Vulnerabilites CVE
Base de donnees CVE enrichie avec CISA KEV et NVD
| CVE ID | CVSS | Severite | KEV | Observations |
|---|---|---|---|---|
| CVE-2018-15959 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead ... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-15962 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a directory listing vulnerability. Successful exploitation could lead to information d... | 5.3 | MEDIUM | — | 0 |
| CVE-2018-15963 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a security bypass vulnerability. Successful exploitation could lead to arbitrary folde... | 5.3 | MEDIUM | — | 0 |
| CVE-2018-15964 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a use of a component with a known vulnerability vulnerability. Successful exploitation... | 7.5 | HIGH | — | 0 |
| CVE-2018-15965 Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have a deserialization of untrusted data vulnerability. Successful exploitation could lead ... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-18066 snmp_oid_compare in snmplib/snmp_api.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an unauthenticated attacker to remotely cause the instance to crash via a crafted UDP... | 7.5 | HIGH | — | 0 |
| CVE-2018-18984 Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest . | 4.6 | MEDIUM | — | 0 |
| CVE-2018-1000874 PHP cebe markdown parser version 1.2.0 and earlier contains a Cross Site Scripting (XSS) vulnerability in all distributed parsers allowing a malicious crafted script to be executed that can result in ... | 6.1 | MEDIUM | — | 0 |
| CVE-2018-19904 Persistent XSS exists in XSLT CMS via the create/?action=items.edit&type=Page "body" field. | 6.1 | MEDIUM | — | 0 |
| CVE-2018-19905 HTML injection exists in razorCMS 3.4.8 via the /#/page keywords parameter. | 5.4 | MEDIUM | — | 0 |
| CVE-2018-19906 Stored XSS exists in razorCMS 3.4.8 via the /#/page description parameter. | 5.4 | MEDIUM | — | 0 |
| CVE-2018-19918 CuppaCMS has XSS via an SVG document uploaded to the administrator/#/component/table_manager/view/cu_views URI. | 5.4 | MEDIUM | — | 0 |
| CVE-2018-20618 ok-file-formats through 2018-10-16 has a heap-based buffer over-read in the ok_mo_decode2 function in ok_mo.c. | 8.8 | HIGH | — | 0 |
| CVE-2018-18601 The TK_set_deviceModel_req_handle function in the cloud communication component in Guardzilla GZ621W devices with firmware 0.5.1.4 has a Buffer Overflow. | 8.1 | HIGH | — | 0 |
| CVE-2018-18602 The Cloud API on Guardzilla smart cameras allows user enumeration, with resultant arbitrary camera access and monitoring. | 9.8 | CRITICAL | — | 0 |
| CVE-2018-19937 A local, authenticated attacker can bypass the passcode in the VideoLAN VLC media player app before 3.1.5 for iOS by opening a URL and turning the phone. | 6.6 | MEDIUM | — | 0 |
| CVE-2018-20622 JasPer 2.0.14 has a memory leak in base/jas_malloc.c in libjasper.a when "--output-format jp2" is used. | 6.5 | MEDIUM | — | 0 |
| CVE-2018-20623 In GNU Binutils 2.31.1, there is a use-after-free in the error function in elfcomm.c when called from the process_archive function in readelf.c via a crafted ELF file. | 5.5 | MEDIUM | — | 0 |
| CVE-2021-39988 The HwNearbyMain module has a NULL Pointer Dereference vulnerability.Successful exploitation of this vulnerability may cause a process to restart. | 7.5 | HIGH | — | 0 |
| CVE-2018-6334 Multipart-file uploads call variables to be improperly registered in the global scope. In cases where variables are not declared explicitly before being used this can lead to unexpected behavior. This... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-6335 A Malformed h2 frame can cause 'std::out_of_range' exception when parsing priority meta data. This behavior can lead to denial-of-service. This affects all supported versions of HHVM (3.25.2, 3.24.6, ... | 7.5 | HIGH | — | 0 |
| CVE-2018-6336 An issue was discovered in osquery. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the... | 7.8 | HIGH | — | 0 |
| CVE-2018-6337 folly::secureRandom will re-use a buffer between parent and child processes when fork() is called. That will result in multiple forked children producing repeat (or similar) results. This affects HHVM... | 7.5 | HIGH | — | 0 |
| CVE-2018-6340 The Memcache::getextendedstats function can be used to trigger an out-of-bounds read. Exploiting this issue requires control over memcached server hostnames and/or ports. This affects all supported ve... | 8.1 | HIGH | — | 0 |
| CVE-2022-40879 kkFileView v4.1.0 is vulnerable to Cross Site Scripting (XSS) via the parameter 'errorMsg.' | 6.1 | MEDIUM | — | 0 |
| CVE-2018-6341 React applications which rendered to HTML using the ReactDOMServer API were not escaping user-supplied attribute names at render-time. That lack of escaping could lead to a cross-site scripting vulner... | 6.1 | MEDIUM | — | 0 |
