CVE-2018-6000 to CVE-2018-6999
240 CVEs with public proof-of-concept exploits.
- CVE-2018-60005 PoCsAn issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi…
- CVE-2018-60042 PoCsSQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter.
- CVE-2018-60052 PoCsSQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.
- CVE-2018-60062 PoCsSQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.
- CVE-2018-60072 PoCsCSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.
- CVE-2018-60083 PoCsArbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.
- CVE-2018-60131 PoCCross-site scripting (XSS) in BigTree 4.2.19 allows any remote users to inject arbitrary web script or HTML via the directory parameter.…
- CVE-2018-60141 PoCSubsonic v6.1.3 has an insecure allow-access-from domain="*" Flash cross-domain policy that allows an attacker to retrieve sensitive user…
- CVE-2018-60151 PoCAn issue was discovered in the "Email Subscribers & Newsletters" plugin before 3.4.8 for WordPress. Sending an HTTP POST request to a URI…
- CVE-2018-60221 PoCDirectory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to…
- CVE-2018-60232 PoCsFastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.
- CVE-2018-60242 PoCsSQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
- CVE-2018-60641 PoCType Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to…
- CVE-2018-60652 PoCsKEVInteger overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to…
- CVE-2018-60841 PoCInsufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to…
- CVE-2018-60921 PoCAn integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute…
- CVE-2018-61261 PoCA precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a…
- CVE-2018-61291 PoCOut of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds…
- CVE-2018-61301 PoCIncorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform…
- CVE-2018-61802 PoCsA flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.
- CVE-2018-61842 PoCsZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
- CVE-2018-61871 PoCIn Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c…
- CVE-2018-61902 PoCsNetis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
- CVE-2018-61911 PoCThe js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.
- CVE-2018-61921 PoCIn Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service…
- CVE-2018-61931 PoCA Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to…
- CVE-2018-61942 PoCsA cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin…
- CVE-2018-61952 PoCsadmin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows…
- CVE-2018-62002 PoCsvBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.
- CVE-2018-62012 PoCsIn eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-62022 PoCsIn eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-62032 PoCsIn eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-62041 PoCIn Max Secure Anti Virus 19.0.3.019,, the driver file (SDActMon.sys) allows local users to cause a denial of service (BSOD) or possibly…
- CVE-2018-62051 PoCIn Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-62061 PoCIn Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-62071 PoCIn Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-62081 PoCIn Max Secure Anti Virus 19.0.3.019,, the driver file (MaxProtector32.sys) allows local users to cause a denial of service (BSOD) or…
- CVE-2018-62091 PoCIn Max Secure Anti Virus 19.0.3.019,, the driver file (MaxCryptMon.sys) allows local users to cause a denial of service (BSOD) or possibly…
- CVE-2018-62171 PoCThe WStr::_alloc_iostr_data() function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 allows remote attackers to cause a…
- CVE-2018-62192 PoCsAn Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with…
- CVE-2018-62202 PoCsAn arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which…
- CVE-2018-62212 PoCsAn unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to…
- CVE-2018-62222 PoCsArbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be…
- CVE-2018-62232 PoCsA missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to…
- CVE-2018-62242 PoCsA lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker…
- CVE-2018-62252 PoCsAn XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to…
- CVE-2018-62262 PoCsReflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an…
- CVE-2018-62272 PoCsA stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject…
- CVE-2018-62282 PoCsA SQL injection vulnerability in a Trend Micro Email Encryption Gateway 5.5 policy script could allow an attacker to execute SQL commands…
- CVE-2018-62292 PoCsA SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 edit policy script could allow an attacker to execute SQL…
- CVE-2018-62302 PoCsA SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to…
- CVE-2018-62311 PoCA server auth command injection authentication bypass vulnerability in Trend Micro Smart Protection Server (Standalone) versions 3.3 and…
- CVE-2018-62371 PoCA vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the…
- CVE-2018-62428 PoCsSome NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An…
- CVE-2018-62881 PoCCross-site Request Forgery leading to Administrative account takeover in Kaspersky Secure Mail Gateway version 1.1.
- CVE-2018-62891 PoCConfiguration file injection leading to Code Execution as Root in Kaspersky Secure Mail Gateway version 1.1.
- CVE-2018-62901 PoCLocal Privilege Escalation in Kaspersky Secure Mail Gateway version 1.1.
