CVE-2018-15000 to CVE-2018-15999
175 CVEs with public proof-of-concept exploits.
- CVE-2018-150011 PoCThe Vivo V7 Android device with a build fingerprint of vivo/1718/1718:7.1.2/N2G47H/compil11021857:user/release-keys contains a platform…
- CVE-2018-150031 PoCThe Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Revvl Plus…
- CVE-2018-150042 PoCsThe Coolpad Canvas device with a build fingerprint of Coolpad/cp3636a/cp3636a:7.0/NRD90M/093031423:user/release-keys contains a platform…
- CVE-2018-150051 PoCThe ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a…
- CVE-2018-150061 PoCThe ZTE ZMAX Champ Android device with a build fingerprint of ZTE/Z917VL/fortune:6.0.1/MMB29M/20170327.120922:user/release-keys contains a…
- CVE-2018-150071 PoCThe Sky Elite 6.0L+ Android device with a build fingerprint of…
- CVE-2018-151201 PoClibpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service…
- CVE-2018-151291 PoCThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
- CVE-2018-151301 PoCThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
- CVE-2018-151311 PoCAn issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8…
- CVE-2018-1513317 PoCsKEVIn Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a…
- CVE-2018-151361 PoCTitanHQ SpamTitan before 7.01 has Improper input validation. This allows internal attackers to bypass the anti-spam filter to send…
- CVE-2018-151371 PoCCeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes…
- CVE-2018-151382 PoCsEricsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
- CVE-2018-151397 PoCsUnrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated…
- CVE-2018-151401 PoCDirectory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the…
- CVE-2018-151411 PoCDirectory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the…
- CVE-2018-151422 PoCsDirectory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the…
- CVE-2018-151524 PoCsAuthentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to…
- CVE-2018-151531 PoCOS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands…
- CVE-2018-151571 PoCThe libfsclfs_block_read function in libfsclfs_block.c in libfsclfs before 2018-07-25 allows remote attackers to cause a heap-based buffer…
- CVE-2018-151581 PoCThe libesedb_page_read_values function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based…
- CVE-2018-151591 PoCThe libesedb_page_read_tags function in libesedb_page.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based…
- CVE-2018-151601 PoCThe libesedb_catalog_definition_read function in libesedb_catalog_definition.c in libesedb through 2018-04-01 allows remote attackers to…
- CVE-2018-151611 PoCThe libesedb_key_append_data function in libesedb_key.c in libesedb through 2018-04-01 allows remote attackers to cause a heap-based…
- CVE-2018-151681 PoCA SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a…
- CVE-2018-151691 PoCA reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote…
- CVE-2018-151721 PoCTP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
- CVE-2018-151732 PoCsNmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application…
- CVE-2018-151741 PoCXnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash)…
- CVE-2018-151751 PoCXnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at…
- CVE-2018-151761 PoCXnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and…
- CVE-2018-151781 PoCOpen redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing…
- CVE-2018-151812 PoCsJioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID…
- CVE-2018-151821 PoCPHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.
- CVE-2018-151831 PoCPHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields.
- CVE-2018-151841 PoCPHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to CVE-2018-6795.
- CVE-2018-151851 PoCPHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via…
- CVE-2018-151861 PoCPHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.
- CVE-2018-151871 PoCPHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.
- CVE-2018-151881 PoCPHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted…
- CVE-2018-151891 PoCPHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
- CVE-2018-151901 PoCPHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
- CVE-2018-151911 PoCPHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First…
- CVE-2018-151971 PoCAn issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow…
- CVE-2018-151981 PoCAn issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.
- CVE-2018-152021 PoCAn issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in…
- CVE-2018-152031 PoCAn issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.
