Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-02 CVE-2018-16365 Cross-Site Request Forgery (CSRF) vulnerability in Idreamsoft Icms 7.0.10
An issue was discovered in idreamsoft iCMS V7.0.10.
network
low complexity
idreamsoft CWE-352
8.8
2018-09-02 CVE-2018-16345 Cross-Site Request Forgery (CSRF) vulnerability in Easycms 1.5
An issue was discovered in EasyCMS 1.5.
network
low complexity
easycms CWE-352
8.8
2018-09-02 CVE-2018-16344 Path Traversal vulnerability in Zzcms 8.3
An issue was discovered in zzcms 8.3.
network
low complexity
zzcms CWE-22
7.5
2018-09-02 CVE-2018-16343 Code Injection vulnerability in Seacms 6.61
SeaCMS 6.61 allows remote attackers to execute arbitrary code because parseIf() in include/main.class.php does not block use of $GLOBALS.
network
low complexity
seacms CWE-94
7.2
2018-09-02 CVE-2018-16339 Cross-Site Request Forgery (CSRF) vulnerability in Phome Empirecms 7.0
An issue was discovered in EmpireCMS 7.0.
network
low complexity
phome CWE-352
8.8
2018-09-02 CVE-2018-16338 Cross-Site Request Forgery (CSRF) vulnerability in Auracms 2.3
An issue was discovered in AuraCMS 2.3.
network
low complexity
auracms CWE-352
8.8
2018-09-02 CVE-2018-16335 Out-of-bounds Write vulnerability in multiple products
newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf.
network
low complexity
libtiff debian CWE-787
8.8
2018-09-02 CVE-2018-16334 OS Command Injection vulnerability in Tendacn Ac10 Firmware and AC9 Firmware
An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN and AC10 V15.03.06.23_CN devices.
network
low complexity
tendacn CWE-78
8.8
2018-09-02 CVE-2018-16333 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Tendacn products
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices.
network
low complexity
tendacn CWE-119
7.5
2018-09-02 CVE-2018-16332 Cross-Site Request Forgery (CSRF) vulnerability in Idreamsoft Icms 7.0.9
An issue was discovered in iCMS 7.0.9.
network
low complexity
idreamsoft CWE-352
8.8