• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-17152
2019-07-12
N/A
6.4 MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XXE.
CVE-2018-17151
2019-07-12
N/A
5.4 MEDIUM
Intersystems Cache 2017.2.2.865.0 has Incorrect Access Control.
CVE-2018-17150
2019-07-12
N/A
6.1 MEDIUM
Intersystems Cache 2017.2.2.865.0 allows XSS.
CVE-2018-1715
2019-10-09
N/A
5.4 MEDIUM
IBM Maximo Asset Management 7.6 through 7.6.3 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 147003.
CVE-2018-17148
2019-06-21
N/A
9.8 CRITICAL
An Insufficient Access Control vulnerability (leading to credential disclosure) in coreconfigsnapshot.php (aka configuration snapshot page) in Nagios XI before 5.5.4 allows remote attackers to gain access to configuration files containing confidential credentials.
CVE-2018-17147
2019-07-11
N/A
4.8 MEDIUM
Nagios XI before 5.5.4 has XSS in the auto login admin management page.
CVE-2018-17146
2019-06-23
N/A
5.4 MEDIUM
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute arbitrary JavaScript code within the auto login admin management page.
CVE-2018-17145
2020-09-15
N/A
7.5 HIGH
Bitcoin Core 0.16.x before 0.16.2 and Bitcoin Knots 0.16.x before 0.16.2 allow remote denial of service via a flood of multiple transaction inv messages with random hashes, aka INVDoS. NOTE: this can also affect other cryptocurrencies, e.g., if they were forked from Bitcoin Core after 2017-11-15.
CVE-2018-17144
2020-08-24
N/A
7.5 HIGH
Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.
CVE-2018-17143
2020-08-24
N/A
7.5 HIGH
The html package (aka x/net/html) through 2018-09-17 in Go mishandles