Vulnerabilities
Vulnerable Software
Security Vulnerabilities - CVEs Published In May 2018
md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.
CVSS Score
9.8
EPSS Score
0.005
Published
2018-05-29
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
CVSS Score
5.3
EPSS Score
0.005
Published
2018-05-28
Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.
CVSS Score
9.8
EPSS Score
0.02
Published
2018-05-28
An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.
CVSS Score
5.4
EPSS Score
0.002
Published
2018-05-28
The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.
CVSS Score
8.8
EPSS Score
0.006
Published
2018-05-28
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
CVSS Score
5.3
EPSS Score
0.034
Published
2018-05-28
PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php.
CVSS Score
8.8
EPSS Score
0.004
Published
2018-05-28
The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.
CVSS Score
9.8
EPSS Score
0.006
Published
2018-05-28
The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.
CVSS Score
5.5
EPSS Score
0.015
Published
2018-05-28
Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.
CVSS Score
4.8
EPSS Score
0.003
Published
2018-05-28


Contact Us

Shodan ® - All rights reserved