• Skip to primary navigation
  • Skip to main content
CVE Vulnerability

CVE Vulnerability

  • CVE’s
  • Products
  • Vendors
Home » CVE’s

CVE’s


CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
CVE-2018-16285
2018-11-02
N/A
6.1 MEDIUM
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
CVE-2018-16283
2018-11-14
N/A
9.8 CRITICAL
The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.
CVE-2018-16282
Edr-810 Firmware, Moxa
Edr-810_firmware, Edr-810, Iologik_2512_firmware, Iologik_2512, Iologik_2512-t_firmware, Iologik_2512-t, Iologik_2512-hspa_firmware, Iologik_2512-hspa, Iologik_2512-hspa-t_firmware, Iologik_2512-hspa-t
2018-11-05
N/A
8.8 HIGH
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.
CVE-2018-16281
2020-08-24
N/A
9.8 CRITICAL
The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control.
CVE-2018-16278
2018-10-23
N/A
9.8 CRITICAL
phpkaiyuancms PhpOpenSourceCMS (POSCMS) V3.2.0 allows an unauthenticated user to execute arbitrary SQL commands via the diy/module/member/controllers/Api.php ajax_save_draft function with the dir parameter.
CVE-2018-16277
2018-11-15
N/A
5.4 MEDIUM
The Image Import function in XWiki through 10.7 has XSS.
CVE-2018-16276
Canonical, Ubuntu Linux
Ubuntu_linux, Accountsservice, Acpi-support, Add-apt-repository, Apparmor, Apt-xapian-index, Bazaar, Checkinstall, C-kernel, Cloud-init
2023-02-24
N/A
7.8 HIGH
An issue was discovered in yurex_read in drivers/usb/misc/yurex.c in the Linux kernel before 4.17.7. Local attackers could use user access read/writes with incorrect bounds checking in the yurex USB driver to crash the kernel or potentially escalate privileges.
CVE-2018-16275
2020-08-24
N/A
7.8 HIGH
OPSWAT MetaDefender before v4.11.2 allows CSV injection.
CVE-2018-16272
2020-01-30
N/A
9.8 CRITICAL
The wpa_supplicant system service in Samsung Galaxy Gear series allows an unprivileged process to fully control the Wi-Fi interface, due to the lack of its D-Bus security policy configurations. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
CVE-2018-16271
2020-01-30
N/A
6.5 MEDIUM
The wemail_consumer_service (from the built-in application wemail) in Samsung Galaxy Gear series allows an unprivileged process to manipulate a user's mailbox, due to improper D-Bus security policy configurations. An arbitrary email can also be sent from the mailbox via the paired smartphone. This affects Tizen-based firmwares including Samsung Galaxy Gear series before build RE2.
« Previous 1 … 2,367 2,368 2,369 2,370 2,371 … 11,258 Next »

Copyright CVE Vulnerabilities 2023
Data Sources:

  • NIST
  • MITRE
  • CVE Search
  • Open CVE