CVE-2018-18000 to CVE-2018-18999
259 CVEs with public proof-of-concept exploits.
- CVE-2018-180041 PoCIncorrect Access Control in mod_inetd.cgi in VIVOTEK Network Camera Series products with firmware before XXXXXX-VVTK-0X09a allows remote…
- CVE-2018-180051 PoCCross-site scripting in event_script.js in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to…
- CVE-2018-180062 PoCsHardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed…
- CVE-2018-180131 PoC* Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this…
- CVE-2018-180141 PoC* Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making…
- CVE-2018-180201 PoCIn QPDF 8.2.1, in libqpdf/QPDFWriter.cc, QPDFWriter::unparseObject and QPDFWriter::unparseChild have recursive calls for a long time,…
- CVE-2018-180231 PoCIn ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the SVGStripString function of coders/svg.c, which allows attackers…
- CVE-2018-180241 PoCIn ImageMagick 7.0.8-13 Q16, there is an infinite loop in the ReadBMPImage function of the coders/bmp.c file. Remote attackers could…
- CVE-2018-180251 PoCIn ImageMagick 7.0.8-13 Q16, there is a heap-based buffer over-read in the EncodeImage function of coders/pict.c, which allows attackers…
- CVE-2018-180261 PoCIMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The…
- CVE-2018-180611 PoCAn issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. Attackers can access the file manager interface that…
- CVE-2018-180621 PoCAn issue was discovered in dialog.php in tecrail Responsive FileManager 9.8.1. A reflected XSS vulnerability allows remote attackers to…
- CVE-2018-180641 PoCcairo through 1.15.14 has an out-of-bounds stack-memory write during processing of a crafted document by WebKitGTK+ because of the…
- CVE-2018-180652 PoCs_set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated…
- CVE-2018-180661 PoCsnmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated…
- CVE-2018-180692 PoCsprocess_forms in the WPML (aka sitepress-multilingual-cms) plugin through 3.6.3 for WordPress has XSS via any locale_file_name_ parameter…
- CVE-2018-180751 PoCWikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort…
- CVE-2018-180871 PoCThe Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web…
- CVE-2018-180881 PoCOpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
- CVE-2018-181981 PoCThe $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to…
- CVE-2018-182071 PoCVirtualmin 6.03 allows Frame Injection via the settings-editor_read.cgi file parameter.
- CVE-2018-182081 PoCVirtualmin 6.03 allows XSS via the query string, as demonstrated by the webmin_search.cgi URI.
- CVE-2018-182091 PoCXSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_type parameter.
- CVE-2018-182101 PoCXSS exists in DiliCMS 2.4.0 via the admin/index.php/setting/site?tab=site_attachment attachment_url parameter.
- CVE-2018-182441 PoCCross-site scripting in syslog.html in VIVOTEK Network Camera Series products with firmware 0x06x to 0x08x allows remote attackers to…
- CVE-2018-182521 PoCAn issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe provides "NT AUTHORITY\SYSTEM" access to unprivileged…
- CVE-2018-182531 PoCAn issue was discovered in CapMon Access Manager 5.4.1.1005. CALRunElevated.exe attempts to enforce access control by adding an…
- CVE-2018-182541 PoCAn issue was discovered in CapMon Access Manager 5.4.1.1005. An unprivileged user can read the cal_whitelist table in the Custom App…
- CVE-2018-182551 PoCAn issue was discovered in CapMon Access Manager 5.4.1.1005. The client applications of AccessManagerCoreService.exe communicate with this…
- CVE-2018-182561 PoCAn issue was discovered in CapMon Access Manager 5.4.1.1005. A regular user can obtain local administrator privileges if they run any…
- CVE-2018-182591 PoCStored XSS has been discovered in version 1.0.12 of the LUYA CMS software via /admin/api-cms-nav/create-page.
- CVE-2018-182641 PoCKubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets…
- CVE-2018-182741 PoCA issue was found in pdfalto 0.2. There is a heap-based buffer overflow in the TextPage::addAttributsNode function in XmlAltoOutputDev.cc.
