33293 vulnerabilidades Orden: CVSS EPSS Año ID
CVE-2018-21218
Software Genérico General
8.8
HIGH
EPSS
0.4%
2018 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D3600 before 1.0.0.67, D6000 before 1.0.0.67, D6100 before 1.0.0.56, D7800 before 1.0.1.30, R6100 before 1.0.1.20, R7500 before 1.0.0.118, R7500v2 before 1.0.3.24, R9000 before 1.0.2.52, WNDR3700v4 before 1.0.2.96, WNDR4300 before 1.0.2.98, WNDR4300v2 before 1.0.0.50, WNDR4500v3 before 1.0.0.50, and WNR2000v5 before 1.0.0.62.

CVE-2018-25195
Wecodex Hotel CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Wecodex Hotel CMS 1.0 contains an SQL injection vulnerability in the admin login functionality that allows unauthenticated attackers to bypass authentication by injecting SQL code. Attackers can submit malicious SQL payloads through the username parameter in POST requests to index.php with action=processlogin to extract sensitive database information or gain unauthorized administrative access.

CVE-2018-21124
Software Genérico General
8.8
HIGH
EPSS
0.2%
2018 1 PoC

NETGEAR WAC510 devices before 5.0.0.17 are affected by privilege escalation.

CVE-2018-4233
Software Genérico Cloud Windows
8.8
HIGH
EPSS
89.9%
2018 3 PoCs

An issue was discovered in certain Apple products. iOS before 11.4 is affected. Safari before 11.1.1 is affected. iCloud before 7.5 on Windows is affected. iTunes before 12.7.5 on Windows is affected. tvOS before 11.4 is affected. watchOS before 4.3.1 is affected. The issue involves the "WebKit" component. It allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted web site.

CVE-2018-3977
Simple DirectMedia Layer General
8.8
HIGH
EPSS
0.9%
2018 1 PoC

An exploitable code execution vulnerability exists in the XCF image rendering functionality of SDL2_image-2.0.3. A specially crafted XCF image can cause a heap overflow, resulting in code execution. An attacker can display a specially crafted image to trigger this vulnerability.

CVE-2018-3983
Atlantis Word Processor General
8.8
HIGH
EPSS
0.5%
2018 1 PoC

An exploitable uninitialized pointer vulnerability exists in the Word document parser of the the Atlantis Word Processor. A specially crafted document can cause an array fetch to return an uninitialized pointer and then performs some arithmetic before writing a value to the result. Usage of this uninitialized pointer can allow an attacker to corrupt heap memory resulting in code execution under the context of the application. An attacker must convince a victim to open a document in order to trigger this vulnerability.

CVE-2018-25199
OOP CMS BLOG Web Database
8.8
HIGH
EPSS
0.2%
2018 CWE-89 1 PoC

OOP CMS BLOG 1.0 contains SQL injection vulnerabilities that allow unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through multiple parameters. Attackers can inject SQL commands via the search parameter in search.php, pageid parameter in page.php, and id parameter in posts.php to extract database information including table names, schema names, and database credentials.

CVE-2018-3976
ACD Systems General
8.8
HIGH
EPSS
0.4%
2018 1 PoC

An exploitable out-of-bounds write exists in the CALS Raster file format-parsing functionality of Canvas Draw version 5.0.0.28. A specially crafted CAL image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a CAL image to trigger this vulnerability and gain code execution.

CVE-2018-3857
Canvas Draw General
8.8
HIGH
EPSS
0.7%
2018 CWE-122 1 PoC

An exploitable heap overflow exists in the TIFF parsing functionality of Canvas Draw version 4.0.0. A specially crafted TIFF image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a TIFF image to trigger this vulnerability and gain code execution. A different vulnerability than CVE-2018-3858.

CVE-2018-21158
Software Genérico General
8.8
HIGH
EPSS
0.3%
2018 1 PoC

NETGEAR R7800 devices before 1.0.2.46 are affected by incorrect configuration of security settings.

