Exploit Database

153,556 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-11583 WRITEUP MEDIUM
SeaCMS 6.61 - Stored Cross-Site Scripting via admin_collect.php siteurl Parameter
SeaCMS 6.61 has stored XSS in admin_collect.php via the siteurl parameter.
CVSS 6.1
CVE-2018-12072 WRITEUP CRITICAL
Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 - Unauthenticated Remote Code Execution via TELNET
An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can completely compromise it.
CVSS 9.8
CVE-2018-12073 WRITEUP MEDIUM
Eminent EM4544 9.10 - Privilege Escalation
An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a new one within the web interface. Therefore, it is possible to exploit this issue (e.g., in combination with a successful XSS, or at an unattended workstation) to change the admin password to an attacker-chosen value without knowing the current password.
CVSS 5.3
CVE-2018-12113 WRITEUP CRITICAL
Core FTP LE <2.2 Build 1921 - Buffer Overflow
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
CVSS 9.8
CVE-2018-12113 WRITEUP CRITICAL
Core FTP LE <2.2 Build 1921 - Buffer Overflow
Core FTP LE version 2.2 Build 1921 is prone to a buffer overflow vulnerability that may result in a DoS or remote code execution via a PASV response.
CVSS 9.8
CVE-2018-12271 WRITEUP MEDIUM
com.getdropbox.Dropbox app <100.2 - Auth Bypass
An issue was discovered in the com.getdropbox.Dropbox app 100.2 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred
CVSS 6.4
CVE-2018-12445 WRITEUP LOW
com.dropbox.android 98.2.2 - Auth Bypass
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 3.1
CVE-2018-12446 WRITEUP LOW
com.dropbox.android 98.2.2 - Auth Bypass
An issue was discovered in the com.dropbox.android application 98.2.2 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 3.6
CVE-2018-13137 WRITEUP MEDIUM
Events Manager 5.9.4 - Cross-Site Scripting via dbem_event_reapproved_email_body Parameter
The Events Manager plugin 5.9.4 for WordPress has XSS via the dbem_event_reapproved_email_body parameter to the wp-admin/edit.php?post_type=event&page=events-manager-options URI.
CVSS 4.8
CVE-2018-13434 WRITEUP MEDIUM
LINE 8.8.0 for iOS - Authentication Bypass via LAContext Return Value Override
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The LAContext class for Biometric (TouchID) validation allows authentication bypass by overriding the LAContext return Boolean value to be "true" because the kSecAccessControlUserPresence protection mechanism is not used. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred
CVSS 6.3
CVE-2018-13435 WRITEUP HIGH
LINE 8.8.0 - Authentication Bypass via Passcode Runtime Manipulation
An issue was discovered in the LINE jp.naver.line application 8.8.0 for iOS. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method to disable passcode authentication. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes iOS devices on which a jailbreak has occurred
CVSS 7.0
CVE-2018-13446 WRITEUP HIGH
LINE 8.8.1 - Authentication Bypass via Runtime Manipulation
An issue was discovered in the LINE jp.naver.line application 8.8.1 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 7.0
CVE-2018-14831 WRITEUP MEDIUM
DamiCMS 6.0.0 - Authenticated Arbitrary File Read via Tpl Add URI
An arbitrary file read vulnerability in DamiCMS v6.0.0 allows remote authenticated administrators to read any files in the server via a crafted /admin.php?s=Tpl/Add/id/ URI.
CVSS 4.9
CVE-2018-15542 WRITEUP MEDIUM
Telegram 4.8.11 - Authentication Bypass via Runtime Manipulation
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 6.4
CVE-2018-15543 WRITEUP MEDIUM
Telegram 4.8.11 - Authentication Bypass via FingerprintManager Callback
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 6.8
CVE-2018-15810 WRITEUP HIGH
Visiology Flipbox < 2.7.0 - Path Traversal via Filename Parameter
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
CVSS 7.5
CVE-2018-16243 WRITEUP MEDIUM
SolarWinds Database Performance Analyzer 11.1.468 and 12.0.3074 - Stored Cross-Site Scripting
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
CVSS 5.4
CVE-2018-16282 WRITEUP HIGH
Moxa EDR-810 V4.2 build 18041013 - OS Command Injection via caname Parameter
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.
CVSS 8.8
CVE-2018-16386 WRITEUP HIGH
SWIFT Alliance Web Platform 7.1.23 - Log Injection
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.
CVSS 7.5
CVE-2018-16450 WRITEUP MEDIUM
craftedweb < 2013-09-24 - Cross-Site Scripting via p Parameter
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
CVSS 6.1
CVE-2018-16590 WRITEUP CRITICAL
FURUNO FELCOM 250 and 500 - Improper Authentication via Client-Side JavaScript
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
CVSS 9.8
CVE-2018-16591 WRITEUP CRITICAL
FURUNO FELCOM 250 and 500 - Unauthenticated Password Change via sm_changepassword.cgi and sm_sms_changepasswd.cgi
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
CVSS 9.8
CVE-2018-16705 WRITEUP CRITICAL
FURUNO FELCOM 250-500 - Info Disclosure
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.
CVSS 9.8
CVE-2018-17572 WRITEUP MEDIUM
InfluxDB < 0.9.5 - Reflected Cross-Site Scripting in Write Data Module
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVSS 4.8
CVE-2018-18405 WRITEUP MEDIUM
jQuery 2.2.2 - Cross-Site Scripting via IMG onerror Attribute
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
CVSS 6.1