Unknown · CVSS Not scored
FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.
Published Nov 29, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In GetSimpleCMS 3.3.15, admin/upload.php blocks .html uploads but there are several alternative cases in which HTML can be executed, such as a file with no extension or an unrecognized extension (e.g., the test or test.asdf filename), because of admin/upload-uploadify.php, and validate_safe_file in admin/inc/security_functions.php.
Published Nov 21, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Shell Metacharacter Injection in www/modules/save.php in FruityWifi (aka PatatasFritas/PatataWifi) through 2.4 allows remote attackers to execute arbitrary code with root privileges via a crafted mod_name parameter in a POST request. NOTE: unlike in CVE-2018-17317, the attacker does not need a valid session.
Published Nov 11, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android ID: A-63521984.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
ShowDoc 2.4.1 allows remote attackers to edit other users' notes by navigating with a modified page_id.
Published Nov 28, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentication.
Published Nov 5, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
SRCMS 3.0.0 allows CSRF via admin.php?m=Admin&c=gifts&a=update to change goods prices with the super administrator's privileges.
Published Nov 16, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In hid_debug_events_read of drivers/hid/hid-debug.c, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-71361580.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
Published Nov 5, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The cross-site scripting vulnerability has been reported to affect earlier versions of Photo Station. If exploited, the vulnerability could allow remote attackers to inject malicious code. This issue affects: QNAP Systems Inc. Photo Station versions prior to 5.7.11; versions prior to 6.0.10.
Published Nov 2, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74947856.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Stored XSS was discovered in the Easy Testimonials plugin 3.2 for WordPress. Three wp-admin/post.php parameters (_ikcf_client and _ikcf_position and _ikcf_other) have Cross-Site Scripting.
Published Nov 26, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
Published Nov 1, 2018 · Updated Sep 16, 2024
High · CVSS 8.1
Pivotal CredHub Service Broker, versions prior to 1.1.0, uses a guessable form of random number generation in creating service broker's UAA client. A remote malicious user may guess the client secret and obtain or modify credentials for users of the CredHub Service.
Published Nov 13, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
Published Nov 5, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
The u3d plugin 9.3.0.10809 (aka plugins\U3DBrowser.fpi) in FoxitReader.exe in Foxit Reader 9.3.0.10826 allows remote attackers to cause a denial of service (out-of-bounds read) or obtain sensitive information via a U3D sample because of a "Read Access Violation starting at U3DBrowser+0x000000000000347a" issue.
Published Nov 17, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.
Published Nov 26, 2018 · Updated Sep 16, 2024
Low · CVSS 3.2
IBM QRadar SIEM 7.3 and 7.4 n a multi tenant configuration could be vulnerable to information disclosure. IBM X-Force ID: 147440.
Published Nov 5, 2020 · Updated Sep 16, 2024
Unknown · CVSS Not scored
There is a heap-based buffer over-read at writer.c (function: write_png_to_file) in libsixel 1.8.2 that will cause a denial of service.
Published Nov 30, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-77486542.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in XiaoCms 20141229. admin/index.php?c=content&a=add&catid=3 has CSRF, as demonstrated by entering news via the data[content] parameter.
Published Nov 12, 2018 · Updated Sep 16, 2024
High · CVSS 8.8
IBM WebSphere MQ 8.0.0.0 through 8.0.0.10, 9.0.0.0 through 9.0.0.5, 9.0.1 through 9.0.5, and 9.1.0.0 could allow a local user to inject code that could be executed with root privileges. IBM X-Force ID: 148947.
Published Nov 13, 2018 · Updated Sep 16, 2024
Medium · CVSS 5.3
IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.
Published Nov 2, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74202041.
Published Nov 6, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive.
Published Nov 26, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
Published Nov 17, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
PRTG Network Monitor before 18.2.41.1652 allows remote unauthenticated attackers to terminate the PRTG Core Server Service via a special HTTP request.
Published Nov 12, 2018 · Updated Sep 16, 2024
Unknown · CVSS Not scored
In Artifex MuPDF 1.14.0, there is an infinite loop in the function svg_dev_end_tile in fitz/svg-device.c, as demonstrated by mutool.
Published Nov 30, 2018 · Updated Sep 12, 2024
Medium · CVSS 5.9
The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.
Published Nov 9, 2023 · Updated Sep 3, 2024
Medium · CVSS 5.5
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been rated as critical. Affected by this issue is some unknown functionality of the component Tag Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The name of the patch is cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-244484.
Published Nov 6, 2023 · Updated Aug 5, 2024
Medium · CVSS 5.5
A vulnerability was found in Vaerys-Dawn DiscordSailv2 up to 2.10.2. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Command Mention Handler. The manipulation leads to improper access controls. Upgrading to version 2.10.3 is able to address this issue. The patch is named cc12e0be82a5d05d9f359ed8e56088f4f8b8eb69. It is recommended to upgrade the affected component. The associated identifier of this vulnerability is VDB-244483.
Published Nov 5, 2023 · Updated Aug 5, 2024
Unknown · CVSS Not scored
The LearnDash LMS WordPress plugin before 2.5.4 does not have any authorisation and validation of the file to be uploaded in the learndash_assignment_process_init() function, which could allow unauthenticated users to upload arbitrary files to the web server
Published Nov 1, 2021 · Updated Aug 5, 2024
Unknown · CVSS Not scored
Tautulli versions 2.1.38 and below allows remote attackers to bypass intended access control in Plex Media Server because the X-Plex-Token is mishandled and can be retrieved from Tautulli. NOTE: Initially, this id was associated with Plex Media Server 1.18.2.2029-36236cc4c as the affected product and version. Further research indicated that Tautulli is the correct affected product.
Published Nov 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
Published Nov 12, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in the MailPoet Newsletters (aka wysija-newsletters) plugin before 2.8.2 for WordPress. The plugin is vulnerable to SPAM attacks.
Published Nov 6, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An XML external entity (XXE) vulnerability in CommandCenterWebServices/.*?wsdl in Raritan CommandCenter Secure Gateway before 8.0.0 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
Published Nov 18, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Cloudera Data Science Workbench (CDSW) 1.4.0 through 1.4.2. Authenticated users can bypass project permission checks and gain read-write access to any project folder.
Published Nov 26, 2019 · Updated Aug 5, 2024
Unknown · CVSS Not scored
There is a heap-based buffer over-read at wav.c in wav_write_header in libsndfile 1.0.28 that will cause a denial of service.
Published Nov 30, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
A stack-based buffer overflow in the find_green() function of dcraw through 9.28, as used in ufraw-batch and many other products, may allow a remote attacker to cause a control-flow hijack, denial-of-service, or unspecified other impact via a maliciously crafted raw photo file.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2alaw_array in alaw.c that will lead to a denial of service.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in tp5cms through 2017-05-25. admin.php/system/set.html has XSS via the title parameter.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in libsndfile 1.0.28. There is a buffer over-read in the function i2ulaw_array in ulaw.c that will lead to a denial of service.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
An issue was discovered in Sales & Company Management System (SCMS) through 2018-06-06. There is a discrepancy in username checking between a component that does string validation, and a component that is supposed to query a MySQL database. Thus, it is possible to register a new account with a duplicate username, as demonstrated by use of the test%c2 string when a test account already exists.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
ShowDoc 2.4.1 allows remote attackers to obtain sensitive information by navigating with a modified page_id, as demonstrated by reading note content, or discovering a username in the JSON data at a diff URL.
Published Nov 27, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
In Wireshark 2.6.0 to 2.6.4, the ZigBee ZCL dissector could crash. This was addressed in epan/dissectors/packet-zbee-zcl-lighting.c by preventing a divide-by-zero error.
Published Nov 29, 2018 · Updated Aug 5, 2024
Unknown · CVSS Not scored
cgi_handle_request in uhttpd in OpenWrt through 18.06.1 and LEDE through 17.01 has unauthenticated reflected XSS via the URI, as demonstrated by a cgi-bin/?[XSS] URI.
Published Nov 28, 2018 · Updated Aug 5, 2024