| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-17918 | Cri | 0.64 | 9.8 | 0.04 | Nov 2, 2018 | Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page. | ||
| CVE-2018-17916 | Cri | 0.64 | 9.8 | 0.04 | Nov 2, 2018 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related… | ||
| CVE-2018-17914 | Cri | 0.64 | 9.8 | 0.05 | Nov 2, 2018 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or… | ||
| CVE-2018-6908 | Cri | 0.64 | 9.8 | 0.02 | Nov 1, 2018 | An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as… | ||
| CVE-2018-6012 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2018 | The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function. | ||
| CVE-2018-18892 | Cri | 0.64 | 9.8 | 0.03 | Nov 1, 2018 | MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php. | ||
| CVE-2018-18888 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2018 | An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed. | ||
| CVE-2018-18887 | Cri | 0.64 | 9.8 | 0.01 | Nov 1, 2018 | S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field). | ||
| CVE-2018-16840 | Cri | 0.64 | 9.8 | 0.03 | Oct 31, 2018 | A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and… | ||
| CVE-2018-18874 | Cri | 0.64 | 9.8 | 0.02 | Oct 31, 2018 | nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI. | ||
| CVE-2018-18869 | Cri | 0.64 | 9.8 | 0.04 | Oct 31, 2018 | EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter. | ||
| CVE-2018-8858 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2018 | If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to extract credentials. | ||
| CVE-2018-16462 | Cri | 0.66 | 10.0 | 0.07 | Oct 30, 2018 | A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument. | ||
| CVE-2018-16461 | Cri | 0.64 | 9.8 | 0.04 | Oct 30, 2018 | A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options. | ||
| CVE-2017-8931 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2018 | Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors. | ||
| CVE-2018-14558 | Cri | 0.76 | 9.8 | 0.09 | KEV | Oct 30, 2018 | An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute… | |
| CVE-2018-18835 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2018 | upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file. | ||
| CVE-2018-18834 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2018 | An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c. | ||
| CVE-2018-18832 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2018 | admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp. | ||
| CVE-2018-18830 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2018 | An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename,… | ||
| CVE-2018-18822 | Cri | 0.64 | 9.8 | 0.02 | Oct 30, 2018 | Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter. | ||
| CVE-2018-18792 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie. | ||
| CVE-2018-18791 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie. | ||
| CVE-2018-18789 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php. | ||
| CVE-2018-18787 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie. | ||
| CVE-2018-18786 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie. | ||
| CVE-2018-18785 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php. | ||
| CVE-2018-18765 | Cri | 0.59 | 9.1 | 0.02 | Oct 29, 2018 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in mg_mqtt_next_subscribe_topic. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory… | ||
| CVE-2018-18764 | Cri | 0.59 | 9.1 | 0.02 | Oct 29, 2018 | An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in a parse_mqtt getu16 call. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory… | ||
| CVE-2018-18754 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file. | ||
| CVE-2018-18753 | Cri | 0.64 | 9.8 | 0.03 | Oct 29, 2018 | Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF. | ||
| CVE-2018-18752 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter. | ||
| CVE-2018-18751 | Cri | 0.64 | 9.8 | 0.04 | Oct 29, 2018 | An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt. | ||
| CVE-2018-18748 | Cri | 0.65 | 10.0 | 0.02 | Oct 29, 2018 | Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's intended functionality | ||
| CVE-2018-18729 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the… | ||
| CVE-2018-18728 | Cri | 0.64 | 9.8 | 0.03 | Oct 29, 2018 | An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request. | ||
| CVE-2018-18705 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php. | ||
| CVE-2018-18704 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter. | ||
| CVE-2018-18702 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion. | ||
| CVE-2016-10734 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php. | ||
| CVE-2016-10733 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string. | ||
| CVE-2016-10732 | Cri | 0.64 | 9.8 | 0.02 | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php. | ||
| CVE-2016-10731 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2018 | ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status,… | ||
| CVE-2018-8955 | Cri | 0.64 | 9.8 | 0.04 | Oct 24, 2018 | The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged. | ||
| CVE-2018-17903 | Cri | 0.59 | 9.1 | 0.02 | Oct 24, 2018 | SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery. | ||
| CVE-2018-15751 | Cri | 0.57 | 9.8 | 0.05 | Oct 24, 2018 | SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi). | ||
| CVE-2018-13342 | Cri | 0.64 | 9.8 | 0.01 | Oct 24, 2018 | The server API in the Anda app relies on hardcoded credentials. | ||
| CVE-2018-18476 | Cri | 0.57 | 9.8 | 0.02 | Oct 24, 2018 | mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns. | ||
| CVE-2018-11792 | Cri | 0.64 | 9.8 | 0.02 | Oct 24, 2018 | In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically… | ||
| CVE-2018-18475 | Cri | 0.65 | 9.8 | 0.20 | Oct 23, 2018 | Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload. |
- risk 0.64cvss 9.8epss 0.04
Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.
- risk 0.64cvss 9.8epss 0.04
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related…
- risk 0.64cvss 9.8epss 0.05
InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or…
- risk 0.64cvss 9.8epss 0.02
An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as…
- risk 0.64cvss 9.8epss 0.01
The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.
