Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-07-17 CVE-2018-14331 Cross-Site Request Forgery (CSRF) vulnerability in Xiaocms X1 20140305
An issue was discovered in XiaoCms X1 v20140305.
network
low complexity
xiaocms CWE-352
8.8
2018-07-17 CVE-2018-0710 OS Command Injection vulnerability in Qnap Q'Center
Command injection vulnerability in SSH of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
network
low complexity
qnap CWE-78
8.8
2018-07-17 CVE-2018-0709 OS Command Injection vulnerability in Qnap Q'Center
Command injection vulnerability in date of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
network
low complexity
qnap CWE-78
8.8
2018-07-17 CVE-2018-0708 OS Command Injection vulnerability in Qnap Q'Center
Command injection vulnerability in networking of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
network
low complexity
qnap CWE-78
8.8
2018-07-17 CVE-2018-0707 OS Command Injection vulnerability in Qnap Q'Center
Command injection vulnerability in change password of QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to run arbitrary commands.
network
low complexity
qnap CWE-78
7.2
2018-07-17 CVE-2018-0706 Unspecified vulnerability in Qnap Q'Center
Exposure of Private Information in QNAP Q'center Virtual Appliance version 1.7.1063 and earlier could allow authenticated users to access sensitive information.
network
low complexity
qnap
8.8
2018-07-16 CVE-2018-10857 Information Exposure vulnerability in multiple products
git-annex is vulnerable to a private data exposure and exfiltration attack.
network
low complexity
git-annex-project debian CWE-200
7.5
2018-07-16 CVE-2018-1046 Out-of-bounds Write vulnerability in Powerdns Pdns
pdns before version 4.1.2 is vulnerable to a buffer overflow in dnsreplay.
local
low complexity
powerdns CWE-787
7.8
2018-07-16 CVE-2018-14326 Integer Overflow or Wraparound vulnerability in Techsmith Mp4V2 2.0.0
In MP4v2 2.0.0, there is an integer overflow (with resultant memory corruption) when resizing MP4Array for the ftyp atom in mp4array.h.
network
low complexity
techsmith CWE-190
8.8
2018-07-16 CVE-2018-14325 Integer Underflow (Wrap or Wraparound) vulnerability in Techsmith Mp4V2 2.0.0
In MP4v2 2.0.0, there is an integer underflow (with resultant memory corruption) when parsing MP4Atom in mp4atom.cpp.
network
low complexity
techsmith CWE-191
8.8