Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-09-22 CVE-2018-17332 Missing Release of Resource after Effective Lifetime vulnerability in Libsvg2 Project Libsvg2
An issue was discovered in libsvg2 through 2012-10-19.
network
low complexity
libsvg2-project CWE-772
7.5
2018-09-21 CVE-2018-14891 Unspecified vulnerability in Vectra Cognito
Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability.
local
low complexity
vectra
7.8
2018-09-21 CVE-2018-14889 Improper Input Validation vulnerability in Apache Couchdb
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
local
low complexity
apache CWE-20
7.8
2018-09-21 CVE-2018-12169 Improper Authentication vulnerability in multiple products
Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.
low complexity
intel lenovo CWE-287
7.6
2018-09-21 CVE-2018-17050 Integer Overflow or Wraparound vulnerability in Polyai Project Polyai
The mintToken function of a smart contract implementation for PolyAi (AI), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
network
low complexity
polyai-project CWE-190
7.5
2018-09-21 CVE-2018-15612 Cross-Site Request Forgery (CSRF) vulnerability in Avaya Orchestration Designer 7.1
A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings.
network
low complexity
avaya CWE-352
8.8
2018-09-21 CVE-2018-14732 Improper Input Validation vulnerability in Webpack.Js Webpack-Dev-Server
An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6.
network
low complexity
webpack-js CWE-20
7.5
2018-09-21 CVE-2018-14731 Information Exposure vulnerability in Parceljs Parcel
An issue was discovered in HMRServer.js in Parcel parcel-bundler.
network
low complexity
parceljs CWE-200
7.5
2018-09-21 CVE-2018-14730 Information Exposure vulnerability in Browserify-Hot Module Replacement Project Browserify-Hot Module Replacement
An issue was discovered in Browserify-HMR.
7.5
2018-09-21 CVE-2018-12511 Integer Overflow or Wraparound vulnerability in Substratum
In the mintToken function of a smart contract implementation for Substratum (SUB), an Ethereum ERC20 token, the administrator can control mintedAmount, leverage an integer overflow, and modify a user account's balance arbitrarily.
network
low complexity
substratum CWE-190
7.5