Common Vulnerabilities and Exposures (CVE) is a critical tool for maintaining software security, providing a standardized way to track and manage vulnerabilities across systems. Organizations should regularly monitor CVE databases, assess the impact of vulnerabilities, and apply patches promptly to reduce the risk of exploitation.
CVE (Common Vulnerabilities and Exposures) is a public database that provides a standardized method for identifying, tracking, and referencing publicly disclosed security vulnerabilities in software and hardware.
Each vulnerability receives a unique identifier called a CVE ID (e.g., CVE-2023-12345), making it easier to reference specific vulnerabilities across different tools and databases.
Total Search Results: 158437
CVE ID | Description | Severity | Published Date | Affected Vendor | Action | ||||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
CVE-2018-17019 | In Bro through 2.5.5, there is a DoS in IRC protocol names command parsing in analyzer/protocol/irc/IRC.cc. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-1702 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 146189. | Unknown | 2018-09-28 | IBM | |||||||||||||
CVE-2018-17020 | ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allow remote attackers to cause a denial of service via a single "GET / HTTP/1.1\r\n" line. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-17021 | Cross-site scripting (XSS) vulnerability on ASUS GT-AC5300 devices with firmware through 3.0.0.4.384_32738 allows remote attackers to inject arbitrary web script or HTML via the appGet.cgi hook parameter. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-17022 | Stack-based buffer overflow on the ASUS GT-AC5300 router through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (device crash) or possibly have unspecified other impact by setting a long sh_path0 value and then sending an appGet.cgi?hook=select_list("Storage_x_SharedPath") request, because ej_select_list in router/httpd/web.c uses strcpy. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-17023 | Cross-site request forgery (CSRF) vulnerability on ASUS GT-AC5300 routers with firmware through 3.0.0.4.384_32738 allows remote attackers to hijack the authentication of administrators for requests that change the administrator password via a request to start_apply.htm. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-17024 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an add_page action. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17025 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page action for a page with no special role. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-17026 | admin/index.php in Monstra CMS 3.0.4 allows XSS via the page_meta_title parameter in an edit_page&name=error404 action, a different vulnerability than CVE-2018-10121. | Unknown | 2018-09-13 | n/a | |||||||||||||
CVE-2018-17030 | BigTree CMS 4.2.23 allows remote authenticated users, if possessing privileges to set hooks, to execute arbitrary code via /core/admin/auto-modules/forms/process.php. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17031 | In Gogs 0.11.53, an attacker can use a crafted .eml file to trigger MIME type sniffing, which leads to XSS, as demonstrated by Internet Explorer, because an "X-Content-Type-Options: nosniff" header is not sent. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17034 | UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17035 | UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17036 | An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17037 | user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17039 | MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-1704 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially-crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that would appear to be trusted. This could allow the attacker to obtain highly sensitive information or conduct further attacks against the victim. IBM X-Force ID: 146339. | Unknown | 2018-09-28 | IBM | |||||||||||||
CVE-2018-17042 | An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17043 | An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init in Storage.cpp, called from parse_doc in parse_doc.cpp. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17044 | In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17045 | An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aksi_users.php?act=update. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17046 | translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17048 | admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17049 | CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-1705 | IBM Platform Symphony 7.1 Fix Pack 1 and 7.1.1 and IBM Spectrum Symphony 7.1.2 and 7.2.0.2 contain an information disclosure vulnerability that could allow an authenticated attacker to obtain highly sensitive information. IBM X-Force ID: 146340. | Unknown | 2018-08-28 | IBM | |||||||||||||
CVE-2018-17050 | The mintToken function of a smart contract implementation for PolyAi (AI), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17051 | K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17053 | Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17054. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17054 | Cross-site scripting (XSS) vulnerability in Identity Server in Progress Sitefinity CMS versions 10.0 through 11.0 allows remote attackers to inject arbitrary web script or HTML via vectors related to login request parameters, a different vulnerability than CVE-2018-17053. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17055 | An arbitrary file upload vulnerability in Progress Sitefinity CMS versions 4.0 through 11.0 related to image uploads. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17056 | Cross-site scripting (XSS) vulnerability in ServiceStack in Progress Sitefinity CMS versions 10.2 through 11.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17057 | An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17058 | An issue was discovered in JABA XPress Online Shop through 2018-09-14. It contains an arbitrary file upload vulnerability in the picture-upload feature of ProductEdit.aspx. An authenticated attacker may bypass the frontend filename validation and upload an arbitrary file via FileUploader.aspx.cs in FileUploader.aspx by using empty w and h parameters. This file may contain arbitrary aspx code that may be executed by accessing /Jec/ProductImages/ |
Unknown | N/A | n/a | |||||||||||||
CVE-2018-1706 | IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341. | Unknown | 2018-10-11 | IBM | |||||||||||||
CVE-2018-17060 | Telerik Extensions for ASP.NET MVC (all versions) does not whitelist requests, which can allow a remote attacker to access files inside the server's web directory. NOTE: this product has been obsolete since June 2013. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17061 | BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17062 | An issue was discovered in SeaCMS 6.64. XSS exists in admin_video.php via the action, area, type, yuyan, jqtype, v_isunion, v_recycled, v_ismoney, or v_ispsd parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17063 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17064 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17065 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17066 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17067 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17068 | An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17069 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17070 | An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17071 | The fallback function of a simple lottery smart contract implementation for Lucky9io, an Ethereum gambling game, generates a random value with the publicly readable variable entry_number. This variable is private, yet it is readable by eth.getStorageAt function. Also, attackers can purchase a ticket at a low price by directly calling the fallback function with small msg.value, because the developer set the currency unit incorrectly. Therefore, it allows attackers to always win and get rewards. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17072 | JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17073 | wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17074 | The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17075 | The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17076 | GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified other impact via a crafted file. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17077 | An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17079 | An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-1708 | IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343. | Unknown | 2018-10-11 | IBM | |||||||||||||
CVE-2018-17081 | e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17082 | The Apache2 component in PHP before 5.6.38, 7.0.x before 7.0.32, 7.1.x before 7.1.22, and 7.2.x before 7.2.10 allows XSS via the body of a "Transfer-Encoding: chunked" request, because the bucket brigade is mishandled in the php_handler function in sapi/apache2handler/sapi_apache2.c. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17085 | An issue was discovered in OTCMS 3.61. XSS exists in admin/users.php via these parameters: dataTypeCN dataMode dataModeStr. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17086 | An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17088 | The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17090 | An issue was discovered in DonLinkage 6.6.8. The modules /pages/bazy/bazy_adresow.php and /pages/proxy/add.php are vulnerable to stored XSS that can be triggered by closing | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17091 | An issue was discovered in DonLinkage 6.6.8. It allows remote attackers to obtain potentially sensitive information via a direct request for files/temporary.txt. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17092 | An issue was discovered in DonLinkage 6.6.8. SQL injection in /pages/proxy/php.php and /pages/proxy/add.php can be exploited via specially crafted input, allowing an attacker to obtain information from a database. The vulnerability can only be triggered by an authorized user. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17095 | An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17096 | The BPMDetect class in BPMDetect.cpp in libSoundTouch.a in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (assertion failure and application exit), as demonstrated by SoundStretch. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17097 | The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (double free) or possibly have unspecified other impact, as demonstrated by SoundStretch. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17098 | The WavFileBase class in WavFile.cpp in Olli Parviainen SoundTouch 2.0 allows remote attackers to cause a denial of service (heap corruption from size inconsistency) or possibly have unspecified other impact, as demonstrated by SoundStretch. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-1710 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364. | Unknown | 2018-09-21 | IBM | |||||||||||||
CVE-2018-17100 | An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17101 | An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17102 | An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17103 | An issue was discovered in GetSimple CMS v3.3.13. There is a CSRF vulnerability that can change the administrator's password via admin/settings.php. NOTE: The vendor reported that the PoC was sending a value for the nonce parameter | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17104 | An issue was discovered in Microweber 1.0.7. There is a CSRF attack (against the admin user) that can add an administrative account via api/save_user. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17106 | In Tinyftp Tinyftpd 1.1, a buffer overflow exists in the text variable of the do_mkd function in the ftpproto.c file. An attacker can overwrite ebp via a long pathname. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17107 | In Tgstation tgstation-server 3.2.4.0 through 3.2.1.0 (fixed in 3.2.5.0), active logins would be cached, allowing subsequent logins to succeed with any username or password. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17108 | The SBIbuddy (aka com.sbi.erupee) application 1.41 and 1.42 for Android might allow attackers to perform Account Takeover attacks by intercepting a security-question response during the initial configuration of the application. | Unknown | 2018-09-16 | n/a | |||||||||||||
CVE-2018-1711 | IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369. | Unknown | 2018-09-21 | IBM | |||||||||||||
CVE-2018-17110 | Simple POS 4.0.24 allows SQL Injection via a products/get_products/ columns[0][search][value] parameter in the management panel, as demonstrated by products/get_products/1. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17111 | The onlyOwner modifier of a smart contract implementation for Coinlancer (CL), an Ethereum ERC20 token, has a potential access control vulnerability. All contract users can access functions that use this onlyOwner modifier, because the comparison between msg.sender and owner is incorrect. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17113 | App/Modules/Admin/Tpl/default/Public/dwz/uploadify/scripts/uploadify.swf in EasyCMS 1.5 has XSS via the uploadifyID or movieName parameter, a related issue to CVE-2018-9173. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-1712 | IBM API Connect's Developer Portal 5.0.0.0 through 5.0.8.3 is vulnerable to Server Side Request Forgery. An attacker, using specially crafted input parameters can trick the server into making potentially malicious calls within the trusted network. IBM X-Force ID: 146370. | Unknown | 2018-08-16 | IBM | |||||||||||||
CVE-2018-17125 | CScms 4.1 allows arbitrary directory deletion via a dir=..\\ substring to plugins\sys\admin\Plugins.php. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17126 | CScms 4.1 allows remote code execution, as demonstrated by 1');eval($_POST[cmd]);# in Web Name to upload\plugins\sys\Install.php. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17127 | blocking_request.cgi on ASUS GT-AC5300 devices through 3.0.0.4.384_32738 allows remote attackers to cause a denial of service (NULL pointer dereference and device crash) via a request that lacks a timestap parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17128 | A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17129 | MetInfo 6.1.0 has SQL injection in doexport() in app/system/feedback/admin/feedback_admin.class.php via the class1 field. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17130 | PHPMyWind 5.5 has XSS in member.php via an HTTP Referer header, | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17131 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the varvalue field. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17132 | admin/goods_update.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the attrvalue[] array parameter. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17133 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the rewrite url setting. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17134 | admin/web_config.php in PHPMyWind 5.5 allows Admin users to execute arbitrary code via the cfg_author field in conjunction with a crafted cfg_webpath field. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17136 | zzcms 8.3 contains a SQL Injection vulnerability in /user/check.php via a Client-Ip HTTP header. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17137 | Prezi Next 1.3.101.11 has a documented purpose of creating HTML5 presentations but has SE_DEBUG_PRIVILEGE on Windows, which might allow attackers to bypass intended access restrictions. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17138 | The Jibu Pro plugin through 1.7 for WordPress is prone to Stored XSS via the wp-content/plugins/jibu-pro/quiz_action.php name (aka Quiz Name) field. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17139 | UltimatePOS 2.5 allows users to upload arbitrary files, which leads to remote command execution by posting to a /products URI with PHP code in a .php file with the image/jpeg content type. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17140 | The Quizlord plugin through 2.0 for WordPress is prone to Stored XSS via the title parameter in a ql_insert action to wp-admin/admin.php. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17141 | HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file. | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17142 | The html package (aka x/net/html) through 2018-09-17 in Go mishandles | Unknown | N/A | n/a | |||||||||||||
CVE-2018-17143 | The html package (aka x/net/html) through 2018-09-17 in Go mishandles Unknown |
N/A |
n/a |
|
CVE-2018-17144 |
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash. |
Unknown |
N/A |
n/a |
|
CVE-2018-17145 |
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15. |
Unknown |
N/A |
n/a |
|
|
vunerability-insight.com © 2023 - 2025. All Rights Reserved.
Vulnerability Data Repositories v