CVE-2018-5000 to CVE-2018-5999
223 CVEs with public proof-of-concept exploits.
- CVE-2018-50071 PoCAdobe Flash Player 30.0.0.113 and earlier versions have a Type Confusion vulnerability. Successful exploitation could lead to arbitrary…
- CVE-2018-50081 PoCAdobe Flash Player 30.0.0.113 and earlier versions have an Out-of-bounds read vulnerability. Successful exploitation could lead to…
- CVE-2018-50721 PoCOnline Ticket Booking has XSS via the admin/sitesettings.php keyword parameter.
- CVE-2018-50731 PoCOnline Ticket Booking has CSRF via admin/movieedit.php.
- CVE-2018-50741 PoCOnline Ticket Booking has XSS via the admin/manageownerlist.php contact parameter.
- CVE-2018-50751 PoCOnline Ticket Booking has XSS via the admin/snacks_edit.php snacks_name parameter.
- CVE-2018-50761 PoCOnline Ticket Booking has XSS via the admin/newsedit.php newstitle parameter.
- CVE-2018-50771 PoCOnline Ticket Booking has XSS via the admin/movieedit.php moviename parameter.
- CVE-2018-50781 PoCOnline Ticket Booking has XSS via the admin/eventlist.php cast parameter.
- CVE-2018-50791 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50801 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50811 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50821 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50831 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50841 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50851 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50861 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50871 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-50881 PoCIn K7 AntiVirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-51231 PoCA third party website can access information available to a user with access to a restricted bug entry using the image generation in…
- CVE-2018-51293 PoCsA lack of parameter validation on IPC messages results in a potential out-of-bounds write through malformed IPC messages. This can…
- CVE-2018-51461 PoCAn out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects…
- CVE-2018-51581 PoCThe PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a…
- CVE-2018-51591 PoCAn integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in…
- CVE-2018-51811 PoCIf a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open…
- CVE-2018-51892 PoCsRace condition in Jungo Windriver 12.5.1 allows local users to cause a denial of service (buffer overflow) or gain system privileges by…
- CVE-2018-52111 PoCPHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
- CVE-2018-52171 PoCIn K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52181 PoCIn K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52191 PoCIn K7 Antivirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52201 PoCIn K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52212 PoCsMultiple buffer overflows in BarCodeWiz BarCode before 6.7 ActiveX control (BarcodeWiz.DLL) allow remote attackers to execute arbitrary…
- CVE-2018-52301 PoCThe issue collector in Atlassian Jira before version 7.6.6, from version 7.7.0 before version 7.7.4, from version 7.8.0 before version…
- CVE-2018-52332 PoCsCross-site scripting (XSS) vulnerability in system/src/Grav/Common/Twig/Twig.php in Grav CMS before 1.3.0 allows remote attackers to…
- CVE-2018-52342 PoCsThe Norton Core router prior to v237 may be susceptible to a command injection exploit. This is a type of attack in which the goal is…
- CVE-2018-52461 PoCIn ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadPATTERNImage in coders/pattern.c.
- CVE-2018-52471 PoCIn ImageMagick 7.0.7-17 Q16, there are memory leaks in ReadRLAImage in coders/rla.c.
- CVE-2018-52481 PoCIn ImageMagick 7.0.7-17 Q16, there is a heap-based buffer over-read in coders/sixel.c in the ReadSIXELImage function, related to the…
- CVE-2018-52511 PoCIn libming 0.4.8, there is an integer signedness error vulnerability (left shift of a negative value) in the readSBits function…
- CVE-2018-52521 PoClibimageworsener.a in ImageWorsener 1.3.2, when libjpeg 8d is used, has a large loop in the get_raw_sample_int function in imagew-main.c.
- CVE-2018-52531 PoCThe AP4_FtypAtom class in Core/Ap4FtypAtom.cpp in Bento4 1.5.1.0 has an Infinite loop via a crafted MP4 file that triggers size mishandling.
- CVE-2018-52612 PoCsAn issue was discovered in Flexense DiskBoss 8.8.16 and earlier. Due to the usage of plaintext information from the handshake as input for…
- CVE-2018-52624 PoCsA stack-based buffer overflow in Flexense DiskBoss 8.8.16 and earlier allows unauthenticated remote attackers to execute arbitrary code in…
- CVE-2018-52631 PoCThe StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.
- CVE-2018-52701 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52711 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52721 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52731 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52741 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52751 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52761 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52771 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52781 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52791 PoCIn Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-52801 PoCSonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.
- CVE-2018-52811 PoCSonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion…
- CVE-2018-52822 PoCsKentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a…
- CVE-2018-52831 PoCThe Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.
- CVE-2018-52841 PoCThe ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.
- CVE-2018-52851 PoCThe ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.
- CVE-2018-52861 PoCThe GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.
