Latest 7 days CVE Lists

Latest 7 days CVE Lists 피드 구독하기
This feed contains the most recent CVE cyber vulnerabilities published within the National Vulnerability Database.
업데이트: 2시간 58분 지남

CVE-2018-18838

13시간 46분 지남
An issue was discovered in Netdata 1.10.0. Log Injection (or Log Forgery) exists via a %0a sequence in the url parameter to api/v1/registry.

CVE-2018-18839

13시간 46분 지남
** DISPUTED ** An issue was discovered in Netdata 1.10.0. Full Path Disclosure (FPD) exists via api/v1/alarms. NOTE: the vendor says "is intentional."

CVE-2019-4142 (cloud_private)

14시간 46분 지남
IBM Cloud Private 2.1.0, 3.1.0, 3.1.1, and 3.1.2 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 158338.

CVE-2018-18852

14시간 46분 지남
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.

CVE-2018-18875 (weather_microserver_firmware)

14시간 46분 지남
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationname.php.

CVE-2018-18876 (weather_microserver_firmware)

14시간 46분 지남
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a readouts_rd.php directory traversal issue makes it possible to read any file present on the underlying operating system.

CVE-2018-18877 (weather_microserver_firmware)

14시간 46분 지남
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can access an alternative configuration page config_main.php that allows manipulation of the device.

CVE-2018-18878 (weather_microserver_firmware)

14시간 46분 지남
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, the BACnet daemon does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.

CVE-2019-7588

화, 2019/06/18 - 11:15오후
A vulnerability in the exacqVision Enterprise System Manager (ESM) v5.12.2 application whereby unauthorized privilege escalation can potentially be achieved. This vulnerability impacts exacqVision ESM v5.12.2 and all prior versions of ESM running on a Windows operating system. This issue does not impact any Windows Server OSs, or Linux deployments with permissions that are not inherited from the root directory. Authorized Users have ?modify? permission to the ESM folders, which allows a low privilege account to modify files located in these directories. An executable can be renamed and replaced by a malicious file that could connect back to a bad actor providing system level privileges. A low privileged user is not able to restart the service, but a restart of the system would trigger the execution of the malicious file. This issue affects: Exacq Technologies, Inc. exacqVision Enterprise System Manager (ESM) Version 5.12.2 and prior versions; This issue does not affect: Exacq Technologies, Inc. exacqVision Enterprise System Manager (ESM) 19.03 and above.

CVE-2018-18879 (weather_microserver_firmware)

화, 2019/06/18 - 11:15오후
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags.php.

CVE-2018-18880 (weather_microserver_firmware)

화, 2019/06/18 - 11:15오후
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.

CVE-2018-18886 (helpy)

화, 2019/06/18 - 11:15오후
Helpy v2.1.0 has Stored XSS via the Ticket title.

CVE-2018-18944 (artha)

화, 2019/06/18 - 11:15오후
Artha ~ The Open Thesaurus 1.0.3.0 has a Buffer Overflow.

CVE-2019-12872 (dotcms)

화, 2019/06/18 - 11:15오후
dotCMS before 5.1.6 is vulnerable to a SQL injection that can be exploited by an attacker of the role Publisher via view_unpushed_bundles.jsp.

CVE-2018-20013

화, 2019/06/18 - 10:15오후
In UrBackup 2.2.6, an attacker can send a malformed request to the client over the network, and trigger a fileservplugin/CClientThread.cpp CClientThread::ProcessPacket metadata_id!=0 assertion, leading to shutting down the client application.

CVE-2019-10998

화, 2019/06/18 - 10:15오후
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.

CVE-2019-12823

화, 2019/06/18 - 10:15오후
Craft CMS 3.1.30 has XSS.

CVE-2019-6965

화, 2019/06/18 - 10:15오후
An XSS issue was discovered in i-doit Open 1.12 via the src/tools/php/qr/qr.php url parameter.

CVE-2019-7159

화, 2019/06/18 - 10:15오후
OX App Suite 7.10.1 and earlier allows Information Exposure.

CVE-2019-12868

화, 2019/06/18 - 9:15오전
app/Model/Server.php in MISP 2.4.109 allows remote command execution by a super administrator because the PHP file_exists function is used with user-controlled entries, and phar:// URLs trigger deserialization.

페이지