Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-05-01 CVE-2018-10256 SQL Injection vulnerability in Hrsale Project Hrsale 1.0.2
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.
network
low complexity
hrsale-project CWE-89
8.8
2018-05-01 CVE-2018-10255 Improper Neutralization of Formula Elements in a CSV File vulnerability in Clustercoding Blog Master PRO 1.0.0
A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.
network
low complexity
clustercoding CWE-1236
8.8
2018-05-01 CVE-2013-2049 Session Fixation vulnerability in Redhat Cloudforms Management Engine 2.0
Red Hat CloudForms 2 Management Engine (CFME) allows remote attackers to conduct session tampering attacks by leveraging use of a static secret_token.rb secret.
network
low complexity
redhat CWE-384
7.5
2018-05-01 CVE-2013-0185 Cross-Site Request Forgery (CSRF) vulnerability in Redhat Manageiq Enterprise Virtualization Manager
Cross-site request forgery (CSRF) vulnerability in ManageIQ Enterprise Virtualization Manager (EVM) allows remote attackers to hijack the authentication of users for requests that have unspecified impact via unknown vectors.
network
low complexity
redhat CWE-352
8.8
2018-05-01 CVE-2013-0159 Link Following vulnerability in Fedoraproject Fedora 17/18
The fedora-business-cards package before 1-0.1.beta1.fc17 on Fedora 17 and before 1-0.1.beta1.fc18 on Fedora 18 allows local users to cause a denial of service or write to arbitrary files via a symlink attack on /tmp/fedora-business-cards-buffer.svg.
local
low complexity
fedoraproject CWE-59
7.1
2018-05-01 CVE-2018-9336 Double Free vulnerability in multiple products
openvpnserv.exe (aka the interactive service helper) in OpenVPN 2.4.x before 2.4.6 allows a local attacker to cause a double-free of memory by sending a malformed request to the interactive service.
local
low complexity
openvpn slackware CWE-415
7.8
2018-05-01 CVE-2018-9232 Improper Authentication vulnerability in Twsz Be126 Firmware
Due to the lack of firmware authentication in the upgrade process of T&W WIFI Repeater BE126 devices, an attacker can craft a malicious firmware and use it as an update.
local
low complexity
twsz CWE-287
7.8
2018-05-01 CVE-2018-6589 Unspecified vulnerability in CA Spectrum
CA Spectrum 10.1 prior to 10.01.02.PTF_10.1.239 and 10.2.x prior to 10.2.3 allows remote attackers to cause a denial of service via unspecified vectors.
network
low complexity
ca
7.5
2018-05-01 CVE-2013-4035 Cryptographic Issues vulnerability in IBM Sterling Connect
IBM Sterling Connect:Direct for OpenVMS 3.4.00, 3.4.01, 3.5.00, 3.6.0, and 3.6.0.1 allow remote attackers to have unspecified impact by leveraging failure to reject client requests for an unencrypted session when used as the server in a TCP/IP session and configured for SSL encryption with the client.
low complexity
ibm CWE-310
7.3
2018-05-01 CVE-2018-10583 Information Exposure vulnerability in multiple products
An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.
network
low complexity
libreoffice apache debian redhat canonical CWE-200
7.5