CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2018-5311

    Last Modified: 21 Nov 2024

    The Easy Custom Auto Excerpt plugin 2.4.6 for WordPress has XSS via the tonjoo_ecae_options[custom_css] parameter to the wp-admin/admin.php?page=tonjoo_excerpt URI.

    Published: 9 Jan 2018
    5.4
    Medium

    CVE-2018-5312

    Last Modified: 21 Nov 2024

    The tabs-responsive plugin 1.8.0 for WordPress has XSS via the post_title parameter to wp-admin/post.php.

    Published: 9 Jan 2018
    9.8
    Critical

    CVE-2017-18025

    Last Modified: 21 Nov 2024

    cgi-bin/drknow.cgi in Innotube ITGuard-Manager 0.0.0.1 allows remote attackers to execute arbitrary OS commands via shell metacharacters in the username field, as demonstrated by a username beginning with "admin|" to use the '|' metacharacter.

    Published: 9 Jan 2018
    7.5
    High

    CVE-2017-15132

    Last Modified: 21 Nov 2024

    A flaw was found in dovecot 2.0 up to 2.2.33 and 2.3.0. An abort of SASL authentication results in a memory leak in dovecot's auth client used by login processes. The leak has impact in high performance configuration where same login processes are reused and can cause the process to crash due to memory exhaustion.

    Published: 9 Jan 2018
    7.5
    High

    CVE-2018-4871

    Last Modified: 21 Nov 2024

    An Out-of-bounds Read issue was discovered in Adobe Flash Player before 28.0.0.137. This vulnerability occurs because of computation that reads data that is past the end of the target buffer. The use of an invalid (out-of-range) pointer offset during access of internal data structure fields causes the vulnerability. A successful attack can lead to sensitive data exposure.

    Published: 9 Jan 2018
    5.4
    Medium

    CVE-2018-5263

    Last Modified: 21 Nov 2024

    The StackIdeas EasyDiscuss (aka com_easydiscuss) extension before 4.0.21 for Joomla! allows XSS.

    Published: 8 Jan 2018
    6.5
    Medium

    CVE-2018-5301

    Last Modified: 21 Nov 2024

    Magento Community Edition and Enterprise Edition before 2.0.10 and 2.1.x before 2.1.2 have CSRF resulting in deletion of a customer address from an address book, aka APPSEC-1433.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2012-3353

    Last Modified: 21 Nov 2024

    The Apache Sling JCR ContentLoader 2.1.4 XmlReader used in the Sling JCR content loader module makes it possible to import arbitrary files in the content repository, including local files, causing potential information leaks. Users should upgrade to version 2.1.6 of the JCR ContentLoader

    Published: 8 Jan 2018
    6.5
    Medium

    CVE-2014-7221

    Last Modified: 21 Nov 2024

    TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (buffer overflow and application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab containing [img]//http:// substrings.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2017-15883

    Last Modified: 21 Nov 2024

    Sitefinity 5.1, 5.2, 5.3, 5.4, 6.x, 7.x, 8.x, 9.x, and 10.x allow remote attackers to bypass authentication and consequently cause a denial of service on load balanced sites or gain privileges via vectors related to weak cryptography.

    Published: 8 Jan 2018
    7.1
    High

    CVE-2014-2071

    Last Modified: 21 Nov 2024

    Aruba Networks ClearPass Policy Manager 6.1.x, 6.2.x before 6.2.5.61640 and 6.3.x before 6.3.0.61712, when configured to use tunneled and non-tunneled EAP methods in a single policy construct, allows remote authenticated users to gain privileges by advertising independent inner and outer identities within a tunneled EAP method.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2014-5334

    Last Modified: 21 Nov 2024

    FreeNAS before 9.3-M3 has a blank admin password, which allows remote attackers to gain root privileges by leveraging a WebGui login.

    Published: 8 Jan 2018
    5.9
    Medium

    CVE-2014-5394

    Last Modified: 21 Nov 2024

    Multiple Huawei Campus switches allow remote attackers to enumerate usernames via vectors involving use of SSH by the maintenance terminal.

    Published: 8 Jan 2018
    6.5
    Medium

    CVE-2014-7222

    Last Modified: 21 Nov 2024

    Buffer overflow in TeamSpeak Client 3.0.14 and earlier allows remote authenticated users to cause a denial of service (application crash) by connecting to a channel with a different client instance, and placing crafted data in the Chat/Server tab with two \\ (backslash) characters, a digit, a \ (backslash) character, and "z" in a series of nested img BBCODE tags.

    Published: 8 Jan 2018
    8.1
    High

    CVE-2015-2318

    Last Modified: 21 Nov 2024

    The TLS stack in Mono before 3.12.1 allows man-in-the-middle attackers to conduct message skipping attacks and consequently impersonate clients by leveraging missing handshake state validation, aka a "SMACK SKIP-TLS" issue.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2014-4972

    Last Modified: 21 Nov 2024

    Unrestricted file upload vulnerability in the Gravity Upload Ajax plugin 1.1 and earlier for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via a direct request to the file under wp-content/uploads/gravity_forms.

    Published: 8 Jan 2018
    6.1
    Medium

    CVE-2014-5069

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Symmetricom s350i 2.70.15 allows remote attackers to inject arbitrary web script or HTML via vectors involving system logs.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2014-5071

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the checkPassword function in Symmetricom s350i 2.70.15 allows remote attackers to execute arbitrary SQL commands via vectors involving a username.