CVE-2018-25187
Tina4 Stack Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Tina4 Stack 1.0.3 contains multiple vulnerabilities allowing unauthenticated attackers to access sensitive database files and execute SQL injection attacks. Attackers can directly request the kim.db database file to retrieve user credentials and password hashes, or inject SQL code through the menu endpoint to manipulate database queries.

CVE-2018-4000
Atlantis Word Processor General
8.8
HIGH
EPSS
0.3%
2018 1 PoC

An exploitable double-free vulnerability exists in the Office Open XML parser of Atlantis Word Processor, version 3.2.5.0. A specially crafted document can cause a TTableRow instance to be referenced twice, resulting in a double-free vulnerability when both the references go out of scope. An attacker must convince a victim to open a document in order to trigger this vulnerability.

CVE-2018-21153
Software Genérico General
8.8
HIGH
EPSS
0.6%
2018 1 PoC

Certain NETGEAR devices are affected by a buffer overflow by an unauthenticated attacker. This affects D7800 before 1.0.1.34, DM200 before 1.0.0.50, EX2700 before 1.0.1.32, EX6100v2 before 1.0.1.70, EX6150v2 before 1.0.1.70, EX6200v2 before 1.0.1.62, EX6400 before 1.0.1.78, EX7300 before 1.0.1.62, EX8000 before 1.0.0.114, R6100 before 1.0.1.22, R7500 before 1.0.0.122, R7500v2 before 1.0.3.26, R7800 before 1.0.2.40, R8900 before 1.0.3.10, R9000 before 1.0.3.10, WN2000RPTv3 before 1.0.1.26, WN3000RPv2 before 1.0.0.56, WN3000RPv3 before 1.0.2.66, WN3100RPv2 before 1.0.0.56, WNDR4300 before 1.0.2.

CVE-2018-3888
Computerinsel Photoline General
8.8
HIGH
EPSS
0.6%
2018 1 PoC

A memory corruption vulnerability exists in the PCX-parsing functionality of Computerinsel Photoline 20.53. A specially crafted PCX image processed via the application can lead to an out-of-bounds write, overwriting arbitrary data. An attacker can deliver a PCX image to trigger this vulnerability and gain code execution.

CVE-2018-3847
CFITSIO General
8.8
HIGH
EPSS
0.6%
2018 1 PoC

Multiple exploitable buffer overflow vulnerabilities exist in image parsing functionality of the CFITSIO library version 3.42. Specially crafted images parsed via the library, can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can deliver an FIT image to trigger this vulnerability and potentially gain code execution.

CVE-2018-25166
Meneame English Pligg Web Database
8.8
HIGH
EPSS
0.1%
2018 CWE-89 1 PoC

Meneame English Pligg 5.8 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the search parameter. Attackers can send GET requests to index.php with crafted SQL payloads in the search parameter to extract sensitive database information including usernames, database names, and version details.

CVE-2018-21102
Software Genérico Web
8.8
HIGH
EPSS
0.2%
2018 1 PoC

NETGEAR ReadyNAS devices before 6.9.3 are affected by CSRF.

CVE-2018-25209
OpenBiz Cubi Lite Web Database
8.8
HIGH
EPSS
0.4%
2018 CWE-89 1 PoC

OpenBiz Cubi Lite 3.0.8 contains a SQL injection vulnerability in the login form that allows unauthenticated attackers to manipulate database queries through the username parameter. Attackers can submit POST requests to /bin/controller.php with malicious SQL code in the username field to extract sensitive database information or bypass authentication.

CVE-2018-4404
Software Genérico General
8.8
HIGH
EPSS
70.2%
2018 1 PoC

In iOS before 11.4 and macOS High Sierra before 10.13.5, a memory corruption issue exists and was addressed with improved memory handling.

CVE-2018-25183
Shipping System CMS Web Database
8.8
HIGH
EPSS
0.5%
2018 CWE-89 1 PoC

Shipping System CMS 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to bypass authentication by injecting SQL code through the username parameter. Attackers can submit malicious SQL payloads using boolean-based blind techniques in POST requests to the admin login endpoint to authenticate without valid credentials.