- CVE-2018-182761 PoCXSS exists in the ProFiles 1.5 component for Joomla! via the name or path parameter when creating a new folder in the administrative panel.
- CVE-2018-182821 PoCNext.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
- CVE-2018-182872 PoCsOn ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the…
- CVE-2018-183072 PoCsA Stored XSS vulnerability has been discovered in version 4.1.0 of AlchemyCMS via the /admin/pictures image field. NOTE: the vendor's…
- CVE-2018-183081 PoCIn the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload…
- CVE-2018-183091 PoCAn issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory…
- CVE-2018-183101 PoCAn invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The…
- CVE-2018-183121 PoCPerl before 5.26.3 and 5.28.0 before 5.28.1 has a buffer overflow via a crafted regular expression that triggers invalid write operations.
- CVE-2018-183131 PoCPerl before 5.26.3 has a buffer over-read via a crafted regular expression that triggers disclosure of sensitive information from process…
- CVE-2018-183181 PoCThe /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service…
- CVE-2018-183192 PoCsAn issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because…
- CVE-2018-183202 PoCsAn issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because…
- CVE-2018-183222 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php…
- CVE-2018-183233 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an…
- CVE-2018-183242 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the…
- CVE-2018-183254 PoCsKEVDNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an…
- CVE-2018-183264 PoCsDNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE:…
- CVE-2018-183332 PoCsA DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to…
- CVE-2018-183681 PoCSymantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a…
- CVE-2018-183752 PoCsgoform/getProfileList in Orange AirBox Y858_FL_01.16_04 allows attackers to extract APN data (name, number, username, and password) via…
- CVE-2018-183762 PoCsgoform/getWlanClientInfo in Orange AirBox Y858_FL_01.16_04 allows remote attackers to discover information about currently connected…
- CVE-2018-183771 PoCgoform/setReset on Orange AirBox Y858_FL_01.16_04 devices allows attackers to reset a router to factory settings, which can be used to…
- CVE-2018-183811 PoCZ-BlogPHP 1.5.2.1935 (Zero) has a stored XSS Vulnerability in zb_system/function/c_system_admin.php via the Content-Type header during the…
- CVE-2018-183821 PoCAdvanced HRM 1.6 allows Remote Code Execution via PHP code in a .php file to the user/update-user-avatar URI, which can be accessed…
- CVE-2018-183871 PoCplaySMS through 1.4.2 allows Privilege Escalation through Daemon abuse.
- CVE-2018-183981 PoCXfce Thunar 1.6.15, when Xfce 4.12 is used, mishandles the IBus-Unikey input method for file searches within File Manager, leading to an…
- CVE-2018-184061 PoCAn issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE…
- CVE-2018-184072 PoCsA heap-based buffer over-read was discovered in the tcpreplay-edit binary of Tcpreplay 4.3.0 beta1, during the incremental checksum…
- CVE-2018-184091 PoCA stack-based buffer over-read exists in setbit() at iptree.h of TCPFLOW 1.5.0, due to received incorrect values causing incorrect…
- CVE-2018-184162 PoCsLANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the…
- CVE-2018-184172 PoCsIn the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the…
- CVE-2018-184192 PoCsStored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the…
- CVE-2018-184201 PoCCross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the…
- CVE-2018-184283 PoCsTP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.
- CVE-2018-184352 PoCsKioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full…
- CVE-2018-184361 PoCJTBC(PHP) 3.0 allows CSRF for creating an account via the console/account/manage.php?type=action&action=add URI.
- CVE-2018-184372 PoCsIn AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.
- CVE-2018-184411 PoCD-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS…
- CVE-2018-184431 PoCOpenEXR 2.3.0 has a memory leak in ThreadPool in IlmBase/IlmThread/IlmThreadPool.cpp, as demonstrated by exrmultiview.
