CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
IBM API Connect 5.0.0.0 through 5.0.8.5 could display highly sensitive information to an attacker with physical access to the system. IBM X-Force ID: 151636.
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.
An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.
An XXE issue was discovered in Douchat 4.0.4 because Datanotify.php calls simplexml_load_string. This can also be used for SSRF.
An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."
A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.
A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.
An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.
N301_firmware, N301, Ac15_firmware, Ac15, 11n, 11n_firmware, 4g300, 4g300_firmware, A15, A15_firmware
2019-01-29
N/A
7.5 HIGH
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.
N301_firmware, N301, Ac15_firmware, Ac15, 11n, 11n_firmware, 4g300, 4g300_firmware, A15, A15_firmware
2019-01-29
N/A
7.5 HIGH
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.
