CVE-2018-17000 to CVE-2018-17999
235 CVEs with public proof-of-concept exploits.
- CVE-2018-170001 PoCA NULL pointer dereference in the function _TIFFmemcmp at tif_unix.c (called from TIFFWriteDirectoryTagTransferfunction) in LibTIFF 4.0.9…
- CVE-2018-170011 PoCOn the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the…
- CVE-2018-170021 PoCOn the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the…
- CVE-2018-170041 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170051 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170061 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170071 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170081 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170091 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170101 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170111 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170121 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170131 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170141 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170151 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170161 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170171 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170181 PoCAn issue was discovered on TP-Link TL-WR886N 6.0 2.3.4 and TL-WR886N 7.0 1.1.0 devices. Authenticated attackers can crash router services…
- CVE-2018-170241 PoCadmin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action.
- CVE-2018-170251 PoCadmin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role.
- CVE-2018-170261 PoCadmin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different…
- CVE-2018-170301 PoCBigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via…
- CVE-2018-170311 PoCIn Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet…
- CVE-2018-170441 PoCIn YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
- CVE-2018-170451 PoCAn issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via…
- CVE-2018-170491 PoCCQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.
- CVE-2018-170531 PoCCross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers…
- CVE-2018-170541 PoCCross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers…
- CVE-2018-170551 PoCAn arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads.
- CVE-2018-170561 PoCCross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to…
- CVE-2018-170573 PoCsAn issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
- CVE-2018-170621 PoCAn issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled,…
- CVE-2018-170631 PoCAn issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the…
- CVE-2018-170641 PoCAn issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the…
- CVE-2018-170651 PoCAn issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password…
- CVE-2018-170661 PoCAn issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the…
- CVE-2018-170671 PoCAn issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based…
- CVE-2018-170681 PoCAn issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the…
- CVE-2018-170691 PoCAn issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.
- CVE-2018-170701 PoCAn issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via…
- CVE-2018-170751 PoCThe html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for…
- CVE-2018-170761 PoCGPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified…
- CVE-2018-170791 PoCAn issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.
- CVE-2018-170812 PoCse107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.
- CVE-2018-170822 PoCsThe Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a…
- CVE-2018-170851 PoCAn issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr.
- CVE-2018-170861 PoCAn issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName.
- CVE-2018-170881 PoCThe ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or…
- CVE-2018-170961 PoCThe BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of…
- CVE-2018-170971 PoCThe WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free)…
- CVE-2018-170981 PoCThe WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap…
- CVE-2018-171021 PoCAn issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via…
- CVE-2018-171031 PoCAn issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via…
- CVE-2018-171041 PoCAn issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via…
- CVE-2018-171101 PoCSimple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as…
- CVE-2018-171131 PoCApp/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName…
- CVE-2018-171261 PoCCScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php.
- CVE-2018-171271 PoCblocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL…
- CVE-2018-171281 PoCA Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.
- CVE-2018-171291 PoCMetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field.
- CVE-2018-171301 PoCPHPMyWind 5.5 has XSS in member.php via an HTTP Referer header,
- CVE-2018-171311 PoCadmin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field.
- CVE-2018-171321 PoCadmin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter.
- CVE-2018-171331 PoCadmin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting.
- CVE-2018-171341 PoCadmin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted…
- CVE-2018-171361 PoCzzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header.
- CVE-2018-171381 PoCThe Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz…
- CVE-2018-171391 PoCUltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP…
- CVE-2018-171401 PoCThe Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php.
- CVE-2018-171421 PoCThe html package (aka x/net/html) through 2018-09-17 in Go mishandles <math><template><mo><template>, leading to a "panic: runtime error"…
- CVE-2018-171442 PoCsBitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3…
- CVE-2018-171501 PoCIntersystems Cache 2017.2.2.865.0 allows XSS.
- CVE-2018-171511 PoCIntersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
- CVE-2018-171521 PoCIntersystems Cache 2017.2.2.865.0 allows XXE.
- CVE-2018-171533 PoCsIt was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An…
- CVE-2018-171733 PoCsLG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
- CVE-2018-171741 PoCA stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker…
- CVE-2018-171792 PoCsAn issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in…
- CVE-2018-171827 PoCsAn issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number…
- CVE-2018-172073 PoCsAn issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and…
- CVE-2018-172152 PoCsAn information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error…
- CVE-2018-172292 PoCsExiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted…
- CVE-2018-172301 PoCExiv2::ul2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted…
- CVE-2018-172331 PoCA SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during…
- CVE-2018-172341 PoCMemory leak in the H5O__chunk_deserialize() function in H5Ocache.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a…
- CVE-2018-172361 PoCThe function MP4Free() in mp4property.cpp in libmp4v2 2.1.0 internally calls free() on a invalid pointer, raising a SIGABRT signal.
