| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-11736 | Cri | 0.60 | 9.8 | 0.09 | Jun 5, 2018 | An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file. | ||
| CVE-2017-16042 | Cri | 0.57 | 9.8 | 0.04 | Jun 4, 2018 | Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution. | ||
| CVE-2017-16020 | Cri | 0.64 | 9.8 | 0.03 | Jun 4, 2018 | Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name. | ||
| CVE-2018-11714 | Cri | 0.69 | 9.8 | 0.68 | Jun 4, 2018 | An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker… | ||
| CVE-2018-10611 | Cri | 0.64 | 9.8 | 0.05 | Jun 4, 2018 | Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services. | ||
| CVE-2018-11711 | Cri | 0.64 | 9.8 | 0.05 | Jun 4, 2018 | A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a… | ||
| CVE-2018-11692 | Cri | 0.64 | 9.8 | 0.04 | Jun 4, 2018 | An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a… | ||
| CVE-2018-11682 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2018 | Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a… | ||
| CVE-2018-11681 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2018 | Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id… | ||
| CVE-2018-11629 | Cri | 0.64 | 9.8 | 0.04 | Jun 2, 2018 | Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor… | ||
| CVE-2018-11143 | Cri | 0.67 | 9.8 | 0.37 | Jun 2, 2018 | Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46). | ||
| CVE-2018-3757 | Cri | 0.57 | 9.8 | 0.05 | Jun 1, 2018 | Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter. | ||
| CVE-2018-3746 | Cri | 0.57 | 9.8 | 0.05 | Jun 1, 2018 | The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine. | ||
| CVE-2018-11652 | Cri | 0.69 | 9.8 | 0.24 | Jun 1, 2018 | CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report. | ||
| CVE-2016-10554 | Cri | 0.57 | 9.8 | 0.02 | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping, even though SQLite… | ||
| CVE-2016-10553 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier. | ||
| CVE-2016-10550 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2018 | sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements.… | ||
| CVE-2016-10546 | Cri | 0.64 | 9.8 | 0.03 | May 31, 2018 | An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed and may be used to run arbitrary JavaScript as well as… | ||
| CVE-2016-10541 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2018 | The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection. | ||
| CVE-2016-10532 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2018 | console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if… | ||
| CVE-2018-11141 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2018 | The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the… | ||
| CVE-2018-11140 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type). | ||
| CVE-2018-11138 | Cri | 0.92 | 9.8 | 0.92 | KEV | May 31, 2018 | The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system. | |
| CVE-2018-11136 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type). | ||
| CVE-2018-9318 | Cri | 0.64 | 9.8 | 0.04 | May 31, 2018 | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network. | ||
| CVE-2018-9311 | Cri | 0.64 | 9.8 | 0.04 | May 31, 2018 | The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network. | ||
| CVE-2018-11036 | Cri | 0.59 | 9.1 | 0.01 | May 31, 2018 | Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information or modify data. | ||
| CVE-2018-11576 | Cri | 0.64 | 9.8 | 0.01 | May 31, 2018 | ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor. | ||
| CVE-2018-11575 | Cri | 0.64 | 9.8 | 0.02 | May 31, 2018 | ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg. | ||
| CVE-2018-11482 | Cri | 0.64 | 9.8 | 0.01 | May 30, 2018 | /usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password. | ||
| CVE-2018-11547 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination. | ||
| CVE-2018-11546 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error. | ||
| CVE-2018-11545 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes. | ||
| CVE-2018-11544 | Cri | 0.64 | 9.8 | 0.01 | May 29, 2018 | The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings. | ||
| CVE-2018-3745 | Cri | 0.59 | 9.1 | 0.02 | May 29, 2018 | atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below. | ||
| CVE-2018-3744 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL. | ||
| CVE-2018-10466 | Cri | 0.65 | 9.8 | 0.17 | May 29, 2018 | Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection. | ||
| CVE-2016-10551 | Cri | 0.57 | 9.8 | 0.02 | May 29, 2018 | waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their… | ||
| CVE-2016-10525 | Cri | 0.57 | 9.8 | 0.02 | May 29, 2018 | When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication. | ||
| CVE-2015-9244 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection. | ||
| CVE-2015-9235 | Cri | 0.57 | 9.8 | 0.09 | May 29, 2018 | In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family). | ||
| CVE-2018-1235 | Cri | 0.70 | 9.8 | 0.42 | May 29, 2018 | Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with… | ||
| CVE-2018-5241 | Cri | 0.64 | 9.8 | 0.05 | May 29, 2018 | Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercepted proxy traffic. When… | ||
| CVE-2018-11536 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits. | ||
| CVE-2018-11535 | Cri | 0.67 | 9.8 | 0.03 | May 29, 2018 | An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection. | ||
| CVE-2018-11531 | Cri | 0.64 | 9.8 | 0.03 | May 29, 2018 | Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp. | ||
| CVE-2018-11528 | Cri | 0.64 | 9.8 | 0.02 | May 29, 2018 | WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI. | ||
| CVE-2018-11523 | Cri | 0.67 | 9.8 | 0.09 | May 29, 2018 | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. | ||
| CVE-2018-11309 | Cri | 0.64 | 9.8 | 0.02 | May 28, 2018 | Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request. | ||
| CVE-2018-11515 | Cri | 0.64 | 9.8 | 0.02 | May 28, 2018 | The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter. |
- risk 0.60cvss 9.8epss 0.09
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
- risk 0.57cvss 9.8epss 0.04
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution.