- CVE-2018-152061 PoCBPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
- CVE-2018-152071 PoCBPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to…
- CVE-2018-152081 PoCBPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
- CVE-2018-152091 PoCChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer…
- CVE-2018-153651 PoCA Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to…
- CVE-2018-153792 PoCsCisco Prime Infrastructure Arbitrary File Upload and Command Execution Vulnerability
- CVE-2018-153891 PoCCisco Prime Collaboration Provisioning Intermittent Hard-Coded Password Vulnerability
- CVE-2018-154371 PoCCisco Immunet and Cisco AMP for Endpoints System Scan Denial of Service Vulnerability
- CVE-2018-154391 PoCCisco Small Business Switches Privileged Access Vulnerability
- CVE-2018-154423 PoCsCisco Webex Meetings Desktop App Update Service Command Injection Vulnerability
- CVE-2018-154441 PoCCisco Energy Management Suite XML External Entity Vulnerability
- CVE-2018-154451 PoCCisco Energy Management Suite Cross-Site Request Forgery Vulnerability
- CVE-2018-154651 PoCCisco Adaptive Security Appliance Software Privilege Escalation Vulnerability
- CVE-2018-1547360 PoCsOpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until…
- CVE-2018-154743 PoCsCSV Injection (aka Excel Macro Injection or Formula Injection) in /lib/plugins/usermanager/admin.php in DokuWiki 2018-04-22a and earlier…
- CVE-2018-154861 PoCAn issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is…
- CVE-2018-154911 PoCA vulnerability in the permission and encryption implementation of Zemana Anti-Logger 1.9.3.527 and prior (fixed in 1.9.3.602) allows an…
- CVE-2018-154991 PoCGEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condition and BSoD on…
- CVE-2018-155081 PoCFive9 Agent Desktop Plus 10.0.70 has Incorrect Access Control allowing a remote attackers to cause a denial of service via opening a…
- CVE-2018-155091 PoCFive9 Agent Desktop Plus 10.0.70 has Incorrect Access Control (issue 2 of 2).
- CVE-2018-155141 PoCHandleRequestAsync in Docker for Windows before 18.06.0-ce-rc3-win68 (edge) and before 18.06.0-ce-win72 (stable) deserialized requests…
- CVE-2018-155152 PoCsThe CaptivelPortal service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices will load a Trojan horse "quserex.dll" from the…
- CVE-2018-155162 PoCsThe FTP service on D-Link Central WiFiManager CWM-100 1.03 r0098 devices allows remote attackers to conduct a PORT command bounce scan via…
- CVE-2018-155173 PoCsThe MailConnect feature on D-Link Central WiFiManager CWM-100 1.03 r0098 devices is intended to check a connection to an SMTP server but…
- CVE-2018-155282 PoCsReflected Cross-Site Scripting exists in the Java System Solutions SSO plugin 4.0.13.1 for BMC MyIT. A remote attacker can abuse this…
- CVE-2018-155301 PoCCross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript…
- CVE-2018-155312 PoCsJavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
- CVE-2018-155332 PoCsA reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to…
- CVE-2018-155342 PoCsGeutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and…
- CVE-2018-155352 PoCs/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be…
- CVE-2018-155361 PoC/filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing…
- CVE-2018-155562 PoCsThe Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 allows login with root level access with the user "root" and an empty…
- CVE-2018-155571 PoCAn issue was discovered in the Quantenna WiFi Controller on Telus Actiontec WEB6000Q v1.1.02.22 devices. An attacker can statically set…
- CVE-2018-155601 PoCPyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt…
- CVE-2018-155621 PoCCMS ISWEB 3.5.3 has XSS via the ordineRis, sezioneRicerca, or oggettiRicerca parameter to index.php.
- CVE-2018-155651 PoCAn issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a…
- CVE-2018-155711 PoCThe Export Users to CSV plugin through 1.1.1 for WordPress allows CSV injection.