- CVE-2018-172371 PoCA SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted…
- CVE-2018-172404 PoCsThere is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate…
- CVE-2018-172465 PoCsKibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the…
- CVE-2018-172546 PoCsThe JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.
- CVE-2018-172821 PoCAn issue was discovered in Exiv2 v0.26. The function Exiv2::DataValue::copy in value.cpp has a NULL pointer dereference.
- CVE-2018-172832 PoCsZoho ManageEngine OpManager before 12.3 Build 123196 does not require authentication for /oputilsServlet requests, as demonstrated by a…
- CVE-2018-172931 PoCAn issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten…
- CVE-2018-172971 PoCThe unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal…
- CVE-2018-173001 PoCStored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.
- CVE-2018-173011 PoCReflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
- CVE-2018-173021 PoCStored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
- CVE-2018-173091 PoCOn the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the…
- CVE-2018-173102 PoCsOn the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via…
- CVE-2018-173111 PoCOn the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via…
- CVE-2018-173121 PoCOn the RICOH Aficio MP 301 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via…
- CVE-2018-173132 PoCsOn the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the…
- CVE-2018-173141 PoCOn the RICOH Aficio MP 305+ printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses…
- CVE-2018-173151 PoCOn the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the…
- CVE-2018-173161 PoCOn the RICOH MP C6003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the…
- CVE-2018-173171 PoCFruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the…
- CVE-2018-173211 PoCAn issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
- CVE-2018-173221 PoCCross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary…
- CVE-2018-173321 PoCAn issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its input pointer in…
- CVE-2018-173331 PoCAn issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in svgStringToLength in svg_types.c allows remote…
- CVE-2018-173341 PoCAn issue was discovered in libsvg2 through 2012-10-19. A stack-based buffer overflow in the svgGetNextPathField function in svg_string.c…
- CVE-2018-173581 PoCAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory…
- CVE-2018-173591 PoCAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory…
- CVE-2018-173601 PoCAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. a heap-based buffer…
- CVE-2018-173652 PoCsSeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
- CVE-2018-173742 PoCsSQL Injection exists in the Auction Factory 4.5.5 component for Joomla! via the filter_order_Dir or filter_order parameter.
- CVE-2018-173752 PoCsSQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.
- CVE-2018-173762 PoCsSQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.
- CVE-2018-173772 PoCsSQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.
- CVE-2018-173782 PoCsSQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.
- CVE-2018-173792 PoCsSQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
- CVE-2018-173802 PoCsSQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.
- CVE-2018-173812 PoCsSQL Injection exists in the Dutch Auction Factory 2.0.2 component for Joomla! via the filter_order_Dir or filter_order parameter.
- CVE-2018-173822 PoCsSQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.
- CVE-2018-173832 PoCsSQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.
- CVE-2018-173842 PoCsSQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.
- CVE-2018-173852 PoCsSQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.
- CVE-2018-173862 PoCsSQL Injection exists in the Micro Deal Factory 2.4.0 component for Joomla! via the id parameter, or the PATH_INFO to mydeals/ or listdeals/.
- CVE-2018-173872 PoCsCSRF exists in Nimble Messaging Bulk SMS Marketing Application 1.0 for adding an admin account.
- CVE-2018-173882 PoCsSQL Injection exists in Twilio WEB To Fax Machine System 1.0 via the email or password parameter to login_check.php, or the id parameter…
- CVE-2018-173892 PoCsCSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
- CVE-2018-173912 PoCsSQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.
- CVE-2018-173932 PoCsSQL Injection exists in HealthNode Hospital Management System 1.0 via the id parameter to dashboard/Patient/info.php or…
- CVE-2018-173942 PoCsSQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.
- CVE-2018-173972 PoCsSQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.
- CVE-2018-173982 PoCsSQL Injection exists in the AMGallery 1.2.3 component for Joomla! via the filter_category_id parameter.
- CVE-2018-173992 PoCsSQL Injection exists in the Jimtawl 2.2.7 component for Joomla! via the id parameter.
- CVE-2018-174083 PoCsStack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via…
- CVE-2018-174121 PoCzzcms v8.3 contains a SQL Injection vulnerability in /user/logincheck.php via an X-Forwarded-For HTTP header.
- CVE-2018-174141 PoCzzcms v8.3 has a SQL injection in /user/jobmanage.php via the bigclass parameter.
- CVE-2018-174151 PoCzzcms V8.3 has a SQL injection in /user/zs_elite.php via the id parameter.
- CVE-2018-174161 PoCA SQL injection vulnerability exists in zzcms v8.3 via the /admin/adclass.php bigclassid parameter.
- CVE-2018-174191 PoCAn issue was discovered in setTA in scan_rr.go in the Miek Gieben DNS library before 1.0.10 for Go. A dns.ParseZone() parsing error causes…
- CVE-2018-174201 PoCAn issue was discovered in ZrLog 2.0.3. There is a SQL injection vulnerability in the article management search box via the keywords…
- CVE-2018-174211 PoCAn issue was discovered in ZrLog 2.0.3. There is stored XSS in the file upload area via a crafted attached/file/ pathname.
- CVE-2018-174222 PoCsdotCMS before 5.0.2 has open redirects via the html/common/forward_js.jsp FORWARD_URL parameter or the…
- CVE-2018-174231 PoCAn issue was discovered in e107 v2.1.9. There is a XSS attack on e107_admin/comment.php.
- CVE-2018-174251 PoCWUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI.
- CVE-2018-174261 PoCWUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI.
- CVE-2018-174281 PoCAn issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.
- CVE-2018-174315 PoCsWeb Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.
- CVE-2018-174321 PoCA NULL pointer dereference in H5O_sdspace_encode() in H5Osdspace.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a…
- CVE-2018-174331 PoCA heap-based buffer overflow in ReadGifImageDesc() in gifread.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial…
- CVE-2018-174341 PoCA SIGFPE signal is raised in the function apply_filters() of h5repack_filters.c in the HDF HDF5 through 1.10.3 library during an attempted…
- CVE-2018-174351 PoCA heap-based buffer over-read in H5O_attr_decode() in H5Oattr.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial…
- CVE-2018-174361 PoCReadCode() in decompress.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a denial of service (invalid write access) via…
- CVE-2018-174371 PoCMemory leak in the H5O_dtype_decode_helper() function in H5Odtype.c in the HDF HDF5 through 1.10.3 library allows attackers to cause a…
- CVE-2018-174381 PoCA SIGFPE signal is raised in the function H5D__select_io() of H5Dselect.c in the HDF HDF5 through 1.10.3 library during an attempted parse…
- CVE-2018-174391 PoCAn issue was discovered in the HDF HDF5 1.10.3 library. There is a stack-based buffer overflow in the function H5S_extent_get_dims() in…
- CVE-2018-174402 PoCsAn issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port…
- CVE-2018-174412 PoCsAn issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is…
- CVE-2018-174422 PoCsAn issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the…
- CVE-2018-174432 PoCsAn issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is…
- CVE-2018-1745610 PoCsGit before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows…
- CVE-2018-174636 PoCsKEVIncorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a…
- CVE-2018-175323 PoCsTeltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in…
- CVE-2018-175333 PoCsTeltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to…
- CVE-2018-175343 PoCsTeltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This…
- CVE-2018-175524 PoCsSQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.
- CVE-2018-175533 PoCsAn "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8…
- CVE-2018-175581 PoCHardcoded manufacturer credentials and an OS command injection vulnerability in the /cgi-bin/mft/ directory on ABUS TVIP TVIP20050…
- CVE-2018-175591 PoCDue to incorrect access control, unauthenticated remote attackers can view the /video.mjpg video stream of certain ABUS TVIP cameras.
- CVE-2018-175621 PoCMulti-Tech FaxFinder before 5.1.6 has SQL Injection via a status/call_details?oid= URI, allowing an attacker to extract the underlying…
- CVE-2018-175721 PoCInfluxDB 0.9.5 has Reflected XSS in the Write Data module.