- CVE-2018-62911 PoCWebConsole Cross-Site Scripting in Kaspersky Secure Mail Gateway version 1.1.
- CVE-2018-63151 PoCThe outputSWF_TEXT_RECORD function (util/outputscript.c) in libming through 0.4.8 is vulnerable to an integer overflow and resultant…
- CVE-2018-63171 PoCThe remote management interface in Claymore Dual Miner 10.5 and earlier is vulnerable to an unauthenticated format string vulnerability,…
- CVE-2018-63232 PoCsThe elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1,…
- CVE-2018-63283 PoCsIt was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could…
- CVE-2018-63293 PoCsIt was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing…
- CVE-2018-63331 PoCThe hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a…
- CVE-2018-63412 PoCsReact applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time.…
- CVE-2018-63421 PoCreact-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an…
- CVE-2018-63531 PoCThe Python console in Electrum through 2.9.4 and 3.x through 3.0.5 supports arbitrary Python code without considering (1)…
- CVE-2018-63571 PoCThe acx_asmw_saveorder_callback function in function.php in the acurax-social-media-widget plugin before 3.2.6 for WordPress has CSRF via…
- CVE-2018-63591 PoCThe decompileIF function (util/decompile.c) in libming through 0.4.8 is vulnerable to a use-after-free, which may allow attackers to cause…
- CVE-2018-63611 PoCEasy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the op parameter, as demonstrated by adding a backdoor FTP account.
- CVE-2018-63621 PoCEasy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.
- CVE-2018-63632 PoCsSQL Injection exists in Task Rabbit Clone 1.0 via the single_blog.php id parameter.
- CVE-2018-63642 PoCsSQL Injection exists in Multilanguage Real Estate MLM Script through 3.0 via the /product-list.php srch parameter.
- CVE-2018-63652 PoCsSQL Injection exists in TSiteBuilder 1.0 via the id parameter to /site.php, /pagelist.php, or /page_new.php.
- CVE-2018-63672 PoCsSQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the…
- CVE-2018-63682 PoCsSQL Injection exists in the JomEstate PRO through 3.7 component for Joomla! via the id parameter in a task=detailed action.
- CVE-2018-63702 PoCsSQL Injection exists in the NeoRecruit 4.1 component for Joomla! via the (1) PATH_INFO or (2) name of a .html file under the all-offers/…
- CVE-2018-63722 PoCsSQL Injection exists in the JB Bus 2.3 component for Joomla! via the order_number parameter.
- CVE-2018-63732 PoCsSQL Injection exists in the Fastball 2.5 component for Joomla! via the season parameter in a view=player action.
- CVE-2018-63763 PoCsIn Joomla! before 3.8.4, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the Hathor…
- CVE-2018-63811 PoCIn ZZIPlib 0.13.67, 0.13.66, 0.13.65, 0.13.64, 0.13.63, 0.13.62, 0.13.61, 0.13.60, 0.13.59, 0.13.58, 0.13.57 and 0.13.56 there is a…
- CVE-2018-63833 PoCsMonstra CMS through 3.0.4 has an incomplete "forbidden types" list that excludes .php (and similar) file extensions but not the .pht or…
- CVE-2018-63881 PoCiBall iB-WRA150N 1.2.6 build 110401 Rel.47776n devices allow remote authenticated users to execute arbitrary OS commands via shell…
- CVE-2018-638926 PoCsIn WordPress through 4.9.2, unauthenticated attackers can cause a denial of service (resource consumption) by using the large list of…
- CVE-2018-63901 PoCThe WStr::assign function in kso.dll in Kingsoft WPS Office 10.1.0.7106 and 10.2.0.5978 does not validate the size of the source memory…
- CVE-2018-63913 PoCsA cross-site request forgery web vulnerability has been discovered on Netis WF2419 V2.2.36123 devices. A remote attacker is able to delete…
- CVE-2018-63932 PoCsFreePBX 10.13.66-32bit and 14.0.1.24 (SNG7-PBX-64bit-1712-2) allow post-authentication SQL injection via the order parameter. NOTE: the…
- CVE-2018-63942 PoCsSQL Injection exists in the InviteX 3.0.5 component for Joomla! via the invite_type parameter in a view=invites action.
- CVE-2018-63951 PoCSQL Injection exists in the Visual Calendar 3.1.3 component for Joomla! via the id parameter in a view=load action.