    Published: 8 Jan 2018
    5.5
    Medium

    CVE-2014-5509

    Last Modified: 21 Nov 2024

    clipedit in the Clipboard module for Perl allows local users to delete arbitrary files via a symlink attack on /tmp/clipedit$$.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2015-2319

    Last Modified: 21 Nov 2024

    The TLS stack in Mono before 3.12.1 makes it easier for remote attackers to conduct cipher-downgrade attacks to EXPORT_RSA ciphers via crafted TLS traffic, related to the "FREAK" issue, a different vulnerability than CVE-2015-0204.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2015-2320

    Last Modified: 21 Nov 2024

    The TLS stack in Mono before 3.12.1 allows remote attackers to have unspecified impact via vectors related to client-side SSLv2 fallback.

    Published: 8 Jan 2018
    9.8
    Critical

    CVE-2017-7997

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Gespage before 7.4.9 allow remote attackers to execute arbitrary SQL commands via the (1) show_prn parameter to webapp/users/prnow.jsp or show_month parameter to (2) webapp/users/blhistory.jsp or (3) webapp/users/prhistory.jsp.

    Published: 8 Jan 2018
    6.1
    Medium

    CVE-2017-7998

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Gespage before 7.4.9 allow remote attackers to inject arbitrary web script or HTML via the (1) printer name when adding a printer in the admin panel or (2) username parameter to webapp/users/user_reg.jsp.

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5282

    Last Modified: 19 Dec 2025

    Kentico 9.0 through 11.0 has a stack-based buffer overflow via the SqlName, SqlPswd, Database, UserName, or Password field in a SilentInstall XML document. NOTE: the vendor disputes this issue because neither a buffer overflow nor a crash can be reproduced; also, reading XML documents is implemented exclusively with managed code within the Microsoft .NET Framework

    Published: 8 Jan 2018
    8.8
    High

    CVE-2018-5259

    Last Modified: 21 Nov 2024

    Discuz! DiscuzX X3.4 allows remote authenticated users to bypass intended attachment-deletion restrictions via a modified aid parameter.

    Published: 8 Jan 2018
    5.4
    Medium

    CVE-2018-5280

    Last Modified: 21 Nov 2024

    SonicWall SonicOS on Network Security Appliance (NSA) 2016 Q4 devices has XSS via the Configure SSO screens.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5283

    Last Modified: 21 Nov 2024

    The Photos in Wifi application 1.0.1 for iOS has directory traversal via the ext parameter to assets-library://asset/asset.php.

    Published: 8 Jan 2018
    5.4
    Medium

    CVE-2018-5281

    Last Modified: 21 Nov 2024

    SonicWall SonicOS on Network Security Appliance (NSA) 2017 Q4 devices has XSS via the CFS Custom Category and Cloud AV DB Exclusion Settings screens.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5298

    Last Modified: 21 Nov 2024

    In the Procter & Gamble "Oral-B App" (aka com.pg.oralb.oralbapp) application 5.0.0 for Android, AES encryption with static parameters is used to secure the locally stored shared preferences. An attacker can gain access to locally stored user data more easily by leveraging access to the preferences XML file.

    Published: 8 Jan 2018
    4.8
    Medium

    CVE-2018-5284

    Last Modified: 21 Nov 2024

    The ImageInject plugin 1.15 for WordPress has XSS via the flickr_appid parameter to wp-admin/options-general.php.

    Published: 8 Jan 2018
    8.8
    High

    CVE-2018-5285

    Last Modified: 21 Nov 2024

    The ImageInject plugin 1.15 for WordPress has CSRF via wp-admin/options-general.php.

    Published: 8 Jan 2018
    6.1
    Medium

    CVE-2018-5286

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-about page.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5290

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5291

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.

    Published: 8 Jan 2018
    6.1
    Medium

    CVE-2018-5292

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-information page.

    Published: 8 Jan 2018
    6.1
    Medium

    CVE-2018-5293

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-tools page.

    Published: 8 Jan 2018
    6.5
    Medium

    CVE-2018-5294

    Last Modified: 21 Nov 2024

    In libming 0.4.8, there is an integer overflow (caused by an out-of-range left shift) in the readUInt32 function (util/read.c). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted swf file.

    Published: 8 Jan 2018
    5.5
    Medium

    CVE-2018-5295

    Last Modified: 21 Nov 2024

    In PoDoFo 0.9.5, there is an integer overflow in the PdfXRefStreamParserObject::ParseStream function (base/PdfXRefStreamParserObject.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5287

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-about page.

    Published: 8 Jan 2018
    6.1
    Medium

    CVE-2018-5288

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has XSS via the wp-admin/admin.php panel parameter for the gd-rating-system-transfer page.

    Published: 8 Jan 2018
    5.5
    Medium

    CVE-2018-5296

    Last Modified: 21 Nov 2024

    In PoDoFo 0.9.5, there is an uncontrolled memory allocation in the PdfParser::ReadXRefSubsection function (base/PdfParser.cpp). Remote attackers could leverage this vulnerability to cause a denial-of-service via a crafted pdf file.

    Published: 8 Jan 2018
    7.5
    High

    CVE-2018-5289

    Last Modified: 21 Nov 2024

    The GD Rating System plugin 2.3 for WordPress has Directory Traversal in the wp-admin/admin.php panel parameter for the gd-rating-system-information page.

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5270

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e010. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5271

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e008. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5272

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e004. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5273

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e014. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5274

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9C40E024. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    3.3
    Low

    CVE-2018-5278

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e00c. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018
    5.7
    Medium

    CVE-2018-3815

    Last Modified: 21 Nov 2024

    The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The attack uses an HTTP POST request to a /Session URI, and interchanges the XML From and To elements.

    Published: 8 Jan 2018
    7.8
    High

    CVE-2018-5277

    Last Modified: 21 Nov 2024

    In Malwarebytes Premium 3.3.1.2183, the driver file (FARFLT.SYS) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x9c40e000. NOTE: the vendor reported that they "have not been able to reproduce the issue on any Windows operating system version (32-bit or 64-bit).

    Published: 8 Jan 2018