- CVE-2018-52871 PoCThe GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the…
- CVE-2018-52881 PoCThe GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.
- CVE-2018-52891 PoCThe GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the…
- CVE-2018-52901 PoCThe GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the…
- CVE-2018-52911 PoCThe GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the…
- CVE-2018-52921 PoCThe GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.
- CVE-2018-52931 PoCThe GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.
- CVE-2018-52951 PoCIn PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp).…
- CVE-2018-52961 PoCIn PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote…
- CVE-2018-53081 PoCPoDoFo 0.9.5 does not properly validate memcpy arguments in the PdfMemoryOutputStream::Write function (base/PdfOutputStream.cpp). Remote…
- CVE-2018-53091 PoCIn PoDoFo 0.9.5, there is an integer overflow in the PdfObjectStreamParserObject::ReadObjectsFromStream function…
- CVE-2018-53151 PoCThe Wachipi WP Events Calendar plugin 1.0 for WordPress has SQL Injection via the event_id parameter to event.php.
- CVE-2018-53161 PoCThe "SagePay Server Gateway for WooCommerce" plugin before 1.0.9 for WordPress has XSS via the includes/pages/redirect.php page parameter.
- CVE-2018-53191 PoCRAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.
- CVE-2018-53301 PoCZyXEL P-660HW v3 devices allow remote attackers to cause a denial of service (router unreachable/unresponsive) via a flood of fragmented…
- CVE-2018-53333 PoCsIn the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an…
- CVE-2018-53471 PoCSeagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in…
- CVE-2018-53531 PoCThe custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and…
- CVE-2018-53541 PoCThe custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate…
- CVE-2018-53571 PoCImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.
- CVE-2018-53592 PoCsThe server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access…
- CVE-2018-53601 PoCLibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function…
- CVE-2018-53611 PoCThe WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.
- CVE-2018-53621 PoCThe WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.
- CVE-2018-53631 PoCThe WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr]…
- CVE-2018-53641 PoCThe WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to…
- CVE-2018-53651 PoCThe WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to…
- CVE-2018-53661 PoCThe WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.
- CVE-2018-53671 PoCThe WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.
- CVE-2018-53681 PoCThe SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.
- CVE-2018-53691 PoCThe SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php with a…
- CVE-2018-53701 PoCBizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.
- CVE-2018-53841 PoCNavarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection
- CVE-2018-53851 PoCNavarino Infinity web interface up to version 2.2 is prone to session fixation attacks
- CVE-2018-53861 PoCSome Navarino Infinity functions placed in the URL can bypass any authentication mechanism leading to an information leak
- CVE-2018-53871 PoCWizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be…
- CVE-2018-53891 PoCCVE-2018-5389
- CVE-2018-54031 PoCImperva SecureSphere gateway (GW) running v13, for both pre-First Time Login or post-First Time Login (FTL), if the attacker knows the…
- CVE-2018-54041 PoCThe Quest Kace K1000 Appliance is vulnerable to multiple Blind SQL Injections.
- CVE-2018-54052 PoCsThe Quest Kace K1000 Appliance is vulnerable to JavaScript injection.
- CVE-2018-54062 PoCsThe Quest Kace K1000 Appliance misconfigures the Cross-Origin Resource Sharing (CORS) mechanism.
- CVE-2018-54072 PoCsSimultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a…
- CVE-2018-54101 PoCDokan file system driver contains a stack-based buffer overflow
- CVE-2018-54121 PoCImperva SecureSphere running v12.0.0.50 is vulnerable to local arbitrary code execution, escaping sealed-mode.
- CVE-2018-54131 PoCImperva SecureSphere running v13.0, v12.0, or v11.5 allows low privileged users to add SSH login keys to the admin user, resulting in…
- CVE-2018-54301 PoCKEVTIBCO JasperReports Server Information Disclosure Vulnerability
- CVE-2018-54791 PoCFoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the…
- CVE-2018-55111 PoCOn F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface…
- CVE-2018-55461 PoCThe svpn and policyserver components of the F5 BIG-IP APM client prior to version 7.1.7.1 for Linux and macOS runs as a privileged process…
- CVE-2018-56501 PoCIn Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the unzip_match function in runzip.c. Remote…
- CVE-2018-56531 PoCAn issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php…
- CVE-2018-56541 PoCAn issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php…
- CVE-2018-56551 PoCAn issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. XSS exists via the wp-admin/admin-ajax.php security…
- CVE-2018-56561 PoCAn issue was discovered in the weblizar-pinterest-feeds plugin 1.1.1 for WordPress. CSRF exists via wp-admin/admin-ajax.php.
- CVE-2018-56571 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56581 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. CSRF exists via wp-admin/admin.php.
- CVE-2018-56591 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56601 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56611 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_width…
- CVE-2018-56621 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56631 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56641 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56651 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php logo_height…
- CVE-2018-56661 PoCAn issue was discovered in the responsive-coming-soon-page plugin 1.1.18 for WordPress. XSS exists via the wp-admin/admin.php bg_color…
- CVE-2018-56671 PoCAn issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general.php…
- CVE-2018-56681 PoCAn issue was discovered in the read-and-understood plugin 2.1 for WordPress. XSS exists via the wp-admin/options-general.php…
- CVE-2018-56691 PoCAn issue was discovered in the read-and-understood plugin 2.1 for WordPress. CSRF exists via wp-admin/options-general.php.
- CVE-2018-56701 PoCAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php sale_conditions[count][]…
- CVE-2018-56711 PoCAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php…
- CVE-2018-56721 PoCAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. XSS exists via the wp-admin/admin.php form_field5[label]…
- CVE-2018-56731 PoCAn issue was discovered in the booking-calendar plugin 2.1.7 for WordPress. CSRF exists via wp-admin/admin.php.
- CVE-2018-56841 PoCIn Libav through 12.2, there is an invalid memcpy call in the ff_mov_read_stsd_entries function of libavformat/mov.c. Remote attackers…
- CVE-2018-56851 PoCIn GraphicsMagick 1.3.27, there is an infinite loop and application hang in the ReadBMPImage function (coders/bmp.c). Remote attackers…
- CVE-2018-56861 PoCIn MuPDF 1.12.0, there is an infinite loop vulnerability and application hang in the pdf_parse_array function (pdf/pdf-parse.c) because…
- CVE-2018-56881 PoCILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.
- CVE-2018-56911 PoCSonicWall Global Management System (GMS) 8.1 has XSS via the `newName` and `Name` values of the `/sgms/TreeControl` module.
- CVE-2018-56921 PoCPiwigo v2.8.2 has XSS via the `tab`, `to`, `section`, `mode`, `installstatus`, and `display` parameters of the `admin.php` file.
- CVE-2018-56931 PoCThe LinuxMagic MagicSpam extension before 2.0.14-1 for Plesk allows local users to discover mailbox names by reading…
- CVE-2018-56941 PoCThe callforward module in User Control Panel (UCP) in Nicolas Gudino (aka Asternic) Flash Operator Panel (FOP) 2.31.03 allows remote…
- CVE-2018-56951 PoCThe WpJobBoard plugin 4.4.4 for WordPress allows SQL injection via the order or sort parameter to the wpjb-job or wpjb-alerts module, with…
- CVE-2018-56961 PoCThe iJoomla com_adagency plugin 6.0.9 for Joomla! allows SQL injection via the `advertiser_status` and `status_select` parameters to…
- CVE-2018-56971 PoCIcy Phoenix 2.2.0.105 allows SQL injection via an unapprove request to admin_kb_art.php or the order parameter to admin_jr_admin.php,…
- CVE-2018-56981 PoClibreadstat.a in WizardMac ReadStat 0.1.1 has a heap-based buffer over-read via an unterminated string.
- CVE-2018-57013 PoCsIn Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not…
- CVE-2018-57022 PoCsTransmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows…
- CVE-2018-57031 PoCThe tcp_v6_syn_recv_sock function in net/ipv6/tcp_ipv6.c in the Linux kernel through 4.14.11 allows attackers to cause a denial of service…
- CVE-2018-57041 PoCOpen On-Chip Debugger (OpenOCD) 0.10.0 does not block attempts to use HTTP POST for sending data to 127.0.0.1 port 4444, which allows…
- CVE-2018-57052 PoCsReservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI).…
- CVE-2018-57081 PoCAn issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the…
- CVE-2018-57113 PoCsgd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x…
- CVE-2018-57131 PoCIn Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-57141 PoCIn Malwarefox Anti-Malware 2.72.169, the driver file (zam64.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-57152 PoCsphprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).
- CVE-2018-57201 PoCAn issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request…
- CVE-2018-57231 PoCMASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.
- CVE-2018-57241 PoCMASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.
- CVE-2018-57251 PoCMASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.
- CVE-2018-57261 PoCMASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by…
- CVE-2018-57271 PoCIn OpenJPEG 2.3.0, there is an integer overflow vulnerability in the opj_t1_encode_cblks function (openjp2/t1.c). Remote attackers could…
- CVE-2018-57311 PoCAn issue was discovered in Heimdal PRO 2.2.190. As part of the scanning feature, a process called md.hs writes an executable called…
- CVE-2018-57361 PoCAn error in zone database reference counting can lead to an assertion failure if a server which is running an affected version of BIND…
- CVE-2018-57401 PoCA flaw in the "deny-answer-aliases" feature can cause an assertion failure in named
- CVE-2018-57471 PoCIn Long Range Zip (aka lrzip) 0.631, there is a use-after-free in the ucompthread function (stream.c). Remote attackers could leverage…
- CVE-2018-57513 PoCsThe backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4…
- CVE-2018-57523 PoCsThe backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4…
- CVE-2018-57533 PoCsThe frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4…
- CVE-2018-57543 PoCsCross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before…
- CVE-2018-57553 PoCsAbsolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before…
- CVE-2018-57563 PoCsThe backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4…
- CVE-2018-57571 PoCAn issue was discovered on AudioCodes 450HD IP Phone devices with firmware 3.0.0.535.106. The traceroute and ping functionality, which…
- CVE-2018-57591 PoCjsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to…
- CVE-2018-57661 PoCIn Libav through 12.2, there is an invalid memcpy in the av_packet_ref function of libavcodec/avpacket.c. Remote attackers could leverage…
- CVE-2018-57674 PoCsAn issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the…
- CVE-2018-57721 PoCIn Exiv2 0.26, there is a segmentation fault caused by uncontrolled recursion in the Exiv2::Image::printIFDStructure function in the…
- CVE-2018-57761 PoCWordPress before 4.9.2 has XSS in the Flash fallback files in MediaElement (under wp-includes/js/mediaelement).
- CVE-2018-57821 PoCA vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28…
- CVE-2018-57831 PoCIn PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PoDoFo::PdfVecObjects::Reserve function (base/PdfVecObjects.h). Remote…
- CVE-2018-57841 PoCIn LibTIFF 4.0.9, there is an uncontrolled resource consumption in the TIFFSetDirectory function of tif_dir.c. Remote attackers could…
- CVE-2018-57851 PoCIn OpenJPEG 2.3.0, there is an integer overflow caused by an out-of-bounds left shift in the opj_j2k_setup_encoder function…
- CVE-2018-57861 PoCIn Long Range Zip (aka lrzip) 0.631, there is an infinite loop and application hang in the get_fileinfo function (lrzip.c). Remote…
- CVE-2018-58731 PoCAn issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing…
- CVE-2018-59251 PoCA security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can…
- CVE-2018-59501 PoCCross-site scripting (XSS) vulnerability in the web UI in Mailman before 2.1.26 allows remote attackers to inject arbitrary web script or…
- CVE-2018-59542 PoCsphpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands.
- CVE-2018-59555 PoCsAn issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated…
- CVE-2018-59562 PoCsIn Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-59572 PoCsIn Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-59582 PoCsIn Zillya! Antivirus 3.0.2230.0, the driver file (zef.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-59611 PoCCentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the `module` value of the `index.php` file.
- CVE-2018-59621 PoCindex.php in CentOS-WebPanel.com (aka CWP) CentOS Web Panel through v0.9.8.12 has XSS via the id parameter to the phpini_editor module or…
- CVE-2018-59632 PoCsCMS Made Simple (CMSMS) 2.2.5 has XSS in admin/addbookmark.php via the title parameter.
- CVE-2018-59641 PoCCMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_messages parameter.
- CVE-2018-59652 PoCsCMS Made Simple (CMSMS) 2.2.5 has XSS in admin/moduleinterface.php via the m1_errors parameter.
- CVE-2018-59671 PoCNetis WF2419 V2.2.36123 devices allow XSS via the Description parameter on the Bandwidth Control Rule Settings page.
- CVE-2018-59691 PoCCross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding…
- CVE-2018-59702 PoCsSQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter.
- CVE-2018-59712 PoCsSQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.
- CVE-2018-59721 PoCSQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.
- CVE-2018-59732 PoCsSQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the…
- CVE-2018-59742 PoCsSQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.
- CVE-2018-59752 PoCsSQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.
- CVE-2018-59761 PoCCross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin…
- CVE-2018-59771 PoCSQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.
- CVE-2018-59781 PoCSQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.
- CVE-2018-59791 PoCSQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.
- CVE-2018-59802 PoCsSQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.
- CVE-2018-59812 PoCsSQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.
- CVE-2018-59822 PoCsSQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request.
- CVE-2018-59832 PoCsSQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.
- CVE-2018-59841 PoCSQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.
- CVE-2018-59851 PoCSQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.
- CVE-2018-59861 PoCSQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.
- CVE-2018-59872 PoCsSQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a…
- CVE-2018-59881 PoCSQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.
- CVE-2018-59892 PoCsSQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue…
- CVE-2018-59902 PoCsSQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.
- CVE-2018-59912 PoCsSQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different…
- CVE-2018-59922 PoCsSQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request.
- CVE-2018-59932 PoCsSQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request.
- CVE-2018-59942 PoCsSQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in…
- CVE-2018-59971 PoCAn issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal…
- CVE-2018-59995 PoCsAn issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST…