Vulnerabilities (CVE)

Total 403884 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-15844 1 Damicms 1 Damicms 2026-06-17 6.8 MEDIUM 8.8 HIGH
An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.
CVE-2018-15843 1 Get-simple 1 Getsimple Cms 2026-06-17 3.5 LOW 4.8 MEDIUM
GetSimple CMS 3.3.14 has XSS via the admin/edit.php "Add New Page" field.
CVE-2018-15842 1 Wolfcms 1 Wolf Cms 2026-06-17 3.5 LOW 4.8 MEDIUM
WolfCMS 0.8.3.1 has XSS via the /?/admin/page/add slug parameter.
CVE-2018-15840 1 Tp-link 2 Tl-wr840n, Tl-wr840n Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
CVE-2018-15839 1 Dlink 2 Dir-615, Dir-615 Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.
CVE-2018-15836 1 Xelerance 1 Openswan 2026-06-17 5.0 MEDIUM 7.5 HIGH
In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Consequently, a remote attacker can forge signatures when small public exponents are being used. IKEv2 signature verification is affected when RAW RSA keys are used.
CVE-2018-15835 1 Google 1 Android 2026-06-17 5.0 MEDIUM 7.5 HIGH
Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.
CVE-2018-15834 1 Radare 1 Radare2 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
In radare2 before 2.9.0, a heap overflow vulnerability exists in the read_module_referenced_functions function in libr/anal/flirt.c via a crafted flirt signature file.
CVE-2018-15833 1 Vanillaforums 1 Vanilla Forums 2026-06-17 4.0 MEDIUM 4.3 MEDIUM
In Vanilla before 2.6.1, the polling functionality allows Insecure Direct Object Reference (IDOR) via the Poll ID, leading to the ability of a single user to select multiple Poll Options (e.g., vote for multiple items).
CVE-2018-15832 1 Ubisoft 1 Uplay 2026-06-17 6.8 MEDIUM 8.8 HIGH
upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process.
CVE-2018-15822 3 Canonical, Debian, Ffmpeg 3 Ubuntu Linux, Debian Linux, Ffmpeg 2026-06-17 5.0 MEDIUM 7.5 HIGH
The flv_write_packet function in libavformat/flvenc.c in FFmpeg through 2.8 does not check for an empty audio packet, leading to an assertion failure.
CVE-2018-15820 1 Easyio 2 Easyio 30p, Easyio 30p Firmware 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
EasyIO EasyIO-30P devices before 2.0.5.27 allow XSS via the dev.htm GDN parameter.
CVE-2018-15819 1 Easyio 2 Easyio 30p, Easyio 30p Firmware 2026-06-17 5.0 MEDIUM 7.5 HIGH
EasyIO EasyIO-30P devices before 2.0.5.27 have Incorrect Access Control, related to webuser.js.
CVE-2018-15818 1 Reputeinfosystems 1 Repute Arforms 2026-06-17 6.4 MEDIUM 7.5 HIGH
An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending a malicious request to admin-ajax.php.
CVE-2018-15817 1 Faststone 1 Image Viewer 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d63 via a crafted image file.
CVE-2018-15816 1 Faststone 1 Image Viewer 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
FastStone Image Viewer 6.5 has a Read Access Violation on Block Data Move starting at image00400000+0x0000000000002d7d via a crafted image file.
CVE-2018-15815 1 Faststone 1 Image Viewer 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
FastStone Image Viewer 6.5 has an Exception Handler Chain Corrupted issue starting at image00400000+0x00000000003ef68a via a crafted image file.
CVE-2018-15814 1 Faststone 1 Image Viewer 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000001cb509 via a crafted image file.
CVE-2018-15813 1 Faststone 1 Image Viewer 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
FastStone Image Viewer 6.5 has a User Mode Write AV starting at image00400000+0x00000000000e1237 via a crafted image file.
CVE-2018-15812 1 Dnnsoftware 1 Dotnetnuke 2026-06-17 5.0 MEDIUM 7.5 HIGH
DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.