CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2019-18645

    Last Modified: 21 Nov 2024

    The quarantine restoration function in Total Defense Anti-virus 11.5.2.28 is vulnerable to symbolic link attacks, allowing files to be written to privileged directories.

    Published: 30 Oct 2019
    6.1
    Medium

    CVE-2010-1673

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in ikiwiki before 3.20101112 allows remote attackers to inject arbitrary web script or HTML via a comment.

    Published: 30 Oct 2019
    7.8
    High

    CVE-2010-0747

    Last Modified: 21 Nov 2024

    drbd8 allows local users to bypass intended restrictions for certain actions via netlink packets, similar to CVE-2009-3725.

    Published: 30 Oct 2019
    7.5
    High

    CVE-2019-18635

    Last Modified: 21 Nov 2024

    An issue was discovered in Mooltipass Moolticute through v0.42.1 and v0.42.x-testing through v0.42.5-testing. There is a NULL pointer dereference in MPDevice_win.cpp.

    Published: 30 Oct 2019
    9.8
    Critical

    CVE-2019-18633

    Last Modified: 21 Nov 2024

    European Commission eIDAS-Node Integration Package before 2.3.1 has Missing Certificate Validation because a certain ExplicitKeyTrustEvaluator return value is not checked. NOTE: only 2.1 is confirmed to be affected.

    Published: 30 Oct 2019
    9.8
    Critical

    CVE-2019-18632

    Last Modified: 21 Nov 2024

    European Commission eIDAS-Node Integration Package before 2.3.1 allows Certificate Faking because an attacker can sign a manipulated SAML response with a forged certificate.

    Published: 30 Oct 2019
    9.8
    Critical

    CVE-2019-10762

    Last Modified: 21 Nov 2024

    columnQuote in medoo before 1.7.5 allows remote attackers to perform a SQL Injection due to improper escaping.

    Published: 30 Oct 2019
    6.5
    Medium

    CVE-2010-0398

    Last Modified: 21 Nov 2024

    The init script in autokey before 0.61.3-2 allows local attackers to write to arbitrary files via a symlink attack.

    Published: 30 Oct 2019
    4.8
    Medium

    CVE-2019-12417

    Last Modified: 21 Nov 2024

    A malicious admin user could edit the state of objects in the Airflow metadata database to execute arbitrary javascript on certain page views. This also presented a Local File Disclosure vulnerability to any file readable by the webserver process.

    Published: 30 Oct 2019
    6.5
    Medium

    CVE-2019-17326

    Last Modified: 21 Nov 2024

    ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to arbitrary file deletion by issuing a HTTP GET request with a specially crafted parameter. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

    Published: 30 Oct 2019
    6.5
    Medium

    CVE-2019-17325

    Last Modified: 21 Nov 2024

    ClipSoft REXPERT 1.0.0.527 and earlier version allows remote attacker to upload arbitrary local file via the ActiveX method in RexViewerCtrl30.ocx. That could lead to disclosure of sensitive information. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

    Published: 30 Oct 2019
    6.5
    Medium

    CVE-2019-17324

    Last Modified: 21 Nov 2024

    ClipSoft REXPERT 1.0.0.527 and earlier version allows directory traversal by issuing a special HTTP POST request with ../ characters. This could lead to create malicious HTML file, because they can inject a content with crafted template. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

    Published: 30 Oct 2019
    8.8
    High

    CVE-2019-17323

    Last Modified: 21 Nov 2024

    ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation and execution via report print function of rexpert viewer with modified XML document. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

    Published: 30 Oct 2019
    6.5
    Medium

    CVE-2019-17322

    Last Modified: 21 Nov 2024

    ClipSoft REXPERT 1.0.0.527 and earlier version allows arbitrary file creation via a POST request with the parameter set to the file path to be written. This can be an executable file that is written to in the arbitrary directory. User interaction is required to exploit this vulnerability in that the target must visit a malicious web page.

    Published: 30 Oct 2019
    5.3
    Medium

    CVE-2019-17321

    Last Modified: 21 Nov 2024

    ClipSoft REXPERT 1.0.0.527 and earlier version have an information disclosure issue. When requesting web page associated with session, could leak username via session file path of HTTP response data. No authentication is required.

    Published: 30 Oct 2019
    7.5
    High

    CVE-2013-1391

    Last Modified: 21 Nov 2024

    Authentication bypass vulnerability in the the web interface in Hunt CCTV, Capture CCTV, Hachi CCTV, NoVus CCTV, and Well-Vision Inc DVR systems allows a remote attacker to retrieve the device configuration.

    Published: 30 Oct 2019
    5.4
    Medium

    CVE-2019-18207

    Last Modified: 21 Nov 2024

    In Zucchetti InfoBusiness before and including 4.4.1, an authenticated user can inject client-side code due to improper validation of the Title field in the InfoBusiness Web Component. The payload will be triggered every time a user browses the reports page.

    Published: 30 Oct 2019
    8.8
    High

    CVE-2019-18206

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in Zucchetti InfoBusiness before and including 4.4.1 allows arbitrary file upload.

    Published: 30 Oct 2019
    6.1
    Medium

    CVE-2019-18205

    Last Modified: 21 Nov 2024

    Multiple Reflected Cross-site Scripting (XSS) vulnerabilities exist in Zucchetti InfoBusiness before and including 4.4.1. The browsing component did not properly sanitize user input (encoded in base64). This also applies to the search functionality for the searchKey parameter.

    Published: 30 Oct 2019
    8.8
    High

    CVE-2019-18204

    Last Modified: 21 Nov 2024

    Zucchetti InfoBusiness before and including 4.4.1 allows any authenticated user to upload .php files in order to achieve code execution.

    Published: 30 Oct 2019
    6.1
    Medium

    CVE-2018-18678

    Last Modified: 21 Nov 2024

    GNUBOARD5 before 5.3.2.0 has XSS that allows remote attackers to inject arbitrary web script or HTML via the "board group extra contents" parameter, aka the adm/boardgroup_form_update.php gr_1~10 parameter.

    Published: 30 Oct 2019
    7.5
    High

    CVE-2018-16417

    Last Modified: 21 Nov 2024

    Aruba Instant 4.x prior to 6.4.4.8-4.2.4.12, 6.5.x prior to 6.5.4.11, 8.3.x prior to 8.3.0.6, and 8.4.x prior to 8.4.0.1 allows Command injection.

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-3869

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4074

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4075

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4076

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4077

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4078

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4079

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4080

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2018-4060

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2018. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16992

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16993

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-2776

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-2778

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-2859

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16350

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16351

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16975

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16976

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16977

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16979

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2016-8381

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2016-9046

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2016-9047

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2016. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-14456

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16964

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16965

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16966

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019
    —
    Unknown

    CVE-2017-16967

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues during 2017. Notes: none

    Published: 30 Oct 2019