- CVE-2018-184441 PoCmakeMultiView.cpp in exrmultiview in OpenEXR 2.3.0 has an out-of-bounds write, leading to an assertion failure or possibly unspecified…
- CVE-2018-184491 PoCEmpireCMS 7.5 allows CSRF for adding a user account via an enews=AddUser action to e/admin/user/ListUser.php, a similar issue to…
- CVE-2018-184601 PoCXSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php…
- CVE-2018-184711 PoC/api/2.0/rest/aggregator/xml in Axentra firmware, used by NETGEAR Stora, Seagate GoFlex Home, and MEDION LifeCloud, has an XXE…
- CVE-2018-184781 PoCPersistent Cross-Site Scripting (XSS) issues in LibreNMS before 1.44 allow remote attackers to inject arbitrary web script or HTML via the…
- CVE-2018-184801 PoCA heap-based buffer over-read exists in libopencad 0.2.0 in the ReadMCHAR function in lib/dwg/io.cpp, resulting in an application crash.
- CVE-2018-184811 PoCA heap-based buffer over-read exists in libopencad 0.2.0 in the ReadCHAR function in lib/dwg/io.cpp, resulting in an application crash.
- CVE-2018-184832 PoCsThe get_count function in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31, allows remote attackers to cause a denial of…
- CVE-2018-184841 PoCAn issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. Stack Exhaustion occurs in the C++…
- CVE-2018-184851 PoCAn issue was discovered in PHPSHE 1.7. admin.php?mod=db&act=del allows remote attackers to delete arbitrary files via directory traversal…
- CVE-2018-184891 PoCThe ping feature in the Diagnostic functionality on TP-LINK WR840N v2 Firmware 3.16.9 Build 150701 Rel.51516n devices allows remote…
- CVE-2018-185001 PoCA use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream…
- CVE-2018-185201 PoCAn Invalid Memory Address Dereference exists in the function elf_end in libelf in elfutils through v0.174. Although eu-size is intended to…
- CVE-2018-185211 PoCDivide-by-zero vulnerabilities in the function arlib_add_symbols() in arlib.c in elfutils 0.174 allow remote attackers to cause a denial…
- CVE-2018-185271 PoCOwnTicket 2018-05-23 allows SQL Injection via the showTicketId or editTicketStatusId parameter.
- CVE-2018-185352 PoCsThe Asusgio low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes functionality to read and write Machine Specific Registers…
- CVE-2018-185362 PoCsThe GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports.…
- CVE-2018-185372 PoCsThe GLCKIo low-level driver in ASUS Aura Sync v1.07.22 and earlier exposes a path to write an arbitrary DWORD to an arbitrary address.
- CVE-2018-185471 PoCVesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period…
- CVE-2018-185481 PoCajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.
- CVE-2018-185512 PoCsServersCheck Monitoring Software through 14.3.3 has Persistent and Reflected XSS via the sensors.html status parameter, sensors.html type…
- CVE-2018-185522 PoCsServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an…
- CVE-2018-185551 PoCA sandbox escape issue was discovered in VyOS 1.1.8. It provides a restricted management shell for operator users to administer the…
- CVE-2018-185564 PoCsA privilege escalation issue was discovered in VyOS 1.1.8. The default configuration also allows operator users to execute the pppd binary…
- CVE-2018-185572 PoCsLibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4,…
- CVE-2018-185662 PoCsThe SIP service in Polycom VVX 500 and 601 devices 5.8.0.12848 and earlier allow remote attackers to obtain sensitive phone configuration…
- CVE-2018-185672 PoCsAudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by…
- CVE-2018-185682 PoCsPolycom VVX 500 and 601 devices 5.8.0.12848 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by…
- CVE-2018-185691 PoCThe Dundas BI server before 5.0.1.1010 is vulnerable to a Server-Side Request Forgery attack, allowing an attacker to forge arbitrary…
- CVE-2018-185701 PoCPlanon before Live Build 41 has XSS.
- CVE-2018-185991 PoCStegdetect through 2018-05-26 has an out-of-bounds write in f5_compress in the f5.c file.