| CVE-2018-6342 react-dev-utils on Windows allows developers to run a local webserver for accepting various commands, including a command to launch an editor. The input to that command was not properly sanitized, all... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-6343 Proxygen fails to validate that a secondary auth manager is set before dereferencing it. That can cause a denial of service issue when parsing a Certificate/CertificateRequest HTTP2 Frame over a fizz ... | 7.5 | HIGH | — | 0 |
| CVE-2018-6344 A heap corruption in WhatsApp can be caused by a malformed RTP packet being sent after a call is established. The vulnerability can be used to cause denial of service. It affects WhatsApp for Android ... | 7.5 | HIGH | — | 0 |
| CVE-2018-6346 A potential denial-of-service issue in the Proxygen handling of invalid HTTP2 priority settings (specifically a circular dependency). This affects Proxygen prior to v2018.12.31.00. | 7.5 | HIGH | — | 0 |
| CVE-2018-6347 An issue in the Proxygen handling of HTTP2 parsing of headers/trailers can lead to a denial-of-service attack. This affects Proxygen prior to v2018.12.31.00. | 7.5 | HIGH | — | 0 |
| CVE-2018-6333 The hhvm-attach deep link handler in Nuclide did not properly sanitize the provided hostname parameter when rendering. As a result, a malicious URL could be used to render HTML and other content insid... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-5733 A malicious client which is allowed to send very large amounts of traffic (billions of packets) to a DHCP server can eventually overflow a 32-bit reference counter, potentially causing dhcpd to crash.... | 7.5 | HIGH | — | 0 |
| CVE-2019-9107 XSS exists in WUZHI CMS 4.1.0 via index.php?m=attachment&f=imagecut&v=init&imgurl=[XSS] to coreframe/app/attachment/imagecut.php. | N/A | NONE | — | 0 |
| CVE-2019-9109 XSS exists in WUZHI CMS 4.1.0 via index.php?m=message&f=message&v=add&username=[XSS] to coreframe/app/message/message.php. | N/A | NONE | — | 0 |
| CVE-2019-9110 XSS exists in WUZHI CMS 4.1.0 via index.php?m=content&f=postinfo&v=listing&set_iframe=[XSS] to coreframe/app/content/postinfo.php. | N/A | NONE | — | 0 |
| CVE-2018-17425 WUZHI CMS 4.1.0 has stored XSS via the "Membership Center" "I want to ask" "detailed description" field under the index.php?m=member URI. | N/A | NONE | — | 0 |
| CVE-2018-17426 WUZHI CMS 4.1.0 has stored XSS via the "Extension module" "SMS in station" field under the index.php?m=core URI. | N/A | NONE | — | 0 |
| CVE-2019-0227 A Server Side Request Forgery (SSRF) vulnerability affected the Apache Axis 1.4 distribution that was last released in 2006. Security and bug commits commits continue in the projects Axis 1.x Subversi... | 7.5 | HIGH | — | 0 |
| CVE-2019-6538 The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D... | 9.3 | CRITICAL | — | 0 |
| CVE-2019-6540 The Conexus telemetry protocol utilized within Medtronic MyCareLink Monitor versions 24950 and 24952, CareLink Monitor version 2490C, CareLink 2090 Programmer, Amplia CRT-D, Claria CRT-D, Compia CRT-D... | 6.5 | MEDIUM | — | 0 |
| CVE-2019-3821 A flaw was found in the way civetweb frontend was handling requests for ceph RGW server with SSL enabled. An unauthenticated attacker could create multiple connections to ceph RADOS gateway to exhaust... | 7.5 | HIGH | — | 0 |
| CVE-2016-1585 In all versions of AppArmor mount rules are accidentally widened when compiled. | 9.8 | CRITICAL | — | 0 |
| CVE-2019-0905 A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrar... | 7.8 | HIGH | — | 0 |
| CVE-2013-7285 Xstream API versions up to 1.4.6 and version 1.4.10, if the security framework has not been initialized, may allow a remote attacker to run arbitrary shell commands by manipulating the processed input... | 9.8 | CRITICAL | — | 0 |
| CVE-2018-20839 systemd 242 changes the VT1 mode upon a logout, which allows attackers to read cleartext passwords in certain circumstances, such as watching a shutdown, or using Ctrl-Alt-F1 and Ctrl-Alt-F2. This occ... | 4.3 | MEDIUM | — | 0 |
| CVE-2019-0620 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability... | 7.6 | HIGH | — | 0 |
| CVE-2019-0709 A remote code execution vulnerability exists when Windows Hyper-V on a host server fails to properly validate input from an authenticated user on a guest operating system. To exploit the vulnerability... | 7.6 | HIGH | — | 0 |
| CVE-2019-0710 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an a... | 6.8 | MEDIUM | — | 0 |
| CVE-2019-0711 A denial of service vulnerability exists when Microsoft Hyper-V on a host server fails to properly validate input from a privileged user on a guest operating system. To exploit the vulnerability, an a... | 6.8 | MEDIUM | — | 0 |
This product uses data from the NVD API but is not endorsed or certified by the NVD.