CVE
Vendors
Products
Updated
CVSS v2
CVSS v3
iScripts eSwap v2.4 has SQL injection via the wishlistdetailed.php User Panel ToId parameter.
SkyCaiji 1.2 allows CSRF to add an Administrator user.
An issue was discovered in Moodle 3.x. By substituting URLs in portfolios, users can instantiate any class. This can also be exploited by users who are logged in as guests to create a DDoS attack.
An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the appshomecontrollerParserController.php scode parameter.
An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.
init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.
sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.
sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call.
jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read.
In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the LDSS dissector could crash. This was addressed in epan/dissectors/packet-ldss.c by avoiding a buffer over-read upon encountering a missing ' ' character.
