Exploit Database

153,618 exploits tracked across all sources.

Sort: Activity Stars
CVE-2018-15542 WRITEUP MEDIUM
Telegram 4.8.11 - Authentication Bypass via Runtime Manipulation
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 6.4
CVE-2018-15543 WRITEUP MEDIUM
Telegram 4.8.11 - Authentication Bypass via FingerprintManager Callback
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred
CVSS 6.8
CVE-2018-15810 WRITEUP HIGH
Visiology Flipbox < 2.7.0 - Path Traversal via Filename Parameter
Visiology Flipbox Software Suite before 2.7.0 allows directory traversal via %5c%2e%2e%2f because it does not sanitize filename parameters.
CVSS 7.5
CVE-2018-16243 WRITEUP MEDIUM
SolarWinds Database Performance Analyzer 11.1.468 and 12.0.3074 - Stored Cross-Site Scripting
SolarWinds Database Performance Analyzer (DPA) 11.1.468 and 12.0.3074 have several persistent XSS vulnerabilities, related to logViewer.iwc, centralManage.cen, userAdministration.iwc, database.iwc, alertManagement.iwc, eventAnnotations.iwc, and central.cen.
CVSS 5.4
CVE-2018-16282 WRITEUP HIGH
Moxa EDR-810 V4.2 build 18041013 - OS Command Injection via caname Parameter
A command injection vulnerability in the web server functionality of Moxa EDR-810 V4.2 build 18041013 allows remote attackers to execute arbitrary OS commands with root privilege via the caname parameter to the /xml/net_WebCADELETEGetValue URI.
CVSS 8.8
CVE-2018-16386 WRITEUP HIGH
SWIFT Alliance Web Platform 7.1.23 - Log Injection
An issue was discovered in SWIFT Alliance Web Platform 7.1.23. A log injection (and an arbitrary log filename) can be achieved via the PATH_INFO to swp/login/EJBRemoteService/, related to com.swift.ejbgwt.j2ee.client.EjBlnvocationException error log information containing null@java:comp/env/ error messages.
CVSS 7.5
CVE-2018-16450 WRITEUP MEDIUM
craftedweb < 2013-09-24 - Cross-Site Scripting via p Parameter
CraftedWeb through 2013-09-24 has reflected XSS via the p parameter.
CVSS 6.1
CVE-2018-16590 WRITEUP CRITICAL
FURUNO FELCOM 250 and 500 - Improper Authentication via Client-Side JavaScript
FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.
CVSS 9.8
CVE-2018-16591 WRITEUP CRITICAL
FURUNO FELCOM 250 and 500 - Unauthenticated Password Change via sm_changepassword.cgi and sm_sms_changepasswd.cgi
FURUNO FELCOM 250 and 500 devices allow unauthenticated users to change the password for the Admin, Log and Service accounts, as well as the password for the protected "SMS" panel via /cgi-bin/sm_changepassword.cgi and /cgi-bin/sm_sms_changepasswd.cgi.
CVSS 9.8
CVE-2018-16705 WRITEUP CRITICAL
FURUNO FELCOM 250-500 - Info Disclosure
FURUNO FELCOM 250 and 500 devices allow unauthenticated access to the xml/permission.xml file containing all of the system's usernames and passwords. This includes the Admin and Service user accounts and their unsalted MD5 hashes, as well as the SMS server password in cleartext.
CVSS 9.8
CVE-2018-17572 WRITEUP MEDIUM
InfluxDB < 0.9.5 - Reflected Cross-Site Scripting in Write Data Module
InfluxDB 0.9.5 has Reflected XSS in the Write Data module.
CVSS 4.8
CVE-2018-18405 WRITEUP MEDIUM
jQuery 2.2.2 - Cross-Site Scripting via IMG onerror Attribute
jQuery v2.2.2 allows XSS via a crafted onerror attribute of an IMG element. NOTE: this vulnerability has been reported to be spam entry
CVSS 6.1
CVE-2018-18476 WRITEUP CRITICAL
mysql-binuuid-rails < 1.1.0 - SQL Injection via Default String Escaping Removal
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
CVSS 9.8
CVE-2018-18754 WRITEUP CRITICAL
ZyXEL VMG3312-B10B 1.00(AAPP.7) - Insufficiently Protected Credentials
ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.