- CVE-2018-63963 PoCsSQL Injection exists in the Google Map Landkarten through 4.2.3 component for Joomla! via the cid or id parameter in a layout=form_markers…
- CVE-2018-63971 PoCDirectory Traversal exists in the Picture Calendar 3.1.4 component for Joomla! via the list.php folder parameter.
- CVE-2018-63981 PoCSQL Injection exists in the CP Event Calendar 3.0.1 component for Joomla! via the id parameter in a task=load action.
- CVE-2018-64091 PoCAn issue was discovered in Appnitro MachForm before 4.2.3. The module in charge of serving stored files gets the path from the database.…
- CVE-2018-64101 PoCAn issue was discovered in Appnitro MachForm before 4.2.3. There is a download.php SQL injection via the q parameter.
- CVE-2018-64111 PoCAn issue was discovered in Appnitro MachForm before 4.2.3. When the form is set to filter a blacklist, it automatically adds dangerous…
- CVE-2018-64431 PoCA vulnerability in Brocade Network Advisor Versions before 14.3.1 could allow an unauthenticated, remote attacker to log in to the JBoss…
- CVE-2018-64581 PoCEasy Hosting Control Panel (EHCP) v0.37.12.b allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging…
- CVE-2018-64601 PoCHotspot Shield runs a webserver with a static IP address 127.0.0.1 and port 895. The web server uses JSONP and hosts sensitive information…
- CVE-2018-64613 PoCsMarch Hare WINCVS before 2.8.01 build 6610, and CVS Suite before 2009R2 build 6610, contains an Insecure Library Loading vulnerability in…
- CVE-2018-64661 PoCA cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject…
- CVE-2018-64671 PoCThe flickrRSS plugin 5.3.1 for WordPress has CSRF via wp-admin/options-general.php.
- CVE-2018-64681 PoCA cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject…
- CVE-2018-64691 PoCA cross-site scripting (XSS) vulnerability in flickrRSS.php in the flickrRSS plugin 5.3.1 for WordPress allows remote attackers to inject…
- CVE-2018-64792 PoCsAn issue was discovered on Netwave IP Camera devices. An unauthenticated attacker can crash a device by sending a POST request with a huge…
- CVE-2018-64813 PoCsA buffer overflow vulnerability in the control protocol of Disk Savvy Enterprise v10.4.18 allows remote attackers to execute arbitrary…
- CVE-2018-64841 PoCIn ZZIPlib 0.13.67, there is a memory alignment error and bus error in the __zzip_fetch_disk_trailer function of zzip/zip.c. Remote…
- CVE-2018-65061 PoCCross-Site Scripting (XSS) exists in the Add Forum feature in the Administrative Panel in miniBB 3.2.2 via crafted use of an onload…
- CVE-2018-65222 PoCsIn nProtect AVS V4.0 before 4.0.0.39, the driver file (TKRgFtXp.SYS) allows local users to cause a denial of service (BSOD) or possibly…
- CVE-2018-65232 PoCsIn nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-65242 PoCsIn nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-65252 PoCsIn nProtect AVS V4.0 before 4.0.0.39, the driver file (TKFsAv.SYS) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-65271 PoCXSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L…
- CVE-2018-65281 PoCXSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L…
- CVE-2018-65291 PoCXSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L…
- CVE-2018-65302 PoCsKEVOS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and…
- CVE-2018-65372 PoCsA buffer overflow vulnerability in the control protocol of Flexense SyncBreeze Enterprise v10.4.18 allows remote attackers to execute…
- CVE-2018-65401 PoCIn ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address in the zzip_disk_findfirst function of zzip/mmapped.c.…
- CVE-2018-65411 PoCIn ZZIPlib 0.13.67, there is a bus error caused by loading of a misaligned address (when handling disk64_trailer local entries) in…
- CVE-2018-65421 PoCIn ZZIPlib 0.13.67, there is a bus error (when handling a disk64_trailer seek value) caused by loading of a misaligned address in the…
- CVE-2018-65431 PoCIn GNU Binutils 2.30, there's an integer overflow in the function load_specific_debug_section() in objdump.c, which results in `malloc()`…
- CVE-2018-65441 PoCpdf_load_obj_stm in pdf/pdf-xref.c in Artifex MuPDF 1.12.0 could reference the object stream recursively and therefore run out of error…
- CVE-2018-65462 PoCsplays_service.exe in the plays.tv service before 1.27.7.0, as distributed in AMD driver-installation packages and Gaming Evolved products,…
- CVE-2018-65591 PoCThe Linux kernel, as used in Ubuntu 18.04 LTS and Ubuntu 18.10, allows local users to obtain names of files in which they would not…
- CVE-2018-65632 PoCsMultiple cross-site request forgery (CSRF) vulnerabilities in totemomail Encryption Gateway before 6.0.0_Build_371 allow remote attackers…
- CVE-2018-657488 PoCsGo before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source…
- CVE-2018-65751 PoCSQL Injection exists in the JEXTN Classified 1.0.0 component for Joomla! via a view=boutique&sid= request.
