CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-l...Show more
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the NBAP dissector could crash with a large loop that ends with a heap-based buffer overflow. This was addressed in epan/dissectors/packet-nbap.c by prohibiting the self-linking of DCH-IDs.Show less
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the IEEE 802.15.4 dissector could crash. This was addressed in epan/dissectors/packet-ieee802154.c by ensuring that an allocation step occurs.
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the MP4 dissector could crash. This was addressed in epan/dissectors/file-mp4.c by restricting the box recursion depth.
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.5, the TCP dissector could crash. This was addressed in epan/dissectors/packet-tcp.c by preserving valid data sources.
1Wireshark
1Wireshark
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.5, the CQL dissector could go into an infinite loop. This was addressed in epan/dissectors/packet-cql.c by checking for a nonzero number of columns.
2Debian
Wireshark
2Debian Linux
Wireshark
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
In Wireshark 2.4.0 to 2.4.5 and 2.2.0 to 2.2.13, the LWAPP dissector could crash. This was addressed in epan/dissectors/packet-lwapp.c by limiting the encapsulation levels to restrict the recursion depth.
1Jasper Project
1Jasper
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.
2Debian
Xmlsoft
2Debian Linux
Libxml2
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.3 MEDIUM· v3
2.6 LOW· v2
The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated b...Show more
The xz_decomp function in xzlib.c in libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035.Show less
1Open Emr
1Openemr
Jun 17, 2026
May 18, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.
1Fiberhome
1Vdsl2 Modem Hg 150 Ub Firmware
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass by ignoring the parent.location='login.html' JavaScript code in the response to an unauthenticated request.
1Fiberhome
1Vdsl2 Modem Hg 150 Ub Firmware
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.
1Gxlcms
1Gxlcms Qy
Jun 17, 2026
Apr 4, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary P...Show more
The upsql function in \Lib\Lib\Action\Admin\DataAction.class.php in Gxlcms QY v1.0.0713 allows remote attackers to execute arbitrary SQL statements via the sql parameter. Consequently, an attacker can execute arbitrary PHP code by placing it after a <?php substring, and then using INTO OUTFILE with a .php filename.Show less
2Ledgersmb
Pgobject Util Dbadmin Project
2Ledgersmb
Pgobject Util Dbadmin
Jun 17, 2026
Jun 8, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injecti...Show more
The PGObject::Util::DBAdmin module before 0.120.0 for Perl, as used in LedgerSMB through 1.5.x, insufficiently sanitizes or escapes variable values used as part of shell command execution, resulting in shell code injection via the create(), run_file(), backup(), or restore() function. The vulnerability allows unauthorized users to execute code with the same privileges as the running application.Show less
1Ericssonlg
1Ipecs Nms
Jun 17, 2026
Apr 22, 2018
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.
1Gitlab
1Gitlab
Jun 17, 2026
Apr 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the m...Show more
GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.Show less
1Gitlab
1Gitlab
Jun 17, 2026
Apr 5, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes ta...Show more
GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.Show less
1Paloaltonetworks
1Pan Os
Jun 17, 2026
Jul 3, 2018
N/A· v4
5.5 MEDIUM· v3
6.6 MEDIUM· v2
The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.
3Canonical
DebianNcmpc Project
3Debian Linux
NcmpcUbuntu Linux
Jun 17, 2026
Apr 3, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
ncmpc through 0.29 is prone to a NULL pointer dereference flaw. If a user uses the chat screen and another client sends a long chat message, a crash and denial of service could occur.
1Yahei
1Yahei Php Prober
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.
1Iscripts
1Easycreate
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.
1Iscripts
1Easycreate
Jun 17, 2026
Apr 4, 2018
N/A· v4
5.4 MEDIUM· v3
3.5 LOW· v2
iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.
1Iscripts
1Sonicbb
Jun 17, 2026
Apr 4, 2018
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.
2Canonical
Gnupg
2Gnupg
Ubuntu Linux
Jun 17, 2026
Apr 4, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subke...Show more
GnuPG 2.2.4 and 2.2.5 does not enforce a configuration in which key certification requires an offline master Certify key, which results in apparently valid certifications that occurred only with access to a signing subkey.Show less
1Sophos
1Endpoint Protection
Jun 17, 2026
Apr 5, 2018
N/A· v4
7.8 HIGH· v3
2.1 LOW· v2
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and su...Show more
Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.Show less
1Twsz
1Be126 Firmware
Jun 17, 2026
May 1, 2018
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update.