- CVE-2018-186031 PoC360 Total Security 3.5.0.1033 allows a Sandbox Escape via an "import os" statement, followed by os.system("CMD") or…
- CVE-2018-186051 PoCA heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD)…
- CVE-2018-186061 PoCAn issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed…
- CVE-2018-186071 PoCAn issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU…
- CVE-2018-186081 PoCDedeCMS 5.7 SP2 allows XSS via the function named GetPageList defined in the include/datalistcp.class.php file that is used to display the…
- CVE-2018-186193 PoCsinternal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to…
- CVE-2018-186231 PoCGrafana 5.3.1 has XSS via the "Dashboard > Text Panel" screen. NOTE: this issue exists because of an incomplete fix for CVE-2018-12099.
- CVE-2018-186241 PoCGrafana 5.3.1 has XSS via a column style on the "Dashboard > Table Panel" screen. NOTE: this issue exists because of an incomplete fix for…
- CVE-2018-186251 PoCGrafana 5.3.1 has XSS via a link on the "Dashboard > All Panels > General" screen. NOTE: this issue exists because of an incomplete fix…
- CVE-2018-186292 PoCsAn issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability…
- CVE-2018-186351 PoCwww/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09…
- CVE-2018-186362 PoCsXSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.
- CVE-2018-186401 PoCAn issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has…
- CVE-2018-186441 PoCAn issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It…
- CVE-2018-186461 PoCAn issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It…
- CVE-2018-186491 PoCAn issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before…
- CVE-2018-186501 PoCAn issue was discovered in Xpdf 4.00. XRef::readXRefStream in XRef.cc allows attackers to launch a denial of service (Integer Overflow)…
- CVE-2018-186511 PoCAn issue was discovered in Xpdf 4.00. catalog->getNumPages() in AcroForm.cc allows attackers to launch a denial of service (hang caused by…
- CVE-2018-186611 PoCAn issue was discovered in LibTIFF 4.0.9. There is a NULL pointer dereference in the function LZWDecode in the file tif_lzw.c.
- CVE-2018-186622 PoCsThere is an out-of-bounds read in fz_run_t3_glyph in fitz/font.c in Artifex MuPDF 1.14.0, as demonstrated by mutool.
- CVE-2018-186951 PoCM2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.
- CVE-2018-186962 PoCsmain.aspx in Microstrategy Analytics 10.4.0026.0049 and earlier has CSRF. NOTE: The vendor claims that documentation for preventing a CSRF…
- CVE-2018-187001 PoCAn issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability…
- CVE-2018-187011 PoCAn issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability…
- CVE-2018-187031 PoCPhpTpoint Mailing Server Using File Handling 1.0 suffers from multiple Arbitrary File Read vulnerabilities in different sections that…
- CVE-2018-187041 PoCPhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
- CVE-2018-187051 PoCPhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with…
- CVE-2018-187061 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187071 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187081 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187091 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187111 PoCAn issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via…
- CVE-2018-187121 PoCAn issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via…
- CVE-2018-187141 PoCRegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL…
- CVE-2018-187201 PoCAn XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.
- CVE-2018-187211 PoCAn XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.
- CVE-2018-187221 PoCAn XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.
- CVE-2018-187231 PoCAn XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5.
- CVE-2018-187241 PoCAn XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.
- CVE-2018-187251 PoCAn XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.
- CVE-2018-187261 PoCAn XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.
- CVE-2018-187271 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187281 PoCAn issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow…
- CVE-2018-187291 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187301 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187311 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187321 PoCAn issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18…
- CVE-2018-187351 PoCA CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
- CVE-2018-187361 PoCAn XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
- CVE-2018-187371 PoCAn XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.
- CVE-2018-187421 PoCA CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.
- CVE-2018-187481 PoCSandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py…
- CVE-2018-187491 PoCdata-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function.
- CVE-2018-187511 PoCAn issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free…
- CVE-2018-187521 PoCWebiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php…
- CVE-2018-187531 PoCTypecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
- CVE-2018-187552 PoCsK-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id…
- CVE-2018-187561 PoCLocal Server 1.0.9 has a Buffer Overflow via crafted data on Port 4008.
- CVE-2018-187572 PoCsOpen Faculty Evaluation System 5.6 for PHP 5.6 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18758.
- CVE-2018-187582 PoCsOpen Faculty Evaluation System 7 for PHP 7 allows submit_feedback.php SQL Injection, a different vulnerability than CVE-2018-18757.
- CVE-2018-187592 PoCsModbus Slave 7.0.0 in modbus tools has a Buffer Overflow.
- CVE-2018-187602 PoCsRhinOS 3.0 build 1190 allows CSRF.
- CVE-2018-187611 PoCSaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.
- CVE-2018-187622 PoCsSaltOS 3.1 r8126 contains a database download vulnerability.
- CVE-2018-187632 PoCsSaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
- CVE-2018-187641 PoCAn exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a…
- CVE-2018-187651 PoCAn exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a…
- CVE-2018-187723 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by…
- CVE-2018-187733 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by…
- CVE-2018-187743 PoCsCentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.
- CVE-2018-187753 PoCsMicrostrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability…
- CVE-2018-187762 PoCsMicrostrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability…
- CVE-2018-187773 PoCsDirectory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote…
- CVE-2018-187785 PoCsACME mini_httpd before 1.30 lets remote users read arbitrary files.
- CVE-2018-187841 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in admin/tagmanage.php via the tabletag parameter. (This needs an admin user…
- CVE-2018-187851 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
- CVE-2018-187861 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
- CVE-2018-187871 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
- CVE-2018-187881 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in admin/classmanage.php via the tablename parameter. (This needs an admin user…
- CVE-2018-187891 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
- CVE-2018-187901 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in admin/special_add.php via a zxbigclassid cookie. (This needs an admin user…
- CVE-2018-187911 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
- CVE-2018-187921 PoCAn issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
- CVE-2018-187932 PoCsSchool Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
- CVE-2018-187942 PoCsSchool Event Management System 1.0 allows CSRF via user/controller.php?action=edit.
- CVE-2018-187952 PoCsSchool Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
- CVE-2018-187961 PoCLibrary Management System 1.0 has SQL Injection via the "Search for Books" screen.
- CVE-2018-187972 PoCsSchool Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.
- CVE-2018-187982 PoCsAttendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and…
- CVE-2018-187992 PoCsSchool Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.
- CVE-2018-188002 PoCsThe Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or…
- CVE-2018-188012 PoCsThe BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].
- CVE-2018-188022 PoCsThe Tubigan "Welcome to our Resort" 1.0 software allows CSRF via admin/mod_users/controller.php?action=edit.
- CVE-2018-188032 PoCsCurriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.
- CVE-2018-188042 PoCsBakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
- CVE-2018-188052 PoCsPoint Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.
- CVE-2018-188061 PoCSchool Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.
- CVE-2018-188092 PoCsKEVTIBCO JasperReports Library Directory Traversal Vulnerability
- CVE-2018-188201 PoCA buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any…
- CVE-2018-188221 PoCGrapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter.
- CVE-2018-188261 PoCThere exists a heap-based buffer overflow in vc1_decode_p_mb_intfi in vc1_block.c in Libav 12.3, which allows attackers to cause a…
- CVE-2018-188271 PoCThere exists a heap-based buffer over-read in ff_vc1_pred_dc in vc1_block.c in Libav 12.3, which allows attackers to cause a…
- CVE-2018-188281 PoCThere exists a heap-based buffer overflow in vc1_decode_i_block_adv in vc1_block.c in Libav 12.3, which allows attackers to cause a…
- CVE-2018-188291 PoCThere exists a NULL pointer dereference in ff_vc1_parse_frame_header_adv in vc1.c in Libav 12.3, which allows attackers to cause a…
- CVE-2018-188401 PoCXSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
- CVE-2018-188452 PoCsinternal/advanced_comment_system/index.php and internal/advanced_comment_system/admin.php in Advanced Comment System, version 1.0, contain…
- CVE-2018-188501 PoCIn Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could…
- CVE-2018-188522 PoCsCerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING…
- CVE-2018-188563 PoCsMultiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can…
- CVE-2018-188573 PoCsMultiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can…
- CVE-2018-188583 PoCsMultiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can…
- CVE-2018-188593 PoCsMultiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can…
- CVE-2018-188603 PoCsA local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-permissive…
- CVE-2018-188611 PoCBuffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
- CVE-2018-188621 PoCBMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by…
- CVE-2018-188642 PoCsLoadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
- CVE-2018-188654 PoCsThe Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow…
- CVE-2018-188711 PoCMissing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker…
- CVE-2018-188721 PoCThe Kieran O'Shea Calendar plugin before 1.3.11 for WordPress has Stored XSS via the event_title parameter in a…
- CVE-2018-188731 PoCAn issue was discovered in JasPer 2.0.14. There is a NULL pointer dereference in the function ras_putdatastd in ras/ras_enc.c.
- CVE-2018-188741 PoCnc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php…
- CVE-2018-188901 PoCMiniCMS 1.10 allows full path disclosure via /mc-admin/post.php?state=delete&delete= with an invalid filename.
- CVE-2018-188911 PoCMiniCMS 1.10 allows file deletion via /mc-admin/post.php?state=delete&delete= because the authentication check occurs too late.
- CVE-2018-188931 PoCJinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.
- CVE-2018-188971 PoCAn issue was discovered in Poppler 0.71.0. There is a memory leak in GfxColorSpace::setDisplayProfile in GfxState.cc, as demonstrated by…
- CVE-2018-189031 PoCVanilla 2.6.x before 2.6.4 allows remote code execution.
- CVE-2018-189091 PoCxhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view.
- CVE-2018-189122 PoCsAn issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious…
- CVE-2018-189151 PoCThere is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a…
- CVE-2018-189191 PoCThe WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.
- CVE-2018-189211 PoCPHP Server Monitor before 3.3.2 has CSRF, as demonstrated by a Delete action.
- CVE-2018-189222 PoCsadd_user in AbiSoft Ticketly 1.0 allows remote attackers to create administrator accounts via an action/add_user.php POST request.
- CVE-2018-189231 PoCAbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in…
- CVE-2018-189241 PoCThe image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd"…
- CVE-2018-189253 PoCsGogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file…
- CVE-2018-189341 PoCAn issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by…
- CVE-2018-189351 PoCAn issue was discovered in PopojiCMS v2.0.1. It has CSRF via the po-admin/route.php?mod=component&act=addnew URI, as demonstrated by…
- CVE-2018-189381 PoCAn issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/…
- CVE-2018-189391 PoCAn issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
- CVE-2018-189402 PoCsservlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in…
- CVE-2018-189412 PoCsIn Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin…
- CVE-2018-189421 PoCIn baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the…
- CVE-2018-189431 PoCAn issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used…
- CVE-2018-189442 PoCsArtha ~ The Open Thesaurus 1.0.3.0 has a Buffer Overflow.
- CVE-2018-189521 PoCJEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
- CVE-2018-1895510 PoCsIn the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it…
- CVE-2018-189572 PoCsAn issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.
- CVE-2018-189591 PoCAn issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. On the 'Air Print Setting' web…
- CVE-2018-189601 PoCAn issue was discovered on Epson WorkForce WF-2861 10.48 LQ22I3, 10.51.LQ20I6 and 10.52.LQ17IA devices. They use SNMP to find certain…
- CVE-2018-189751 PoCAn issue was discovered in the Ascensia Contour NEXT ONE app for iOS before 2019-01-15. An attacker may proxy communications between the…
- CVE-2018-189761 PoCAn issue was discovered in the Ascensia Contour NEXT ONE application for iOS and Android before 2019-01-15. An attacker may retrieve…
- CVE-2018-189771 PoCAn issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. An attacker may reverse engineer the…
- CVE-2018-189781 PoCAn issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded encryption…
- CVE-2018-189791 PoCAn issue was discovered in the Ascensia Contour NEXT ONE application for Android before 2019-01-15. It has a statically coded…
- CVE-2018-189801 PoCAn XML External Entity injection (XXE) vulnerability exists in Zoho ManageEngine Network Configuration Manager and OpManager before…
- CVE-2018-189822 PoCsNUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject…