Vulnerabilities (CVE)

Total 403391 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-12659 1 Slims Akasia Project 1 Slims Akasia 2026-06-17 6.8 MEDIUM 8.8 HIGH
SLiMS 8 Akasia 8.3.1 allows remote attackers to bypass the CSRF protection mechanism and obtain admin access by omitting the csrf_token parameter.
CVE-2018-12658 1 Slims Project 1 Slims 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) exists in the Stock Take module in SLiMS 8 Akasia 8.3.1 via an admin/modules/stock_take/index.php?keywords= URI.
CVE-2018-12657 1 Slims Akasia Project 1 Slims Akasia 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.
CVE-2018-12656 1 Slims Akasia Project 1 Slims Akasia 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI.
CVE-2018-12655 1 Slims Akasia Project 1 Slims Akasia 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.
CVE-2018-12654 1 Slims Akasia Project 1 Slims Akasia 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI.
CVE-2018-12653 1 Myadrenalin 1 Adrenalin 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious JavaScript code in /RPT/SSRSDynamicEditReports.aspx via 'ReportId' parameter.
CVE-2018-12652 1 Myadrenalin 1 Adrenalin 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the LeaveEmployeeSearch.aspx prntFrmName or prntDDLCntrlName parameter.
CVE-2018-12651 1 Myadrenalin 1 Human Resource Management Software 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the ShiftEmployeeSearch.aspx prntFrmName or prntDDLCntrlName parameter.
CVE-2018-12650 1 Myadrenalin 1 Human Resource Management Software 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'.
CVE-2018-12648 1 Exempi Project 1 Exempi 2026-06-17 4.3 MEDIUM 7.5 HIGH
The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.
CVE-2018-12642 1 Froxlor 1 Froxlor 2026-06-17 5.0 MEDIUM 7.5 HIGH
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
CVE-2018-12641 1 Gnu 1 Binutils 2026-06-17 4.3 MEDIUM 5.5 MEDIUM
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are recursive stack frames: demangle_arm_hp_template, demangle_class_name, demangle_fund_type, do_type, do_arg, demangle_args, and demangle_nested_args. This can occur during execution of nm-new.
CVE-2018-12640 1 Insteon 2 2864-222, 2864-222 Firmware 2026-06-17 7.5 HIGH 9.8 CRITICAL
The webService binary on Insteon HD IP Camera White 2864-222 devices has a Buffer Overflow via a crafted pid, pwd, or usr key in a GET request on port 34100.
CVE-2018-12638 1 Bose 1 Soundtouch 2026-06-17 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in the Bose Soundtouch app 18.1.4 for iOS. There is no frontend input validation of the device name. A malicious device name can execute JavaScript on the registered Bose User Account if a speaker has been connected to the app.
CVE-2018-12636 1 Ithemes 1 Security 2026-06-17 6.5 MEDIUM 7.2 HIGH
The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.
CVE-2018-12635 1 Circontrol 1 Scada 2026-06-17 5.0 MEDIUM 7.5 HIGH
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
CVE-2018-12634 1 Circontrol 1 Circarlife Scada 2026-06-17 5.0 MEDIUM 9.8 CRITICAL
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
CVE-2018-12633 1 Linux 1 Linux Kernel 2026-06-17 6.3 MEDIUM 6.3 MEDIUM
An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.
CVE-2018-12632 1 Redatam 1 Redatam 2026-06-17 5.0 MEDIUM 5.3 MEDIUM
Redatam7 (formerly Redatam WebServer) allows remote attackers to discover the installation path via an invalid LFN parameter to the /redbin/rpwebutilities.exe/text URI.