- risk 0.64cvss 9.8epss 0.03
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name.
- risk 0.69cvss 9.8epss 0.68
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused by improper session handling on the /cgi/ folder or a /cgi file. If an attacker…
- risk 0.64cvss 9.8epss 0.05
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and support remote code execution through web services.
- risk 0.64cvss 9.8epss 0.05
A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors involving /portal_top.html to get full access to the device. NOTE: the vendor reportedly responded that this issue occurs when a…
- risk 0.64cvss 9.8epss 0.04
An issue was discovered on Canon LBP6650, LBP3370, LBP3460, and LBP7750C devices. It is possible to bypass the Administrator Mode authentication for /tlogin.cgi via vectors involving frame.cgi?page=DevStatus. NOTE: the vendor reportedly responded that this issue occurs when a…
- risk 0.64cvss 9.8epss 0.04
Default and unremovable support credentials allow attackers to gain total super user control of an IoT device through a TELNET session to products using the Stanza Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id as not being a…
- risk 0.64cvss 9.8epss 0.04
Default and unremovable support credentials (user:nwk password:nwk2) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the RadioRA 2 Lutron integration protocol Revision M to Revision Y. NOTE: The vendor disputes this id…
- risk 0.64cvss 9.8epss 0.04
Default and unremovable support credentials (user:lutron password:integration) allow attackers to gain total super user control of an IoT device through a TELNET session to products using the HomeWorks QS Lutron integration protocol Revision M to Revision Y. NOTE: The vendor…
- risk 0.67cvss 9.8epss 0.37
Quest DR Series Disk Backup software version before 4.0.3.1 allows command injection (issue 1 of 46).
- risk 0.57cvss 9.8epss 0.05
Command injection exists in pdf-image v2.0.0 due to an unescaped string parameter.
- risk 0.57cvss 9.8epss 0.05
The pdfinfojs NPM module versions <= 0.3.6 has a command injection vulnerability that allows an attacker to execute arbitrary commands on the victim's machine.
- risk 0.69cvss 9.8epss 0.24
CSV Injection vulnerability in Nikto 2.1.6 and earlier allows remote attackers to inject arbitrary OS commands via the Server field in an HTTP response header, which is directly injected into a CSV report.
- risk 0.57cvss 9.8epss 0.02
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. Before version 1.7.0-alpha3, sequelize defaulted SQLite to use MySQL backslash escaping, even though SQLite…
- risk 0.64cvss 9.8epss 0.01
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS. A fix was pushed out that fixed potential SQL injection in sequelize 2.1.3 and earlier.
- risk 0.64cvss 9.8epss 0.02
sequelize is an Object-relational mapping, or a middleman to convert things from Postgres, MySQL, MariaDB, SQLite and Microsoft SQL Server into usable data for NodeJS If user input goes into the `limit` or `order` parameters, a malicious user can put in their own SQL statements.…
- risk 0.64cvss 9.8epss 0.03
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed and may be used to run arbitrary JavaScript as well as…
- risk 0.64cvss 9.8epss 0.02
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.
- risk 0.64cvss 9.8epss 0.02
console-io is a module that allows users to implement a web console in their application. A malicious user could bypass the authentication and execute any command that the user who is running the console-io application 2.2.13 and earlier is able to run. This means that if…
- risk 0.64cvss 9.8epss 0.02
The 'IMAGES_JSON' and 'attachments_to_remove[]' parameters of the '/adminui/advisory.php' script in the Quest KACE System Management Virtual Appliance 8.0.318 can be abused to write and delete files respectively via Directory Traversal. Files can be at any location where the…
- risk 0.64cvss 9.8epss 0.01
The 'reportID' parameter received by the '/common/run_report.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, an error-based type).
