Search Results (324375 CVEs found)

CVE Vendors Products Updated CVSS v3.1
CVE-2018-10058 2 Bfgminer, Cgminer Project 2 Bfgminer, Cgminer 2024-11-21 N/A
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to execute arbitrary code due to a stack-based buffer overflow in the addpool, failover-only, poolquota, and save command handlers.
CVE-2018-10057 2 Bfgminer, Cgminer Project 2 Bfgminer, Cgminer 2024-11-21 N/A
The remote management interface of cgminer 4.10.0 and bfgminer 5.5.0 allows an authenticated remote attacker to write the miner configuration file to arbitrary locations on the server due to missing basedir restrictions (absolute directory traversal).
CVE-2018-10055 1 Google 1 Tensorflow 2024-11-21 N/A
Invalid memory access and/or a heap buffer overflow in the TensorFlow XLA compiler in Google TensorFlow before 1.7.1 could cause a crash or read from other parts of process memory via a crafted configuration file.
CVE-2018-10054 2 Cognitect, H2database 2 Datomic, H2 2024-11-21 8.8 High
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
CVE-2018-10052 1 Iscripts 1 Supportdesk 2024-11-21 N/A
iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter.
CVE-2018-10051 1 Iscripts 1 Supportdesk 2024-11-21 N/A
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.
CVE-2018-10050 1 Iscripts 1 Eswap 2024-11-21 N/A
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
CVE-2018-10049 1 Iscripts 1 Eswap 2024-11-21 N/A
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
CVE-2018-10048 1 Iscripts 1 Eswap 2024-11-21 N/A
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
CVE-2018-10033 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
CVE-2018-10032 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
CVE-2018-10031 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
CVE-2018-10030 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/siteprefs.php.
CVE-2018-10029 1 Cmsmadesimple 1 Cms Made Simple 2024-11-21 N/A
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
CVE-2018-10028 1 Joyplus-cms Project 1 Joyplus-cms 2024-11-21 N/A
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
CVE-2018-10027 1 Estsoft 1 Alzip 2024-11-21 N/A
ESTsoft ALZip before 10.76 allows local users to execute arbitrary code via creating a malicious .DLL file and installing it in a specific directory: %PROGRAMFILES%\ESTsoft\ALZip\Formats, %PROGRAMFILES%\ESTsoft\ALZip\Coders, %PROGRAMFILES(X86)%\ESTsoft\ALZip\Formats, or %PROGRAMFILES(X86)%\ESTsoft\ALZip\Coders.
CVE-2018-10026 1 Yzmcms 1 Yzmcms 2024-11-21 N/A
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
CVE-2018-10024 1 Ubiquoss 2 Vp5208a, Vp5208a Firmware 2024-11-21 N/A
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credentials can be used to access the system via SSH (or TELNET if it is enabled).
CVE-2018-10023 1 Catfish-cms 1 Catfish Cms 2024-11-21 N/A
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
CVE-2018-10021 1 Linux 1 Linux Kernel 2024-11-21 0.0 Low
drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata qc leak) by triggering certain failure conditions. NOTE: a third party disputes the relevance of this report because the failure can only occur for physically proximate attackers who unplug SAS Host Bus Adapter cables