- risk 0.64cvss 9.8epss 0.03
MiniCMS 1.10 allows execution of arbitrary PHP code via the install.php sitename parameter, which affects the site_name field in mc_conf.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in laravelCMS through 2018-04-02. \app\Http\Controllers\Backend\ProfileController.php allows upload of arbitrary PHP files because the file extension is not properly checked and uploaded files are not properly renamed.
- risk 0.64cvss 9.8epss 0.01
S-CMS PHP 1.0 has SQL injection in member/member_news.php via the type parameter (aka the $N_type field).
- risk 0.64cvss 9.8epss 0.03
A heap use-after-free flaw was found in curl versions from 7.59.0 through 7.61.1 in the code related to closing an easy handle. When closing and cleaning up an 'easy' handle in the `Curl_close()` function, the library code first frees a struct (without nulling the pointer) and…
- risk 0.64cvss 9.8epss 0.02
nc-cms through 2017-03-10 allows remote attackers to execute arbitrary PHP code via the "Upload File or Image" feature, with a .php filename and "Content-Type: application/octet-stream" to the index.php?action=file_manager_upload URI.
- risk 0.64cvss 9.8epss 0.04
EmpireCMS V7.5 allows remote attackers to upload and execute arbitrary code via ..%2F directory traversal in a .php filename in the upload/e/admin/ecmscom.php path parameter.
- risk 0.64cvss 9.8epss 0.01
If an attacker has access to the firmware from the VGo Robot (Versions 3.0.3.52164 and 3.0.3.53662. Prior versions may also be affected) they may be able to extract credentials.
- risk 0.66cvss 10.0epss 0.07
A command injection vulnerability in the apex-publish-static-files npm module version <2.0.1 which allows arbitrary shell command execution through a maliciously crafted argument.
- risk 0.64cvss 9.8epss 0.04
A command injection vulnerability in libnmapp package for versions <0.4.16 allows arbitrary commands to be executed via arguments to the range options.
- risk 0.64cvss 9.8epss 0.02
Bitdefender GravityZone VMware appliance before 6.2.1-35 might allow attackers to gain access with root privileges via unspecified vectors.
- risk 0.76cvss 9.8epss 0.09
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06.23_CN(AC10). A command Injection vulnerability allows attackers to execute…
- risk 0.64cvss 9.8epss 0.02
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
- risk 0.64cvss 9.8epss 0.02
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.
- risk 0.64cvss 9.8epss 0.01
admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename,…
- risk 0.64cvss 9.8epss 0.02
Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs_list.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.02
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/search.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zt/top.php via a Host HTTP header to zt/news.php.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in ajax/zs.php via a pxzs cookie.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in zzcms 8.3. SQL Injection exists in zs/subzs.php with a zzcmscpid cookie to zs/search.php.
- risk 0.59cvss 9.1epss 0.02
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in mg_mqtt_next_subscribe_topic. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory…
- risk 0.59cvss 9.1epss 0.02
An exploitable arbitrary memory read vulnerability exists in the MQTT packet-parsing functionality of Cesanta Mongoose 6.13. It is a heap-based buffer over-read in a parse_mqtt getu16 call. A specially crafted MQTT SUBSCRIBE packet can cause an arbitrary out-of-bounds memory…
- risk 0.64cvss 9.8epss 0.01
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
- risk 0.64cvss 9.8epss 0.03
Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.
- risk 0.64cvss 9.8epss 0.02
Webiness Inventory 2.3 suffers from an Arbitrary File upload vulnerability via PHP code in the protected/library/ajax/WsSaveToModel.php logo parameter.
- risk 0.64cvss 9.8epss 0.04
An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.
- risk 0.65cvss 10.0epss 0.02
Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's intended functionality
- risk 0.64cvss 9.8epss 0.01
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the…
- risk 0.64cvss 9.8epss 0.03
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.
- risk 0.64cvss 9.8epss 0.02
PhpTpoint hospital management system suffers from multiple SQL injection vulnerabilities via the index.php user parameter associated with LOGIN.php, or the rno parameter to ALIST.php, DUNDEL.php, PDEL.php, or PUNDEL.php.
- risk 0.64cvss 9.8epss 0.02
PhpTpoint Pharmacy Management System suffers from a SQL injection vulnerability in the index.php username parameter.
- risk 0.64cvss 9.8epss 0.01
spider.admincp.php in iCMS v7.0.11 allows SQL injection via admincp.php?app=spider&do=import_rule because the upfile content is base64 decoded, deserialized, and used for database insertion.
- risk 0.64cvss 9.8epss 0.02
ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.
- risk 0.64cvss 9.8epss 0.02
ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.
- risk 0.64cvss 9.8epss 0.02
ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.
- risk 0.64cvss 9.8epss 0.01
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status,…
- risk 0.64cvss 9.8epss 0.04
The installer for BitDefender GravityZone relies on an encoded string in a filename to determine the URL for installation metadata, which allows remote attackers to execute arbitrary code by changing the filename while leaving the file's digital signature unchanged.
- risk 0.59cvss 9.1epss 0.02
SAGA1-L8B with any firmware versions prior to A0.10 are vulnerable to a replay attack and command forgery.
- risk 0.57cvss 9.8epss 0.05
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
- risk 0.64cvss 9.8epss 0.01
The server API in the Anda app relies on hardcoded credentials.
- risk 0.57cvss 9.8epss 0.02
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
- risk 0.64cvss 9.8epss 0.02
In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically…
- risk 0.65cvss 9.8epss 0.20
Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.