Exploit Database

153,556 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-18476 WRITEUP CRITICAL
mysql-binuuid-rails < 1.1.0 - SQL Injection via Default String Escaping Removal
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
CVSS 9.8
CVE-2018-18754 WRITEUP CRITICAL
ZyXEL VMG3312-B10B 1.00(AAPP.7) - Insufficiently Protected Credentials
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
CVSS 9.8
CVE-2018-19326 WRITEUP HIGH
Zyxel VMG1312-B10D <5.13(AAXA.8)C0 - Path Traversal
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
CVSS 7.5
CVE-2018-19391 WRITEUP MEDIUM
Cobham Satcom Sailor 250 and 500 Firmware < 1.25 - Unauthenticated Stored Cross-Site Scripting via Phone Book Name Field
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.
CVSS 6.1
CVE-2018-19392 WRITEUP CRITICAL
Cobham Satcom Sailor 250/500 <1.25 - Unauthenticated RCE
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).
CVSS 9.8
CVE-2018-19393 WRITEUP HIGH
Cobham Satcom Sailor 800/900 - Privilege Escalation
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this vulnerability could be leveraged to achieve a Denial of Service (DoS) condition, where the device would require a factory reset to return to normal operation.
CVSS 7.5
CVE-2018-19394 WRITEUP MEDIUM
Cobham Satcom Sailor 800 and 900 Firmware - Authenticated Stored Cross-Site Scripting via Configuration File Restore
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
CVSS 4.8
CVE-2018-5258 WRITEUP MEDIUM
Neon app <1.6.14 iOS - Info Disclosure
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS 5.9
CVE-2018-5761 WRITEUP HIGH
Rubrik CDM <4.0.4-p2 - Info Disclosure
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
CVSS 8.1
CVE-2018-6186 WRITEUP HIGH
Citrix NetScaler VPX through NS12.0 53.13.nc - Authenticated Server-Side Request Forgery via /rapi/read_url URI
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.
CVSS 8.8
CVE-2018-6311 WRITEUP MEDIUM
Foxconn femtocell FEMTO AP-FC4064-T - Privilege Escalation
One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system compromise and disclosure of user communications.
CVSS 6.8
CVE-2018-6312 WRITEUP HIGH
Foxconn femtocell FEMTO AP-FC4064-T - Weak Default Password
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password. This vulnerability will lead to full system compromise and disclosure of user communications. The foxconn account with an 8-character lowercase alphabetic password can be used.
CVSS 7.2
CVE-2018-6355 WRITEUP MEDIUM
iBall iB-WRB302N Firmware 1.0.1 - Unauthenticated Stored Cross-Site Scripting via lang Parameter
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
CVSS 6.1
CVE-2018-6842 WRITEUP MEDIUM
Kentico Xperience 10.0-10.0.50 - Cross-Site Scripting via Crafted URL
Kentico 10 before 10.0.50 and 11 before 11.0.3 has XSS in which a crafted URL results in improper construction of a system page.
CVSS 5.4
CVE-2018-6843 WRITEUP HIGH
Kentico Xperience 10.0-10.0.50 - Authenticated SQL Injection
Kentico 10 before 10.0.50 and 11 before 11.0.3 has SQL injection in the administration interface.
CVSS 7.2
CVE-2018-8741 WRITEUP HIGH
SquirrelMail 1.4.22 - Path Traversal
A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.
CVSS 8.8
CVE-2018-9031 WRITEUP CRITICAL
TNLSoftSolutions Sentry Vision 3.x - Unauthenticated Password Disclosure via Client-Side Authentication
The login interface on TNLSoftSolutions Sentry Vision 3.x devices provides password disclosure by reading an "if(pwd ==" line in the HTML source code. This means, in effect, that authentication occurs only on the client side.
CVSS 9.8
CVE-2018-9111 WRITEUP MEDIUM
Foxconn AP-FC4064-T Firmware - Stored Cross-Site Scripting via User Account Configuration
Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configuration of a user account. An attacker can execute arbitrary script on an unsuspecting user's browser.
CVSS 5.4
CVE-2018-9112 WRITEUP CRITICAL
Foxconn AP-FC4064-T Firmware - Use of Hard-coded Credentials and Privilege Escalation via Cookie Manipulation
A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.
CVSS 9.8
CVE-2018-9177 WRITEUP MEDIUM
Twonky Server < 8.5.1 - Cross-Site Scripting via Shared Folders Screen
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
CVSS 6.1
CVE-2018-9182 WRITEUP MEDIUM
Twonky Server < 8.5.1 - Cross-Site Scripting via Language Parameter
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
CVSS 6.1
CVE-2018-9249 WRITEUP CRITICAL
FiberHome VDSL2 Modem HG 150-UB Firmware - Authentication Bypass via JavaScript Location Ignore
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
CVSS 9.8
CVE-2018-9921 WRITEUP MEDIUM
CMS Made Simple 2.2.7 - Path Traversal via Admin Checksum Endpoint
In CMS Made Simple 2.2.7, a Directory Traversal issue makes it possible to determine the existence of files and directories outside the web-site installation directory, and determine whether a file has contents matching a specified checksum. The attack uses an admin/checksum.php?__c= request.
CVSS 5.3
CVE-2018-9991 WRITEUP MEDIUM
Frog CMS 0.9.5 - Cross-Site Scripting via Admin User Add Name or Username Parameter
Frog CMS 0.9.5 has XSS via the /admin/?/user/add Name or Username parameter.
CVSS 4.8
CVE-2018-9992 WRITEUP MEDIUM
Frog CMS 0.9.5 - Stored Cross-Site Scripting via File Manager Name Field
Frog CMS 0.9.5 has XSS via the name field of a new "File" or "Directory" on the admin/?/plugin/file_manager/browse/ screen.
CVSS 4.8