CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Escanav
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002...Show more
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020F8.Show less
1Escanav
1Anti Virus
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.8 HIGH· v3
6.1 MEDIUM· v2
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x83002...Show more
In eScan Antivirus 14.0.1400.2029, the driver file (econceal.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x830020E0 or 0x830020E4.Show less
1Vbulletin
1Vbulletin
Jun 17, 2026
Jan 25, 2018
N/A· v4
6.1 MEDIUM· v3
5.8 MEDIUM· v2
vBulletin 3.x.x and 4.2.x through 4.2.5 has an open redirect via the redirector.php url parameter.
2Canonical
Tats
2Ubuntu Linux
W3m
Jun 17, 2026
Jan 25, 2018
N/A· v4
4.7 MEDIUM· v3
3.3 LOW· v2
w3m through 0.5.3 does not properly handle temporary files when the ~/.w3m directory is unwritable, which allows a local attacker to craft a symlink attack to overwrite arbitrary files.
2Canonical
Tats
2Ubuntu Linux
W3m
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
w3m through 0.5.3 is prone to a NULL pointer dereference flaw in formUpdateBuffer in form.c.
2Canonical
Tats
2Ubuntu Linux
W3m
Jun 17, 2026
Jan 25, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
w3m through 0.5.3 is prone to an infinite recursion flaw in HTMLlineproc0 because the feed_table_block_tag function in table.c does not prevent a negative indent value.
1Splashing Images Project
1Splashing Images
Jun 17, 2026
Jan 30, 2018
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object In...Show more
admin/partials/wp-splashing-admin-main.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows authenticated (administrator, editor, or author) remote attackers to conduct PHP Object Injection attacks via crafted serialized data in the 'session' HTTP GET parameter to wp-admin/upload.php.Show less
1Splashing Images Project
1Splashing Images
Jun 17, 2026
Jan 30, 2018
N/A· v4
4.8 MEDIUM· v3
3.5 LOW· v2
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web...Show more
A cross-site scripting (XSS) vulnerability in admin/partials/wp-splashing-admin-sidebar.php in the Splashing Images plugin (wp-splashing-images) before 2.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the search parameter to wp-admin/upload.php.Show less
1Routers2 Project
1Routers2
Jun 17, 2026
Jan 24, 2018
N/A· v4
4.7 MEDIUM· v3
2.6 LOW· v2
A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl.
2Artifex
Debian
2Debian Linux
Mupdf
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.
1Artifex
1Mujs
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.
1Netis Systems
1Wf2419 Firmware
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.
1F Secure
1Radar
Jun 17, 2026
Feb 16, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested...Show more
F-Secure Radar (on-premises) before 2018-02-15 has XSS via vectors involving the Tags parameter in the JSON request body in an outbound request for the /api/latest/vulnerabilityscans/tags/batch resource, aka a "suggested metadata tags for assets" issue.Show less
2Canonical
Djangoproject
2Django
Ubuntu Linux
Jun 17, 2026
Feb 5, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allow...Show more
django.contrib.auth.forms.AuthenticationForm in Django 2.0 before 2.0.2, and 1.11.8 and 1.11.9, allows remote attackers to obtain potentially sensitive information by leveraging data exposure from the confirm_login_allowed() method, as demonstrated by discovering whether a user account is inactive.Show less
2Artifex
Debian
2Debian Linux
Mupdf
Jun 17, 2026
Jan 24, 2018
N/A· v4
5.5 MEDIUM· v3
4.3 MEDIUM· v2
In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of servic...Show more
In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.Show less
1Citrix
1Netscaler
Jun 17, 2026
Feb 1, 2018
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote...Show more
Citrix NetScaler VPX through NS12.0 53.13.nc allows an SSRF attack via the /rapi/read_url URI by an authenticated attacker who has a webapp account. The attacker can gain access to the nsroot account, and execute remote commands with root privileges.Show less
1Zeit
1Next.js
Jun 17, 2026
Jan 24, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.
1Bitdefender
1Total Security
Jun 17, 2026
Mar 12, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of an "insecurely created named pipe". Ensures full access to Everyone users...Show more
BitDefender Total Security 2018 allows local users to gain privileges or cause a denial of service by impersonating all the pipes through a use of an "insecurely created named pipe". Ensures full access to Everyone users group.Show less
1Mahara
1Mahara
Jun 17, 2026
Apr 9, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but...Show more
Mahara 16.10 before 16.10.9 and 17.04 before 17.04.7 and 17.10 before 17.10.4 are vulnerable to bad input when TinyMCE is bypassed by POST packages. Therefore, Mahara should not rely on TinyMCE's code stripping alone but also clean input on the server / PHP side as one can create own packets of POST data containing bad content with which to hit the server.Show less
1Themashabrand
1Online Voting Platform
Jun 17, 2026
Feb 8, 2018
N/A· v4
9.8 CRITICAL· v3
5.0 MEDIUM· v2
A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.
15none
1Nonecms
Jun 17, 2026
Jan 23, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server Side Request Forgery (SSRF), because URL...Show more
The copy function in application/admin/controller/Article.php in NoneCms 1.3.0 allows remote attackers to access the content of internal and external network resources via Server Side Request Forgery (SSRF), because URL validation only considers whether the URL contains the "csdn" substring.Show less
1Thethinkery
1Project Log
Jun 17, 2026
Feb 18, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.
1Fastweb
1Fastgate Firmware
Jun 17, 2026
May 11, 2018
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.
15none
1Nonecms
Jun 17, 2026
Jan 23, 2018
N/A· v4
6.5 MEDIUM· v3
5.5 MEDIUM· v2
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the par...Show more
Directory traversal vulnerability in application/admin/controller/Main.php in NoneCms through 1.3.0 allows remote authenticated users to delete arbitrary files by leveraging back-office access to provide a ..\ in the param.path parameter.Show less
1Silextechnology
2Geh Sd 320an Firmware
Sd 320an Firmware
Jun 17, 2026
May 9, 2018
N/A· v4
7.4 HIGH· v3
6.5 MEDIUM· v2
Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution.