Vulnerabilities (CVE)

Total 315023 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-5219 1 K7computing 1 Antivirus 2024-11-21 6.1 MEDIUM 7.8 HIGH
In K7 Antivirus 15.1.0306, the driver file (K7FWHlpr.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002168.
CVE-2018-5218 1 K7computing 1 Antivirus 2024-11-21 6.1 MEDIUM 7.8 HIGH
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x950025b0.
CVE-2018-5217 1 K7computing 1 Antivirus 2024-11-21 6.1 MEDIUM 7.8 HIGH
In K7 Antivirus 15.1.0306, the driver file (K7Sentry.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x95002578.
CVE-2018-5216 1 Radiantcms 1 Radiant Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Radiant CMS 1.1.4 has XSS via crafted Markdown input in the part_body_content parameter to an admin/pages/*/edit resource.
CVE-2018-5215 1 Fork-cms 1 Fork Cms 2024-11-21 3.5 LOW 5.4 MEDIUM
Fork CMS 5.0.7 has XSS in /private/en/pages/edit via the title parameter.
CVE-2018-5214 1 Add Link To Facebook Project 1 Add Link To Facebook 2024-11-21 3.5 LOW 5.4 MEDIUM
The "Add Link to Facebook" plugin through 2.3 for WordPress has XSS via the al2fb_facebook_id parameter to wp-admin/profile.php.
CVE-2018-5213 1 Simple Download Monitor Project 1 Simple Download Monitor 2024-11-21 3.5 LOW 5.4 MEDIUM
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload (aka Downloadable File) parameter in an edit action to wp-admin/post.php.
CVE-2018-5212 1 Simple Download Monitor Project 1 Simple Download Monitor 2024-11-21 3.5 LOW 5.4 MEDIUM
The Simple Download Monitor plugin before 3.5.4 for WordPress has XSS via the sdm_upload_thumbnail (aka File Thumbnail) parameter in an edit action to wp-admin/post.php.
CVE-2018-5211 1 Phpsugar 1 Php Melody 2024-11-21 7.5 HIGH 9.8 CRITICAL
PHP Melody version 2.7.1 suffer from SQL Injection Time-based attack on the page ajax.php with the parameter playlist.
CVE-2018-5210 1 Samsung 1 Samsung Mobile 2024-11-21 9.3 HIGH 8.1 HIGH
On Samsung mobile devices with N(7.x) software and Exynos chipsets, attackers can conduct a Trustlet stack overflow attack for arbitrary TEE code execution, in conjunction with a brute-force attack to discover unlock information (PIN, password, or pattern). The Samsung ID is SVE-2017-10733.
CVE-2018-5208 2 Debian, Irssi 2 Debian Linux, Irssi 2024-11-21 7.5 HIGH 9.8 CRITICAL
In Irssi before 1.0.6, a calculation error in the completion code could cause a heap buffer overflow when completing certain strings.
CVE-2018-5207 2 Debian, Irssi 2 Debian Linux, Irssi 2024-11-21 5.0 MEDIUM 7.5 HIGH
When using an incomplete variable argument, Irssi before 1.0.6 may access data beyond the end of the string.
CVE-2018-5206 2 Debian, Irssi 2 Debian Linux, Irssi 2024-11-21 7.5 HIGH 9.8 CRITICAL
When the channel topic is set without specifying a sender, Irssi before 1.0.6 may dereference a NULL pointer.
CVE-2018-5205 3 Canonical, Debian, Irssi 3 Ubuntu Linux, Debian Linux, Irssi 2024-11-21 5.0 MEDIUM 7.5 HIGH
When using incomplete escape codes, Irssi before 1.0.6 may access data beyond the end of the string.
CVE-2018-5204 1 Infraware-global 1 Ml Report 2024-11-21 7.5 HIGH 9.8 CRITICAL
ML Report version Between 2.00.000.0000 and 2.18.628.5980 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.
CVE-2018-5203 1 Dextsolution 1 Dextuploadx5 2024-11-21 7.5 HIGH 9.8 CRITICAL
DEXTUploadX5 version Between 1.0.0.0 and 2.2.0.0 contains a vulnerability that could allow remote attacker to download and execute remote arbitrary file by setting the arguments to the activex method. this can be leveraged for code execution.
CVE-2018-5202 1 Signkorea 1 Skcertservice 2024-11-21 6.8 MEDIUM 7.8 HIGH
SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded by SKCertService. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.
CVE-2018-5201 1 Hancom 4 Hancom Office 2010, Hancom Office 2014, Hancom Office 2018 and 1 more 2024-11-21 4.3 MEDIUM 5.5 MEDIUM
Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.
CVE-2018-5200 1 Pandora 1 Kmplayer 2024-11-21 6.8 MEDIUM 7.8 HIGH
KMPlayer 4.2.2.15 and earlier have a Heap Based Buffer Overflow Vulnerability. It could be exploited with a crafted FLV format file. The problem is that more frame data is copied to heap memory than the size specified in the frame header. This results in a memory corruption and remote code execution.
CVE-2018-5199 1 Wizvera 1 Veraport G3 2024-11-21 6.8 MEDIUM 8.8 HIGH
In Veraport G3 ALL on MacOS, due to insufficient domain validation, It is possible to overwrite installation file to malicious file. A remote unauthenticated attacker may use this vulnerability to execute arbitrary file.