- CVE-2018-155762 PoCsAn issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code…
- CVE-2018-155871 PoCGNOME Evolution through 3.28.2 is prone to OpenPGP signatures being spoofed for arbitrary messages using a specially crafted email that…
- CVE-2018-155912 PoCsAn issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass…
- CVE-2018-155961 PoCAn issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as…
- CVE-2018-156071 PoCIn ImageMagick 7.0.8-11 Q16, a tiny input file 0x50 0x36 0x36 0x36 0x36 0x4c 0x36 0x38 0x36 0x36 0x36 0x36 0x36 0x36 0x1f 0x35 0x50 0x00…
- CVE-2018-156081 PoCZoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.
- CVE-2018-156401 PoCImproper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated…
- CVE-2018-156551 PoCAn issue was discovered in 42Gears SureMDM before 2018-11-27, related to CORS settings. Cross-origin access is possible.
- CVE-2018-156561 PoCAn issue was discovered in the registration API endpoint in 42Gears SureMDM before 2018-11-27. An attacker can submit a GET request to…
- CVE-2018-156573 PoCsAn SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.
- CVE-2018-156581 PoCAn issue was discovered in 42Gears SureMDM before 2018-11-27. By visiting the page found at /console/ConsolePage/Master.html, an attacker…
- CVE-2018-156591 PoCAn issue was discovered in 42Gears SureMDM before 2018-11-27, related to the access policy for Silverlight applications. Cross-origin…
- CVE-2018-156711 PoCAn issue was discovered in the HDF HDF5 1.10.2 library. Excessive stack consumption has been detected in the function H5P__get_cb() in…
- CVE-2018-156761 PoCAn issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_protection.php…
- CVE-2018-156771 PoCThe newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable…
- CVE-2018-156781 PoCAn issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable…
- CVE-2018-156791 PoCAn issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at…
- CVE-2018-156801 PoCAn issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes,…
- CVE-2018-156811 PoCAn issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored…
- CVE-2018-156821 PoCAn issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of…
- CVE-2018-156831 PoCAn issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of…
- CVE-2018-156841 PoCAn issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names,…
- CVE-2018-156854 PoCsGitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or…
- CVE-2018-156861 PoCsystemd: reexec state injection: fgets() on overlong lines leads to line splitting
- CVE-2018-156871 PoCsystemd: chown_one() can dereference symlinks
- CVE-2018-156911 PoCInsecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to…
- CVE-2018-157031 PoCAdvantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated…
- CVE-2018-157041 PoCAdvantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could…
- CVE-2018-157052 PoCsWADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the…
- CVE-2018-157061 PoCWADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to read any file on the filesystem due to a…
- CVE-2018-157072 PoCsAdvantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this…
- CVE-2018-157085 PoCsSnoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.
- CVE-2018-157091 PoCNagios XI 5.5.6 allows remote authenticated attackers to execute arbitrary commands via a crafted HTTP request.
- CVE-2018-157104 PoCsNagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.
- CVE-2018-157111 PoCNagios XI 5.5.6 allows remote authenticated attackers to reset and regenerate the API key of more privileged users. The attacker can then…
- CVE-2018-157121 PoCNagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the host parameter in api_tool.php.
- CVE-2018-157131 PoCNagios XI 5.5.6 allows persistent cross site scripting from remote authenticated attackers via the stored email address in admin/users.php.
- CVE-2018-157141 PoCNagios XI 5.5.6 allows reflected cross site scripting from remote unauthenticated attackers via the oname and oname2 parameters.
