CVE Feed

    Dashboard / CVE

    3.3
    Low

    CVE-2017-2158

    Last Modified: 21 Nov 2024

    Improper verification when expanding ZIP64 archives in Lhaplus versions 1.73 and earlier may lead to unintended contents to be extracted from a specially crafted ZIP64 archive.

    Published: 12 Jan 2018
    6.5
    Medium

    CVE-2018-5357

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-22 Q16 has memory leaks in the ReadDCMImage function in coders/dcm.c.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5361

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has CSRF via wp-admin/options.php.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5362

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][page] parameter to wp-admin/options.php.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5364

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[browser_redirect][redirect_by_language] parameter to wp-admin/options.php.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5365

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[selector_wp_list_pages][show_selector] parameter to wp-admin/options.php.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5366

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[more_languages] parameter to wp-admin/options.php.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5367

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[post_type][post] parameter to wp-admin/options.php.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5369

    Last Modified: 21 Nov 2024

    The SrbTransLatin plugin 1.46 for WordPress has XSS via an srbtranslatoptions action to wp-admin/options-general.php with a lang_identificator parameter.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5371

    Last Modified: 21 Nov 2024

    diag_ping.cmd on D-Link DSL-2640U devices with firmware IM_1.00 and ME_1.00, and DSL-2540U devices with firmware ME_1.00, allows authenticated remote attackers to execute arbitrary OS commands via shell metacharacters in the ipaddr field of an HTTP GET request.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5372

    Last Modified: 21 Nov 2024

    The Testimonial Slider plugin through 1.2.4 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5373

    Last Modified: 21 Nov 2024

    The Smooth Slider plugin through 2.8.6 for WordPress has SQL Injection via smooth-slider.php (trid parameter).

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5374

    Last Modified: 21 Nov 2024

    The Dbox 3D Slider Lite plugin through 1.2.2 for WordPress has SQL Injection via settings\sliders.php (current_slider_id parameter).

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2018-5376

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_upload.php op parameter.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2018-5377

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX X3.4 allows remote attackers to bypass intended access restrictions via the archiver\index.php action parameter.

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2018-5375

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX X3.4 has XSS via the include\spacecp\spacecp_space.php appid parameter in a delete action.

    Published: 12 Jan 2018
    4.8
    Medium

    CVE-2018-5363

    Last Modified: 21 Nov 2024

    The WPGlobus plugin 1.9.6 for WordPress has XSS via the wpglobus_option[enabled_languages][en] or wpglobus_option[enabled_languages][fr] (or any other language) parameter to wp-admin/options.php.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5368

    Last Modified: 21 Nov 2024

    The SrbTransLatin plugin 1.46 for WordPress has CSRF via an srbtranslatoptions action to wp-admin/options-general.php.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2018-5327

    Last Modified: 21 Nov 2024

    Cheetah Mobile Armorfly Browser & Downloader 1.1.05.0010, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2017-16736

    Last Modified: 21 Nov 2024

    An Unrestricted Upload Of File With Dangerous Type issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows a remote attacker to upload arbitrary files.

    Published: 12 Jan 2018
    6.5
    Medium

    CVE-2017-16732

    Last Modified: 21 Nov 2024

    A use-after-free issue was discovered in Advantech WebAccess versions prior to 8.3. WebAccess allows an unauthenticated attacker to specify an arbitrary address.

    Published: 12 Jan 2018
    7.5
    High

    CVE-2018-5326

    Last Modified: 21 Nov 2024

    Cheetah Mobile CM Browser 5.22.06.0012, when installed on unspecified "older" Android platforms, allows Same Origin Policy Bypass.

    Published: 12 Jan 2018
    9.8
    Critical

    CVE-2018-5347

    Last Modified: 21 Nov 2024

    Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

    Published: 12 Jan 2018
    6.5
    Medium

    CVE-2018-5358

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.7-22 Q16 has memory leaks in the EncodeImageAttributes function in coders/json.c, as demonstrated by the ReadPSDLayersInternal function in coders/psd.c.

    Published: 12 Jan 2018
    6.5
    Medium

    CVE-2018-0486

    Last Modified: 21 Nov 2024

    Shibboleth XMLTooling-C before 1.6.3, as used in Shibboleth Service Provider before 2.6.0 on Windows and other products, mishandles digital signatures of user attribute data, which allows remote attackers to obtain sensitive information or conduct impersonation attacks via a crafted DTD.

    Published: 12 Jan 2018
    8.8
    High

    CVE-2018-5360

    Last Modified: 21 Nov 2024

    LibTIFF before 4.0.6 mishandles the reading of TIFF files, as demonstrated by a heap-based buffer over-read in the ReadTIFFImage function in coders/tiff.c in GraphicsMagick 1.3.27.

