Vulnerabilities > High

DATE CVE VULNERABILITY TITLE RISK
2018-03-08 CVE-2018-0209 Unspecified vulnerability in Cisco Small Business 500 Series Stackable Managed Switches Firmware 2.2.5.68/2.3.0.130
A vulnerability in the Simple Network Management Protocol (SNMP) subsystem communication channel through the Cisco 550X Series Stackable Managed Switches could allow an authenticated, remote attacker to cause the device to reload unexpectedly, causing a denial of service (DoS) condition.
network
low complexity
cisco
7.7
2018-03-08 CVE-2018-0141 Use of Hard-coded Credentials vulnerability in Cisco products
A vulnerability in Cisco Prime Collaboration Provisioning (PCP) Software 11.6 could allow an unauthenticated, local attacker to log in to the underlying Linux operating system.
local
low complexity
cisco CWE-798
8.4
2018-03-07 CVE-2018-7752 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in multiple products
GPAC through 0.7.1 has a Buffer Overflow in the gf_media_avc_read_sps function in media_tools/av_parsers.c, a different vulnerability than CVE-2018-1000100.
local
low complexity
gpac debian canonical CWE-119
7.8
2018-03-07 CVE-2017-12174 It was found that when Artemis and HornetQ before 2.4.0 are configured with UDP discovery and JGroups discovery a huge byte array is created when receiving an unexpected multicast message.
network
low complexity
apache redhat
7.5
2018-03-07 CVE-2018-7565 Cross-Site Request Forgery (CSRF) vulnerability in Polycom QDX 6000 Firmware
CSRF exists on Polycom QDX 6000 devices.
network
low complexity
polycom CWE-352
8.8
2018-03-07 CVE-2018-7204 Information Exposure Through Log Files vulnerability in Giribaz File Manager
inc/logger.php in the Giribaz File Manager plugin before 5.0.2 for WordPress logged activity related to the plugin in /wp-content/uploads/file-manager/log.txt.
network
low complexity
giribaz CWE-532
7.5
2018-03-07 CVE-2018-5452 Out-of-bounds Write vulnerability in Emerson Controlwave Micro Firmware 05.78.00
A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior.
network
low complexity
emerson CWE-787
7.5
2018-03-07 CVE-2018-7746 Cross-site Scripting vulnerability in Cobub Razor 0.7.2
An issue was discovered in Western Bridge Cobub Razor 0.7.2.
network
low complexity
cobub CWE-79
8.8
2018-03-07 CVE-2018-7745 Improper Authentication vulnerability in Cobub Razor 0.7.2
An issue was discovered in Western Bridge Cobub Razor 0.7.2.
network
low complexity
cobub CWE-287
7.5
2018-03-07 CVE-2018-1000118 OS Command Injection vulnerability in Electronjs Electron
Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute.
network
low complexity
electronjs CWE-78
8.8