- CVE-2018-65761 PoCSQL Injection exists in Event Manager 1.0 via the event.php id parameter or the page.php slug parameter.
- CVE-2018-65771 PoCSQL Injection exists in the JEXTN Membership 3.1.0 component for Joomla! via the usr_plan parameter in a…
- CVE-2018-65781 PoCSQL Injection exists in the JE PayperVideo 3.0.0 component for Joomla! via the usr_plan parameter in a…
- CVE-2018-65791 PoCSQL Injection exists in the JEXTN Reverse Auction 3.1.0 component for Joomla! via a view=products&uid= request.
- CVE-2018-65801 PoCArbitrary file upload exists in the Jimtawl 2.1.6 and 2.2.5 component for Joomla! via a view=upload&task=upload&pop=true&tmpl=component…
- CVE-2018-65811 PoCSQL Injection exists in the JMS Music 1.1.1 component for Joomla! via a search with the keyword, artist, or username parameter.
- CVE-2018-65821 PoCSQL Injection exists in the Zh GoogleMap 8.4.0.0 component for Joomla! via the id parameter in a getPlacemarkDetails,…
- CVE-2018-65832 PoCsSQL Injection exists in the Timetable Responsive Schedule 1.5 component for Joomla! via a view=event&alias= request.
- CVE-2018-65842 PoCsSQL Injection exists in the DT Register 3.2.7 component for Joomla! via a task=edit&id= request.
- CVE-2018-65852 PoCsSQL Injection exists in the JTicketing 2.0.16 component for Joomla! via a view=events action with a filter_creator or filter_events_cat…
- CVE-2018-65931 PoCAn issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged…
- CVE-2018-65941 PoClib/Crypto/PublicKey/ElGamal.py in PyCrypto through 2.6.1 generates weak ElGamal key parameters, which allows attackers to obtain…
- CVE-2018-66041 PoCSQL Injection exists in the Zh YandexMap 6.2.1.0 component for Joomla! via the id parameter in a task=getPlacemarkDetails request.
- CVE-2018-66054 PoCsSQL Injection exists in the Zh BaiduMap 3.0.0.1 component for Joomla! via the id parameter in a getPlacemarkDetails,…
- CVE-2018-66061 PoCAn issue was discovered in MalwareFox AntiMalware 2.74.0.150. Improper access control in zam32.sys and zam64.sys allows a non-privileged…
- CVE-2018-66091 PoCSQL Injection exists in the JSP Tickets 1.1 component for Joomla! via the ticketcode parameter in a ticketlist edit action, or the id…
- CVE-2018-66101 PoCInformation Leakage exists in the jLike 1.0 component for Joomla! via a task=getUserByCommentId request.
- CVE-2018-66161 PoCIn OpenJPEG 2.3.0, there is excessive iteration in the opj_t1_encode_cblks function of openjp2/t1.c. Remote attackers could leverage this…
- CVE-2018-66171 PoCEasy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database…
- CVE-2018-66181 PoCEasy Hosting Control Panel (EHCP) v0.37.12.b allows attackers to obtain sensitive information by leveraging cleartext password storage.
- CVE-2018-66192 PoCsEasy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing…
- CVE-2018-66253 PoCsIn WatchDog Anti-Malware 2.74.186.150, the driver file (ZAMGUARD32.SYS) allows local users to cause a denial of service (BSOD) or possibly…
- CVE-2018-66261 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service…
- CVE-2018-66273 PoCsIn WatchDog Anti-Malware 2.74.186.150, the driver file (ZAMGUARD32.SYS) allows local users to cause a denial of service (BSOD) or possibly…
- CVE-2018-66281 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service…
- CVE-2018-66291 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service…
- CVE-2018-66301 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service…
- CVE-2018-66311 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110009.sys) allows local users to cause a denial of service…
- CVE-2018-66321 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service…
- CVE-2018-66331 PoCIn Micropoint proactive defense software 2.0.20266.0146, the driver file (mp110005.sys) allows local users to cause a denial of service…
- CVE-2018-66401 PoCA Heap Overflow (Remote Code Execution) issue was discovered in Design Science MathType 6.9c. Crafted input can modify the next pointer of…
- CVE-2018-66431 PoCInfoblox NetMRI 7.1.1 has Reflected Cross-Site Scripting via the /api/docs/index.php query parameter.
- CVE-2018-66551 PoCPHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field.
- CVE-2018-66561 PoCZ-BlogPHP 1.5.1 has CSRF via zb_users/plugin/AppCentre/app_del.php, as demonstrated by deleting files and directories.
- CVE-2018-66711 PoCSB10240 - ePolicy Orchestrator (ePO) - Application Protection Bypass vulnerability
- CVE-2018-67551 PoCTrue Key (TK) Windows Client - Weak Directory Permission Vulnerability
- CVE-2018-67561 PoCTrue Key (TK) Windows Client - Authentication Abuse vulnerability
- CVE-2018-67571 PoCTrue Key (TK) Windows Client - Privilege Escalation vulnerability
- CVE-2018-67671 PoCA stack-based buffer over-read in the ParseRiffHeaderConfig function of cli/riff.c file of WavPack 5.1.0 allows a remote attacker to cause…
- CVE-2018-67681 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67691 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67701 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67711 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67721 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67731 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67741 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67751 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KrnlCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67761 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67771 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67781 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67791 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67801 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67811 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67821 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67831 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67841 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67851 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KSysCall.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67861 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67871 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67881 PoCIn Jiangmin Antivirus 16.0.0.100, the driver file (KVFG.sys) allows local users to cause a denial of service (BSOD) or possibly have…
- CVE-2018-67899 PoCsKEVAn issue was discovered in the base64d function in the SMTP listener in Exim before 4.90.1. By sending a handcrafted message, a buffer…
- CVE-2018-67942 PoCsSuricata before 4.0.4 is prone to an HTTP detection bypass vulnerability in detect.c and stream-tcp.c. If a malicious server breaks a…
- CVE-2018-67951 PoCPHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field.
- CVE-2018-67961 PoCPHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.
- CVE-2018-68241 PoCCozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the…
- CVE-2018-68291 PoCcipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers…
- CVE-2018-68301 PoCDirectory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4,…
- CVE-2018-68311 PoCThe setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P…
- CVE-2018-68321 PoCStack-based buffer overflow in the getSWFlag function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P…
- CVE-2018-68361 PoCThe netmonrec_comment_destroy function in wiretap/netmon.c in Wireshark through 2.4.4 performs a free operation on an uninitialized memory…
- CVE-2018-68451 PoCPHP Scripts Mall Multi Language Olx Clone Script 2.0.6 has XSS via the Leave Comment field.
- CVE-2018-68492 PoCsIn the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as…
- CVE-2018-68511 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68521 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68531 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68541 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68551 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68561 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68571 PoCSophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local…
- CVE-2018-68581 PoCCross Site Scripting (XSS) exists in PHP Scripts Mall Facebook Clone Script.
- CVE-2018-68591 PoCSQL Injection exists in PHP Scripts Mall Schools Alert Management Script 2.0.2 via the Login Parameter.
- CVE-2018-68601 PoCArbitrary File Upload and Remote Code Execution exist in PHP Scripts Mall Schools Alert Management Script 2.0.2 via a profile picture.
- CVE-2018-68611 PoCCross Site Scripting (XSS) exists in PHP Scripts Mall Lawyer Search Script 1.0.2 via a profile update parameter.
- CVE-2018-68621 PoCCross Site Scripting (XSS) exists in PHP Scripts Mall Bitcoin MLM Software 1.0.2 via a profile field.
- CVE-2018-68631 PoCSQL Injection exists in PHP Scripts Mall Select Your College Script 2.0.2 via a Login Parameter.
- CVE-2018-68641 PoCCross Site Scripting (XSS) exists in PHP Scripts Mall Multi religion Responsive Matrimonial 4.7.2 via a user profile update parameter.
- CVE-2018-68661 PoCCross Site Scripting (XSS) exists in PHP Scripts Mall Learning and Examination Management System Script 2.3.1 via a crafted message.
- CVE-2018-68672 PoCsCross Site Scripting (XSS) exists in PHP Scripts Mall Alibaba Clone Script 1.0.2 via a profile parameter.
- CVE-2018-68681 PoCCross Site Scripting (XSS) exists in PHP Scripts Mall Slickdeals / DealNews / Groupon Clone Script 3.0.2 via a User Profile Field parameter.
- CVE-2018-68691 PoCIn ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c.…
- CVE-2018-68712 PoCsLibreOffice before 5.4.5 and 6.x before 6.0.1 allows remote attackers to read arbitrary files via =WEBSERVICE calls in a document, which…
- CVE-2018-68761 PoCThe OLEProperty class in ole/oleprop.cpp in libfpx 1.3.1-10, as used in ImageMagick 7.0.7-22 Q16 and other products, allows remote…
- CVE-2018-68781 PoCCross Site Scripting (XSS) exists in the review section in PHP Scripts Mall Hot Scripts Clone Script Classified 3.1 via the title or…
- CVE-2018-68801 PoCEmpireCMS 6.6 through 7.2 allows remote attackers to discover the full path via an array value for a parameter to class/connect.php.
- CVE-2018-68812 PoCsEmpireCMS 6.6 allows remote attackers to discover the full path via an array value for a parameter to admin/tool/ShowPic.php.
- CVE-2018-68822 PoCsKEVCross-site scripting (XSS) vulnerability in the ZmMailMsgView.getAttachmentLinkHtml function in Zimbra Collaboration Suite (ZCS) before…
- CVE-2018-68881 PoCAn issue was discovered in Typesetter 5.1. The User Permissions page (aka Admin/Users) suffers from critical flaw of Cross Site Request…
- CVE-2018-68891 PoCAn issue was discovered in Typesetter 5.1. It suffers from a Host header injection vulnerability, Using this attack, a malicious user can…
- CVE-2018-68901 PoCCross-site scripting (XSS) vulnerability in Wolf CMS 0.8.3.1 via the page editing feature, as demonstrated by /?/admin/page/edit/3.
- CVE-2018-68911 PoCBookly #1 WordPress Booking Plugin Lite before 14.5 has XSS via a jQuery.ajax request to ng-payment_details_dialog.js.
- CVE-2018-689210 PoCsAn issue was discovered in CloudMe before 1.11.0. An unauthenticated remote attacker that can connect to the "CloudMe Sync" client…
- CVE-2018-69052 PoCsThe page module in TYPO3 before 8.7.11, and 9.1.0, has XSS via $GLOBALS['TYPO3_CONF_VARS']['SYS']['sitename'], as demonstrated by an admin…
- CVE-2018-69104 PoCsDedeCMS 5.7 allows remote attackers to discover the full path via a direct request for include/downmix.inc.php or…
- CVE-2018-69111 PoCThe VBWinExec function in Node\AspVBObj.dll in Advantech WebAccess 8.3.0 allows remote attackers to execute arbitrary OS commands via a…
- CVE-2018-69281 PoCPHP Scripts Mall News Website Script 2.0.4 has SQL Injection via a search term.
- CVE-2018-69361 PoCCross Site Scripting (XSS) exists on the D-Link DIR-600M C1 3.01 via the SSID or the name of a user account.
- CVE-2018-69403 PoCsA /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in…
- CVE-2018-69413 PoCsA /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution…
- CVE-2018-69431 PoCcore/lib/upload/um-image-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it…
- CVE-2018-69441 PoCcore/lib/upload/um-file-upload.php in the UltimateMember plugin 2.0 for WordPress has a cross-site scripting vulnerability because it…
- CVE-2018-69472 PoCsAn uninitialised stack variable in the nxfuse component that is part of the Open Source DokanFS library shipped with NoMachine 6.0.66_2…
- CVE-2018-69541 PoCsystemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain…
- CVE-2018-69614 PoCsKEVVMware NSX SD-WAN Edge by VeloCloud prior to version 3.1.0 contains a command injection vulnerability in the local web UI component. This…
- CVE-2018-69733 PoCsVMware Workstation (14.x before 14.1.3) and Fusion (10.x before 10.1.3) contain an out-of-bounds write vulnerability in the e1000 device.…