    Published: 12 Jan 2018
    7.7
    High

    CVE-2018-1000026

    Last Modified: 21 Nov 2024

    Linux Linux kernel version at least v4.8 onwards, probably well before contains a Insufficient input validation vulnerability in bnx2x network card driver that can result in DoS: Network card firmware assertion takes card off-line. This attack appear to be exploitable via An attacker on a must pass a very large, specially crafted packet to the bnx2x card. This can be done from an untrusted guest VM..

    Published: 12 Jan 2018
    6.1
    Medium

    CVE-2012-6671

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in actions/main.php in the DragonByte Technologies Forumon RPG module before 1.0.8 for vBulletin when creating a new monster, allow remote attackers to inject arbitrary web script or HTML via the (1) monster[title] or (2) monster[description] parameters.

    Published: 11 Jan 2018
    6.1
    Medium

    CVE-2012-6670

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the DragonByte Technologies vbActivity module before 3.0.1 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the reason parameter in (1) actions/nominatemedal.php or (2) actions/requestmedal.php.

    Published: 11 Jan 2018
    6.1
    Medium

    CVE-2012-6668

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the Shout Reports in the DragonByte Technologies vBShout module before 6.0.6 for vBulletin allow remote attackers to inject arbitrary web script or HTML via the (1) reportreason parameter in actions/doreport.php or (2) modnotes parameter in actions/updatereport.php.

    Published: 11 Jan 2018
    6.1
    Medium

    CVE-2012-6682

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in downloads/actions/editdownload.php in the DragonByte Technologies vBDownloads module 1.3.2 and earlier for vBulletin allows remote attackers to inject arbitrary web script or HTML via the mirrors[] parameter.

    Published: 11 Jan 2018
    8.8
    High

    CVE-2012-0699

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in Family Connections CMS (aka FCMS) 2.9 and earlier allow remote attackers to hijack the authentication of arbitrary users for requests that (1) add news via an add action to familynews.php or (2) add a prayer via an add action to prayers.php.

    Published: 11 Jan 2018
    6.1
    Medium

    CVE-2018-1361

    Last Modified: 21 Nov 2024

    IBM WebSphere Portal 8.5 and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 137158.

    Published: 11 Jan 2018
    5.4
    Medium

    CVE-2017-1739

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, and 7.0.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134921.

    Published: 11 Jan 2018
    3.3
    Low

    CVE-2017-1478

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 9.0.0 allows web pages to be stored locally which can be read by another user on the system. IBM X-Force ID: 128613.

    Published: 11 Jan 2018
    3.3
    Low

    CVE-2017-1681

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server (IBM Liberty for Java for Bluemix 3.15) could allow a local attacker to obtain sensitive information, caused by improper handling of application requests, which could allow unauthorized access to read a file. IBM X-Force ID: 134003.

    Published: 11 Jan 2018
    5.4
    Medium

    CVE-2017-1740

    Last Modified: 21 Nov 2024

    IBM Curam Social Program Management 6.0.5, 6.1.1, 6.2.0, 7.0.1, and 7.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134922.

    Published: 11 Jan 2018
    6.1
    Medium

    CVE-2012-6667

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in vbshout.php in DragonByte Technologies vBShout module for vBulletin allows remote attackers to inject arbitrary web script or HTML via the shout parameter in a shout action.

    Published: 11 Jan 2018
    7.5
    High

    CVE-2014-5068

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the web application in Symmetricom s350i 2.70.15 allows remote attackers to read arbitrary files via a (1) ../ (dot dot slash) or (2) ..\ (dot dot forward slash) before a file name.

    Published: 11 Jan 2018
    8.8
    High

    CVE-2014-5070

    Last Modified: 21 Nov 2024

    Symmetricom s350i 2.70.15 allows remote authenticated users to gain privileges via vectors related to pushing unauthenticated users to the login page.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15614

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-outif variable in the pptp_client.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15617

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the iface variable in the interface_wan.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15618

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_client.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15619

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the pptphellointerval variable in the pptp_client.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15623

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-enable variable in the pptp_server.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15626

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-bindif variable in the pptp_server.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15627

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-pns variable in the pptp_client.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15628

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the lcpechointerval variable in the pptp_server.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15630

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-remotesubnet variable in the pptp_client.lua file.

    Published: 11 Jan 2018
    7.2
    High

    CVE-2017-15631

    Last Modified: 21 Nov 2024

    TP-Link WVR, WAR and ER devices allow remote authenticated administrators to execute arbitrary commands via command injection in the new-workmode variable in the pptp_client.lua file.

    Published: 11 Jan 2018