- CVE-2018-175732 PoCsThe Wp-Insert plugin through 2.4.2 for WordPress allows upload of arbitrary PHP code because of the exposure and configuration of…
- CVE-2018-175802 PoCsA heap-based buffer over-read exists in the function fast_edit_packet() in the file send_packets.c of Tcpreplay v4.3.0 beta1. This can…
- CVE-2018-175812 PoCsCiffDirectory::readDirectory() at crwimage_int.cpp in Exiv2 0.26 has excessive stack consumption due to a recursive function, leading to…
- CVE-2018-175822 PoCsTcpreplay v4.3.0 beta1 contains a heap-based buffer over-read. The get_next_packet() function in the send_packets.c file uses the memcpy()…
- CVE-2018-175872 PoCsAirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- CVE-2018-175882 PoCsAirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- CVE-2018-175891 PoCAirTies Air 5650 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- CVE-2018-175901 PoCAirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- CVE-2018-175911 PoCAirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- CVE-2018-175931 PoCAirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
- CVE-2018-177652 PoCsIngenico Telium 2 POS terminals have undeclared TRACE protocol commands. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-177662 PoCsIngenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03…
- CVE-2018-177672 PoCsIngenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-177682 PoCsIngenico Telium 2 POS terminals have an insecure TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-177692 PoCsIngenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03…
- CVE-2018-177702 PoCsIngenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixed in Telium 2 SDK…
- CVE-2018-177712 PoCsIngenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-177722 PoCsIngenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-177732 PoCsIngenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch…
- CVE-2018-177742 PoCsIngenico Telium 2 POS terminals have an insecure NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
- CVE-2018-177752 PoCsSeqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain…
- CVE-2018-177762 PoCsPCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges…
- CVE-2018-177841 PoCMultiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote…
- CVE-2018-177861 PoCOn D-Link DIR-823G devices, ExportSettings.sh, upload_settings.cgi, GetDownLoadSyslog.sh, and upload_firmware.cgi do not require…
- CVE-2018-177871 PoCOn D-Link DIR-823G devices, the GoAhead configuration allows /HNAP1 Command Injection via shell metacharacters in the POST data, because…
- CVE-2018-177951 PoCThe function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based…
- CVE-2018-177971 PoCAn issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences…
- CVE-2018-177981 PoCAn issue was discovered in zzcms 8.3. user/ztconfig.php allows remote attackers to delete arbitrary files via an absolute pathname in the…
- CVE-2018-178301 PoCThe $args variable in addons/mediapool/pages/index.php in REDAXO 5.6.2 is not effectively filtered, because names are not restricted (only…
- CVE-2018-178311 PoCIn REDAXO before 5.6.3, a critical SQL injection vulnerability has been discovered in the rex_list class because of the prepareQuery…
- CVE-2018-178322 PoCsXSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.
- CVE-2018-178402 PoCsSQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
- CVE-2018-178412 PoCsSQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
- CVE-2018-178422 PoCsSQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
- CVE-2018-178432 PoCsSQL injection exists in ADD Clicking MLM Software 1.0, Binary MLM Software 1.0, Level MLM Software 1.0, Singleleg MLM Software 1.0,…
- CVE-2018-178491 PoCNavigate CMS 2.8 has Stored XSS via a navigate_upload.php (aka File Upload) request with a multipart/form-data JavaScript payload.
- CVE-2018-178521 PoCA SQL injection was discovered in WUZHI CMS 4.1.0 in coreframe/app/coupon/admin/card.php via the groupname parameter to the…
- CVE-2018-178661 PoCMultiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile &…
- CVE-2018-178713 PoCsVerba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Incorrect Access Control.
- CVE-2018-178722 PoCsVerba Collaboration Compliance and Quality Management Platform before 9.2.1.5545 has Insecure Permissions.
- CVE-2018-178732 PoCsAn incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows…
- CVE-2018-178761 PoCA Stored XSS vulnerability has been discovered in the v5.5.0 version of the Coaster CMS product.
- CVE-2018-178781 PoCBuffer Overflow vulnerability in certain ABUS TVIP cameras allows attackers to gain control of the program via crafted string sent to…
- CVE-2018-178791 PoCAn issue was discovered on certain ABUS TVIP cameras. The CGI scripts allow remote attackers to execute code via system() as root. There…
- CVE-2018-178801 PoCOn D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 RunReboot commands without authentication to trigger a…
- CVE-2018-178811 PoCOn D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to…
- CVE-2018-178881 PoCNUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the…
- CVE-2018-179141 PoCInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This…
- CVE-2018-179161 PoCInduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A…
- CVE-2018-179341 PoCNUUO CMS All versions 3.3 and prior the application allows external input to construct a pathname that is able to be resolved outside the…
- CVE-2018-179361 PoCNUUO CMS All versions 3.3 and prior the application allows the upload of arbitrary files that can modify or overwrite configuration files…
- CVE-2018-179471 PoCThe Snazzy Maps plugin before 1.1.5 for WordPress has XSS via the text or tab parameter.
- CVE-2018-179612 PoCsArtifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup.…
- CVE-2018-179742 PoCsAn issue was discovered in Tcpreplay 4.3.0 beta1. A heap-based buffer over-read was triggered in the function dlt_en10mb_encode() of the…
- CVE-2018-179751 PoCAn issue was discovered in GitLab Community Edition 11.x before 11.1.8, 11.2.x before 11.2.5, and 11.3.x before 11.3.2. There is…
- CVE-2018-179803 PoCsNoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same…
- CVE-2018-179811 PoCLifesize Express ls ex2_4.7.10 2000 (14) devices allow XSS via the interface/interface.php brand parameter.
- CVE-2018-179841 PoCAn unanchored /[a-z]{2}/ regular expression in ISPConfig before 3.1.13 makes it possible to include arbitrary files, leading to code…
- CVE-2018-179882 PoCsLayerBB 1.1.1 and 1.1.3 has SQL Injection via the search.php search_query parameter.
- CVE-2018-179962 PoCsLayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and…
- CVE-2018-179972 PoCsLayerBB 1.1.1 allows XSS via the titles of conversations (PMs).