CVSS 9.8
CVE-2018-19326 WRITEUP HIGH
Zyxel VMG1312-B10D <5.13(AAXA.8)C0 - Path Traversal
Zyxel VMG1312-B10D devices before 5.13(AAXA.8)C0 allow ../ Directory Traversal, as demonstrated by reading /etc/passwd.
CVSS 7.5
CVE-2018-19391 WRITEUP MEDIUM
Cobham Satcom Sailor 250 and 500 Firmware < 1.25 - Unauthenticated Stored Cross-Site Scripting via Phone Book Name Field
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained persistent XSS, which could be exploited by an unauthenticated threat actor via the /index.lua?pageID=Phone%20book name field.
CVSS 6.1
CVE-2018-19392 WRITEUP CRITICAL
Cobham Satcom Sailor 250/500 <1.25 - Unauthenticated RCE
Cobham Satcom Sailor 250 and 500 devices before 1.25 contained an unauthenticated password reset vulnerability. This could allow modification of any user account's password (including the default "admin" account), without prior knowledge of their password. All that is required is knowledge of the username and attack vector (/index.lua?pageID=Administration usernameAdmChange, passwordAdmChange1, and passwordAdmChange2 fields).
CVSS 9.8
CVE-2018-19393 WRITEUP HIGH
Cobham Satcom Sailor 800/900 - Privilege Escalation
Cobham Satcom Sailor 800 and 900 devices contained a vulnerability that allowed for arbitrary writing of content to the system's configuration file. This was exploitable via multiple attack vectors depending on the device's configuration. Further analysis also indicated this vulnerability could be leveraged to achieve a Denial of Service (DoS) condition, where the device would require a factory reset to return to normal operation.
CVSS 7.5
CVE-2018-19394 WRITEUP MEDIUM
Cobham Satcom Sailor 800 and 900 Firmware - Authenticated Stored Cross-Site Scripting via Configuration File Restore
Cobham Satcom Sailor 800 and 900 devices contained persistent XSS, which required administrative access to exploit. The vulnerability was exploitable by acquiring a copy of the device's configuration file, inserting an XSS payload into a relevant field (e.g., Satellite name), and then restoring the malicious configuration file.
CVSS 4.8
CVE-2018-5258 WRITEUP MEDIUM
Neon app <1.6.14 iOS - Info Disclosure
The Neon app 1.6.14 iOS does not verify X.509 certificates from SSL servers, which allows remote attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVSS 5.9
CVE-2018-5761 WRITEUP HIGH
Rubrik CDM <4.0.4-p2 - Info Disclosure
A man-in-the-middle vulnerability related to vCenter access was found in Rubrik CDM 3.x and 4.x before 4.0.4-p2. This vulnerability might expose Rubrik user credentials configured to access vCenter as Rubrik clusters did not verify TLS certificates presented by vCenter.
CVSS 8.1
CVE-2018-6186 WRITEUP HIGH
Citrix NetScaler VPX through NS12.0 53.13.nc - Authenticated Server-Side Request Forgery via /rapi/read_url URI
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.
CVSS 8.8
CVE-2018-6311 WRITEUP MEDIUM
Foxconn femtocell FEMTO AP-FC4064-T - Privilege Escalation
One can gain root access on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via UART pins without any restrictions, which leads to full system compromise and disclosure of user communications.
CVSS 6.8
CVE-2018-6312 WRITEUP HIGH
Foxconn femtocell FEMTO AP-FC4064-T - Weak Default Password
A privileged account with a weak default password on the Foxconn femtocell FEMTO AP-FC4064-T version AP_GT_B38_5.8.3lb15-W47 LTE Build 15 can be used to turn on the TELNET service via the web interface, which allows root login without any password. This vulnerability will lead to full system compromise and disclosure of user communications. The foxconn account with an 8-character lowercase alphabetic password can be used.
CVSS 7.2
CVE-2018-6355 WRITEUP MEDIUM
iBall iB-WRB302N Firmware 1.0.1 - Unauthenticated Stored Cross-Site Scripting via lang Parameter
/goform/setLang on iBall 300M devices with "iB-WRB302N_1.0.1-Sep 8 2017" firmware has Unauthenticated Stored Cross Site Scripting via the lang parameter.
CVSS 6.1