modifying the filename POST…
- CVE-2018-123171 PoCOS command injection in group.cgi in ASUSTOR ADM version 3.1.1 allows attackers to execute system commands as root by modifying the "name"…
- CVE-2018-123181 PoCInformation disclosure in the SNMP settings page in ASUSTOR ADM version 3.1.1 allows attackers to obtain the SNMP password in cleartext.
- CVE-2018-123191 PoCDenial-of-service in the login page of ASUSTOR ADM 3.1.1 allows attackers to prevent users from signing in by placing malformed text in…
- CVE-2018-123262 PoCsBuffer overflow in redis-cli of Redis before 4.0.10 and 5.x before 5.0 RC3 allows an attacker to achieve code execution and escalate to…
- CVE-2018-123271 PoCStack-based buffer overflow in ntpq and ntpdc of NTP version 4.2.8p11 allows an attacker to achieve code execution or escalate to higher…
- CVE-2018-123681 PoCWindows 10 does not warn users before opening executable files with the SettingContent-ms extension even when they have been downloaded…
- CVE-2018-123863 PoCsA vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to…
- CVE-2018-124181 PoCArchive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an…
- CVE-2018-124471 PoCThe restore_tqb_pixels function in hevc_filter.c in libavcodec, as used in libbpg 0.9.8 and other products, has an integer overflow that…
- CVE-2018-124531 PoCType confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause…
- CVE-2018-124551 PoCIntelbras NPLUG 1.0.0.14 wireless repeater devices have a critical vulnerability that allows an attacker to authenticate in the web…
- CVE-2018-124632 PoCsMFSBGN03811 rev.1 - Fortify Software Security Center (SSC), Multiple vulnerabilities
- CVE-2018-124642 PoCsUnauthenticated SQL injection in Micro Focus Secure Messaging Gateway
- CVE-2018-124652 PoCsRemote Code Execution in Micro Focus Secure Messaging Gateway
- CVE-2018-124821 PoCOCS Inventory 2.4.1 contains multiple SQL injections in the search engine. Authentication is needed in order to exploit the issues.
- CVE-2018-124831 PoCOCS Inventory 2.4.1 is prone to a remote command-execution vulnerability. Specifically, this issue occurs because the content of the…
- CVE-2018-124931 PoCAn issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an…
- CVE-2018-124941 PoCAn issue was discovered in PublicCMS V4.0.20180210. There is a "Directory Traversal" and "Arbitrary file read" vulnerability via an…
- CVE-2018-124951 PoCThe quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based…
- CVE-2018-125192 PoCsAn issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js…
- CVE-2018-125202 PoCsAn issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program…
- CVE-2018-125222 PoCsAn issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory…
- CVE-2018-125232 PoCsAn issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory…
- CVE-2018-125242 PoCsAn issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory…
- CVE-2018-125252 PoCsAn issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory…
- CVE-2018-125281 PoCAn issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a…
- CVE-2018-125291 PoCAn issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including…
- CVE-2018-125321 PoCJBoss RichFaces 4.5.3 through 4.5.17 allows unauthenticated remote attackers to inject an arbitrary expression language (EL) variable…
- CVE-2018-125336 PoCsJBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute…
- CVE-2018-125371 PoCIn Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and…
- CVE-2018-125401 PoCIn version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form…
- CVE-2018-125421 PoCIn version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a…
- CVE-2018-125713 PoCsuniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS…
- CVE-2018-125721 PoCAvast Free Antivirus prior to 19.1.2360 stores user credentials in memory upon login, which allows local users to obtain sensitive…
- CVE-2018-125781 PoCThere is a heap-based buffer overflow in bmp_compress1_row in appliers.cpp in sam2p 0.49.4 that leads to a denial of service or possibly…
- CVE-2018-125821 PoCAn issue was discovered in AKCMS 6.1. CSRF can add an admin account via a /index.php?file=account&action=manageaccounts&job=newaccount URI.
- CVE-2018-125831 PoCAn issue was discovered in AKCMS 6.1. CSRF can delete an article via an admincp deleteitem action to index.php.
- CVE-2018-125842 PoCsThe ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to…
- CVE-2018-125892 PoCsPolaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current…
- CVE-2018-125963 PoCsEpiserver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call…
- CVE-2018-125991 PoCIn ImageMagick 7.0.8-3 Q16, ReadBMPImage and WriteBMPImage in coders/bmp.c allow attackers to cause an out of bounds write via a crafted…
- CVE-2018-126001 PoCIn ImageMagick 7.0.8-3 Q16, ReadDIBImage and WriteDIBImage in coders/dib.c allow attackers to cause an out of bounds write via a crafted…
- CVE-2018-126011 PoCThere is a heap-based buffer overflow in ReadImage in input-tga.ci in sam2p 0.49.4 that leads to a denial of service or possibly…
- CVE-2018-126022 PoCsA CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
- CVE-2018-126032 PoCsCross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of…
- CVE-2018-126042 PoCsGreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.
- CVE-2018-126071 PoCAn issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1.…
- CVE-2018-126091 PoCOX App Suite 7.8.4 and earlier allows Server-Side Request Forgery.
- CVE-2018-126101 PoCOX App Suite 7.8.4 and earlier allows Information Exposure.
- CVE-2018-126111 PoCOX App Suite 7.8.4 and earlier allows Directory Traversal.
- CVE-2018-1261314 PoCsAn issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the…
- CVE-2018-126172 PoCsqmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer…
- CVE-2018-126301 PoCNEWMARK (aka New Mark) NMCMS 2.1 allows SQL Injection via the sect_id parameter to the /catalog URI.
- CVE-2018-126311 PoCRedatam7 (formerly Redatam WebServer) allows remote attackers to read arbitrary files via /redbin/rpwebutilities.exe/text?LFN=../…
- CVE-2018-126321 PoCRedatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN parameter to the…
- CVE-2018-126331 PoCAn issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the…
- CVE-2018-126343 PoCsCirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or…
- CVE-2018-126362 PoCsThe iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via…
- CVE-2018-126381 PoCAn issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious…
- CVE-2018-126481 PoCThe WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.
- CVE-2018-126501 PoCAdrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via…
- CVE-2018-126531 PoCA Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious JavaScript code in…
- CVE-2018-126591 PoCSLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token…
- CVE-2018-126661 PoCSV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the…
- CVE-2018-126671 PoCThe SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication…
- CVE-2018-126681 PoCSV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices have a Hard-coded Password.
- CVE-2018-126691 PoCSV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow remote authenticated users to…
- CVE-2018-126701 PoCSV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection.
- CVE-2018-126711 PoCAn attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web…
- CVE-2018-126721 PoCThe SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable…
- CVE-2018-126731 PoCAn attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web…
- CVE-2018-126741 PoCThe SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within…
- CVE-2018-126752 PoCsThe SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs…
- CVE-2018-126891 PoCphpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and…
- CVE-2018-126922 PoCsTP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell…
- CVE-2018-126931 PoCStack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause…
- CVE-2018-126941 PoCTP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via…
- CVE-2018-127051 PoCDIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).
- CVE-2018-127061 PoCDIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
- CVE-2018-127101 PoCAn issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low…
- CVE-2018-127151 PoCDIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.
- CVE-2018-127391 PoCIn BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
- CVE-2018-127982 PoCsAdobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap…
- CVE-2018-128271 PoCAdobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information…
- CVE-2018-128332 PoCsAdobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap…
- CVE-2018-128382 PoCsAdobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a stack…
- CVE-2018-128412 PoCsAdobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a double…
- CVE-2018-128851 PoCThe randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random value with publicly…
- CVE-2018-128954 PoCsWordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb…
- CVE-2018-128973 PoCsSolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.
- CVE-2018-129031 PoCIn CyberArk Endpoint Privilege Manager (formerly Viewfinity) 10.2.1.603, there is persistent XSS via an account name on the create token…
- CVE-2018-129041 PoCIn arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to…
- CVE-2018-129082 PoCsBrynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via…
- CVE-2018-129092 PoCsWebgrind 1.5 relies on user input to display a file, which lets anyone view files from the local filesystem (that the webserver user has…
- CVE-2018-129121 PoCAn issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an…
- CVE-2018-129131 PoCIn Miniz 2.0.7, tinfl_decompress in miniz_tinfl.c has an infinite loop because sym2 and counter can both remain equal to zero.
- CVE-2018-129191 PoCIn CraftedWeb through 2013-09-24, aasp_includes/pages/notice.php allows XSS via the e parameter.
- CVE-2018-129711 PoCEasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.
- CVE-2018-129771 PoCA SQL injection vulnerability in the SoftExpert (SE) Excellence Suite 2.0 allows remote authenticated users to perform SQL heuristics by…
- CVE-2018-129793 PoCsAn issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an…
- CVE-2018-129803 PoCsAn issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an…
- CVE-2018-129813 PoCsAn issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited…
- CVE-2018-129821 PoCInvalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have…
- CVE-2018-129831 PoCA stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be…
- CVE-2018-129841 PoCHycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.
- CVE-2018-129901 PoCphpwcms 1.8.9 allows remote attackers to discover the installation path via an invalid csrf_token_value field.
- CVE-2018-129963 PoCsA reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote…
- CVE-2018-129972 PoCsIncorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager…
- CVE-2018-129984 PoCsA reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration…
- CVE-2018-129993 PoCsIncorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on…