- risk 0.92cvss 9.8epss 0.92
The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.
- risk 0.64cvss 9.8epss 0.01
The 'orgID' parameter received by the '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is not sanitized, leading to SQL injection (in particular, a blind time-based type).
- risk 0.64cvss 9.8epss 0.04
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network.
- risk 0.64cvss 9.8epss 0.04
The Telematics Control Unit (aka Telematic Communication Box or TCB), when present on BMW vehicles produced in 2012 through 2018, allows a remote attack via a cellular network.
- risk 0.59cvss 9.1epss 0.01
Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain sensitive information or modify data.
- risk 0.64cvss 9.8epss 0.01
ngiflib.c in MiniUPnP ngiflib 0.4 has a heap-based buffer over-read in GifIndexToTrueColor.
- risk 0.64cvss 9.8epss 0.02
ngiflib.c in MiniUPnP ngiflib 0.4 has a stack-based buffer overflow in DecodeGifImg.
- risk 0.64cvss 9.8epss 0.01
/usr/lib/lua/luci/websys.lua on TP-LINK IPC TL-IPC223(P)-6, TL-IPC323K-D, TL-IPC325(KP)-*, and TL-IPC40A-4 devices has a hardcoded zMiVw8Kw0oxKXL0 password.
- risk 0.64cvss 9.8epss 0.02
md_is_link_reference_definition_helper in md4c 0.2.5 has a heap-based buffer over-read because md_is_link_label mishandles loop termination.
- risk 0.64cvss 9.8epss 0.02
md4c 0.2.5 has a heap-based buffer over-read because md_is_named_entity_contents has an off-by-one error.
- risk 0.64cvss 9.8epss 0.02
md4c 0.2.5 has a heap-based buffer overflow in md_merge_lines because md_is_link_label mishandles the case of a link label composed solely of backslash escapes.
- risk 0.64cvss 9.8epss 0.01
The Olive Tree Ftp Server application 1.32 for Android has Insecure Data Storage because a username and password are stored in the /data/data/com.theolivetree.ftpserver/shared_prefs/com.theolivetree.ftpserver_preferences.xml file as the prefUsername and prefUserpass strings.
- risk 0.59cvss 9.1epss 0.02
atob 2.0.3 and earlier allocates uninitialized Buffers when number is passed in input on Node.js 4.x and below.
- risk 0.64cvss 9.8epss 0.02
The html-pages node module contains a path traversal vulnerabilities that allows an attacker to read any file from the server with cURL.
- risk 0.65cvss 9.8epss 0.17
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
- risk 0.57cvss 9.8epss 0.02
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their…
- risk 0.57cvss 9.8epss 0.02
When attempting to allow authentication mode `try` in hapi, hapi-auth-jwt2 version 5.1.1 introduced an issue whereby people could bypass authentication.
- risk 0.64cvss 9.8epss 0.02
Keys of objects in mysql node module v2.0.0-alpha7 and earlier are not escaped with `mysql.escape()` which could lead to SQL Injection.
- risk 0.57cvss 9.8epss 0.09
In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).
- risk 0.70cvss 9.8epss 0.42
Dell EMC RecoverPoint versions prior to 5.1.2 and RecoverPoint for VMs versions prior to 5.1.1.3, contain a command injection vulnerability. An unauthenticated remote attacker may potentially exploit this vulnerability to execute arbitrary commands on the affected system with…
- risk 0.64cvss 9.8epss 0.05
Symantec Advanced Secure Gateway (ASG) 6.6 and 6.7, and ProxySG 6.5, 6.6, and 6.7 are susceptible to a SAML authentication bypass vulnerability. The products can be configured with a SAML authentication realm to authenticate network users in intercepted proxy traffic. When…
- risk 0.64cvss 9.8epss 0.02
md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.
- risk 0.67cvss 9.8epss 0.03
An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.
- risk 0.64cvss 9.8epss 0.03
Exiv2 0.26 has a heap-based buffer overflow in getData in preview.cpp.
- risk 0.64cvss 9.8epss 0.02
WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.
- risk 0.67cvss 9.8epss 0.09
upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.
- risk 0.64cvss 9.8epss 0.02
Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.
- risk 0.64cvss 9.8epss 0.02
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.