Total
210374 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2022-33182 | 1 Broadcom | 1 Fabric Operating System | 2023-02-28 | N/A | 7.8 HIGH |
A privilege escalation vulnerability in Brocade Fabric OS CLI before Brocade Fabric OS v9.1.0, 9.0.1e, 8.2.3c, 8.2.0cbn5, could allow a local authenticated user to escalate its privilege to root using switch commands “supportlink”, “firmwaredownload”, “portcfgupload, license, and “fosexec”. | |||||
CVE-2019-12804 | 1 Hunesion | 1 I-onenet | 2023-02-28 | 4.3 MEDIUM | 5.5 MEDIUM |
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, due to the lack of update file integrity checking in the upgrade process, an attacker can craft malicious file and use it as an update. | |||||
CVE-2019-12803 | 1 Hunesion | 1 I-onenet | 2023-02-28 | 10.0 HIGH | 9.8 CRITICAL |
In Hunesion i-oneNet version 3.0.7 ~ 3.0.53 and 4.0.4 ~ 4.0.16, the specific upload web module doesn't verify the file extension and type, and an attacker can upload a webshell. After the webshell upload, an attacker can use the webshell to perform remote code exection such as running a system command. | |||||
CVE-2018-3787 | 1 Simplehttpserver Project | 1 Simplehttpserver | 2023-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Path traversal in simplehttpserver <v0.2.1 allows listing any file on the server. | |||||
CVE-2018-3776 | 1 Nextcloud | 1 Nextcloud Server | 2023-02-28 | 5.0 MEDIUM | 5.3 MEDIUM |
Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log. | |||||
CVE-2018-3778 | 1 Aedes Project | 1 Aedes | 2023-02-28 | 5.0 MEDIUM | 5.3 MEDIUM |
Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized. | |||||
CVE-2018-3777 | 1 Restforce | 1 Restforce | 2023-02-28 | 7.5 HIGH | 9.8 CRITICAL |
Insufficient URI encoding in restforce before 3.0.0 allows attacker to inject arbitrary parameters into Salesforce API requests. | |||||
CVE-2021-32419 | 1 Schismtracker | 1 Schism Tracker | 2023-02-28 | N/A | 5.3 MEDIUM |
An issue in Schism Tracker v20200412 fixed in v.20200412 allows attacker to obtain sensitive information via the fmt_mtm_load_song function in fmt/mtm.c. | |||||
CVE-2018-3770 | 1 Markdown-pdf Project | 1 Markdown-pdf | 2023-02-28 | 2.1 LOW | 5.5 MEDIUM |
A path traversal exists in markdown-pdf version <9.0.0 that allows a user to insert a malicious html code that can result in reading the local files. | |||||
CVE-2018-3769 | 1 Ruby-grape | 1 Grape | 2023-02-28 | 4.3 MEDIUM | 6.1 MEDIUM |
ruby-grape ruby gem suffers from a cross-site scripting (XSS) vulnerability via "format" parameter. | |||||
CVE-2018-3766 | 1 Buttle Project | 1 Buttle | 2023-02-28 | 5.0 MEDIUM | 7.5 HIGH |
Path traversal in buttle module versions <= 0.2.0 allows to read any file in the server. | |||||
CVE-2018-3763 | 1 Nextcloud | 1 Calendar | 2023-02-28 | 3.5 LOW | 4.8 MEDIUM |
In Nextcloud Calendar before 1.5.8 and 1.6.1, a missing sanitization of search results for an autocomplete field could lead to a stored XSS requiring user-interaction. The missing sanitization only affected group names, hence malicious search results could only be crafted by privileged users like admins or group admins. | |||||
CVE-2018-3762 | 1 Nextcloud | 1 Nextcloud Server | 2023-02-28 | 4.0 MEDIUM | 4.3 MEDIUM |
Nextcloud Server before 12.0.8 and 13.0.3 suffers from improper checks of dropped permissions for incoming shares allowing a user to still request previews for files it should not have access to. | |||||
CVE-2018-3761 | 1 Nextcloud | 1 Nextcloud Server | 2023-02-28 | 5.8 MEDIUM | 8.1 HIGH |
Nextcloud Server before 12.0.8 and 13.0.3 suffer from improper authentication on the OAuth2 token endpoint. Missing checks potentially allowed handing out new tokens in case the OAuth2 client was partly compromised. | |||||
CVE-2018-3732 | 1 Resolve-path Project | 1 Resolve-path | 2023-02-28 | 5.0 MEDIUM | 7.5 HIGH |
resolve-path node module before 1.4.0 suffers from a Path Traversal vulnerability due to lack of validation of paths with certain special characters, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3729 | 1 Localhost-now Project | 1 Localhost-now | 2023-02-28 | 5.0 MEDIUM | 7.5 HIGH |
localhost-now node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3727 | 1 626 Project | 1 626 | 2023-02-28 | 5.0 MEDIUM | 7.5 HIGH |
626 node module suffers from a Path Traversal vulnerability due to lack of validation of file, which allows a malicious user to read content of any file with known path. | |||||
CVE-2018-3720 | 1 Assign-deep Project | 1 Assign-deep | 2023-02-28 | 6.5 MEDIUM | 8.8 HIGH |
assign-deep node module before 0.4.7 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. | |||||
CVE-2021-32163 | 1 Linuxfoundation | 1 Modular Open Smart Network | 2023-02-28 | N/A | 9.8 CRITICAL |
Authentication vulnerability in MOSN v.0.23.0 allows attacker to escalate privileges via case-sensitive JWT authorization. | |||||
CVE-2018-3719 | 1 Mixin-deep Project | 1 Mixin-deep | 2023-02-28 | 6.5 MEDIUM | 8.8 HIGH |
mixin-deep node module before 1.3.1 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on all objects. |