- CVE-2018-157151 PoCZoom clients on Windows (before version 4.1.34814.1119), Mac OS (before version 4.1.34801.1116), and Linux (2.4.129780.0915 and below) are…
- CVE-2018-157163 PoCsNUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to…
- CVE-2018-157201 PoCLogitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the…
- CVE-2018-157211 PoCThe XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote…
- CVE-2018-157231 PoCThe Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An…
- CVE-2018-157271 PoCGrafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid…
- CVE-2018-157281 PoCCouchbase Server exposed the '/diag/eval' endpoint which by default is available on TCP/8091 and/or TCP/18091. Authenticated users that…
- CVE-2018-157291 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to…
- CVE-2018-157301 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to…
- CVE-2018-157311 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to…
- CVE-2018-157322 PoCsAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not…
- CVE-2018-157331 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a NULL Pointer Dereference vulnerability…
- CVE-2018-157341 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not…
- CVE-2018-157351 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains an Arbitrary Write vulnerability due to not…
- CVE-2018-157361 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to…
- CVE-2018-157371 PoCAn issue was discovered in STOPzilla AntiMalware 6.5.2.59. The driver file szkg64.sys contains a Denial of Service vulnerability due to…
- CVE-2018-157401 PoCZoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.
- CVE-2018-157455 PoCsArgus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the…
- CVE-2018-157521 PoCAn issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive…
- CVE-2018-157531 PoCAn issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES…
- CVE-2018-157671 PoCImproper Authorization Vulnerability
- CVE-2018-157681 PoCInsecure MySQL Configuration Vulnerability
- CVE-2018-158114 PoCsKEVDNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.
- CVE-2018-158123 PoCsDNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.
- CVE-2018-158181 PoCAn issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges…
- CVE-2018-158192 PoCsEasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
- CVE-2018-158202 PoCsEasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
- CVE-2018-158321 PoCupc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is…
- CVE-2018-158351 PoCAndroid 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
- CVE-2018-158391 PoCD-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
- CVE-2018-158442 PoCsAn issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via…
- CVE-2018-158451 PoCThere is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.
- CVE-2018-158521 PoCTechnicolor TC7200.20 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses,…
- CVE-2018-158701 PoCAn invalid memory address dereference was discovered in decompileGETVARIABLE in libming 0.4.8 before 2018-03-12. The vulnerability causes…
- CVE-2018-158711 PoCAn invalid memory address dereference was discovered in decompileSingleArgBuiltInFunctionCall in libming 0.4.8 before 2018-03-12. The…
- CVE-2018-158777 PoCsThe Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the…
- CVE-2018-158842 PoCsRICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.
- CVE-2018-158901 PoCAn issue was discovered in EthereumJ 1.8.2. There is Unsafe Deserialization in ois.readObject in mine/Ethash.java and decoder.readObject…
- CVE-2018-158931 PoCA SQL injection was discovered in /coreframe/app/admin/copyfrom.php in WUZHI CMS 4.1.0 via the index.php?m=core&f=copyfrom&v=listing…
- CVE-2018-158941 PoCA SQL injection was discovered in /coreframe/app/admin/pay/admin/index.php in WUZHI CMS 4.1.0 via the index.php?m=pay&f=index&v=listing…
- CVE-2018-158961 PoCPHP Scripts Mall Website Seller Script 2.0.5 has XSS via Personal Address or Company Name.
- CVE-2018-158971 PoCPHP Scripts Mall Website Seller Script 2.0.5 allows remote attackers to cause a denial of service via crafted JavaScript code in the First…
- CVE-2018-158991 PoCAn issue was discovered in MiniCMS 1.10. There is a post.php?date= XSS vulnerability.
- CVE-2018-159031 PoCThe Discuss v1.2.1 module in Claromentis 8.2.2 is vulnerable to stored Cross Site Scripting (XSS). An authenticated attacker will be able…
- CVE-2018-159062 PoCsSolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and…
- CVE-2018-159071 PoCTechnicolor (formerly RCA) TC8305C devices allow remote attackers to cause a denial of service (networking outage) via a flood of random…
- CVE-2018-159122 PoCsAn issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can install or remove…
- CVE-2018-159172 PoCsPersistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2018-159181 PoCAn issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and…
- CVE-2018-1596111 PoCsKEVAdobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file…
- CVE-2018-159682 PoCsAdobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an…
- CVE-2018-1598210 PoCsKEVFlash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation…