CVE-2018-21000 to CVE-2018-21999
10 CVEs with public proof-of-concept exploits.
- CVE-2018-210131 PoCThe Swape theme before 1.2.1 for WordPress has incorrect access control, as demonstrated by allowing new administrator accounts via…
- CVE-2018-210141 PoCThe buddyboss-media plugin through 3.2.3 for WordPress has stored XSS.
- CVE-2018-210151 PoCAVC_DuplicateConfig() at isomedia/avc_ext.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (NULL pointer dereference…
- CVE-2018-210161 PoCaudio_sample_entry_AddBox() at isomedia/box_code_base.c in GPAC 0.7.1 allows remote attackers to cause a denial of service (heap-based…
- CVE-2018-210171 PoCGPAC 0.7.1 has a memory leak in dinf_Read in isomedia/box_code_base.c.
- CVE-2018-210312 PoCsTautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token…
- CVE-2018-210341 PoCIn Argo versions prior to v1.5.0-rc1, it was possible for authenticated Argo users to submit API calls to retrieve secrets and other…
- CVE-2018-210361 PoCSails.js before v1.0.0-46 allows attackers to cause a denial of service with a single request because there is no error handler in…
- CVE-2018-210371 PoCSubrion CMS 4.1.5 (and possibly earlier versions) allow CSRF to change the administrator password via the panel/members/edit/1 URI.
- CVE-2018-212681 PoCThe traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs…