Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-24 CVE-2013-3023 Information Exposure vulnerability in IBM Tivoli Application Dependency Discovery Manager
IBM Tivoli Application Dependency Discovery Manager (TADDM) 7.1.2 and 7.2.0 through 7.2.1.4 might allow remote attackers to obtain sensitive information about Tomcat credentials by sniffing the network for a session in which HTTP is used.
network
high complexity
ibm CWE-200
8.1
2018-05-24 CVE-2018-7526 Forced Browsing vulnerability in Beaconmedaes Scroll Medical AIR Systems Firmware
In TotalAlert Web Application in BeaconMedaes Scroll Medical Air Systems prior to v4107600010.23, by accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access information in the application without authenticating.
network
low complexity
beaconmedaes CWE-425
7.5
2018-05-24 CVE-2018-11416 Double Free vulnerability in Jpegoptim Project Jpegoptim 1.4.5
jpegoptim.c in jpegoptim 1.4.5 (fixed in 1.4.6) has an invalid use of realloc() and free(), which allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.
network
low complexity
jpegoptim-project CWE-415
8.8
2018-05-24 CVE-2018-11414 SQL Injection vulnerability in Bearadmin Project Bearadmin 0.5
An issue was discovered in BearAdmin 0.5.
network
low complexity
bearadmin-project CWE-89
8.8
2018-05-24 CVE-2018-7942 Unspecified vulnerability in Huawei products
The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have an authentication bypass vulnerability.
network
low complexity
huawei
7.5
2018-05-24 CVE-2018-7904 Unspecified vulnerability in Huawei 1288H V5 Firmware and 2288H V5 Firmware
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability.
network
low complexity
huawei
8.8
2018-05-24 CVE-2018-7903 Unspecified vulnerability in Huawei 1288H V5 Firmware and 2288H V5 Firmware
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability.
network
low complexity
huawei
8.8
2018-05-24 CVE-2018-7902 Unspecified vulnerability in Huawei 1288H V5 Firmware and 2288H V5 Firmware
Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability.
network
low complexity
huawei
8.8
2018-05-24 CVE-2018-5485 Unspecified vulnerability in Netapp Oncommand Unified Manager 7.2/7.3
NetApp OnCommand Unified Manager for Windows versions 7.2 through 7.3 are susceptible to a vulnerability which could lead to a privilege escalation attack.
local
low complexity
netapp
7.8
2018-05-24 CVE-2018-1000039 Use After Free vulnerability in Artifex Mupdf
In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.
local
low complexity
artifex CWE-416
7.8