Show filters
596 Total Results
Displaying 131-140 of 596
Sort by:
Attacker Value
Unknown
CVE-2018-12206
Disclosure Date: December 14, 2018 (last updated November 27, 2024)
Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
0
Attacker Value
Unknown
CVE-2018-3854
Disclosure Date: December 03, 2018 (last updated November 27, 2024)
An exploitable information disclosure vulnerability exists in the password protection functionality of Quicken Deluxe 2018 for Mac version 5.2.2. A specially crafted sqlite3 request can cause the removal of the password protection, allowing an attacker to access and modify the data without knowing the password. An attacker needs to have access to the password-protected files to trigger this vulnerability.
0
Attacker Value
Unknown
CVE-2018-12193
Disclosure Date: October 10, 2018 (last updated November 27, 2024)
Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.
0
Attacker Value
Unknown
CVE-2018-17102
Disclosure Date: September 16, 2018 (last updated November 27, 2024)
An issue was discovered in QuickAppsCMS (aka QACMS) through 2.0.0-beta2. A CSRF vulnerability can change the administrator password via the user/me URI.
0
Attacker Value
Unknown
CVE-2018-1999022
Disclosure Date: July 23, 2018 (last updated November 27, 2024)
PEAR HTML_QuickForm version 3.2.14 contains an eval injection (CWE-95) vulnerability in HTML_QuickForm's getSubmitValue method, HTML_QuickForm's validate method, HTML_QuickForm_hierselect's _setOptions method, HTML_QuickForm_element's _findValue method, HTML_QuickForm_element's _prepareValue method. that can result in Possible information disclosure, possible impact on data integrity and execution of arbitrary code. This attack appear to be exploitable via A specially crafted query string could be utilised, e.g. http://www.example.com/admin/add_practice_type_id[1]=fubar%27])%20OR%20die(%27OOK!%27);%20//&mode=live. This vulnerability appears to have been fixed in 3.2.15.
0
Attacker Value
Unknown
CVE-2018-12534
Disclosure Date: June 18, 2018 (last updated November 26, 2024)
A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.
0
Attacker Value
Unknown
CVE-2017-16196
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
quickserver is a simple static file server. quickserver is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
0
Attacker Value
Unknown
CVE-2017-16109
Disclosure Date: June 07, 2018 (last updated November 26, 2024)
easyquick is a simple web server. easyquick is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. Access is constrained, however, to supported file types. Requesting a file such as /etc/passwd returns a "not supported" error.
0
Attacker Value
Unknown
CVE-2018-11485
Disclosure Date: June 01, 2018 (last updated November 26, 2024)
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admin page. The attack is possible by modifying the "referral_site" cookie to have an XSS payload, and placing an order.
0
Attacker Value
Unknown
CVE-2018-9108
Disclosure Date: March 28, 2018 (last updated November 26, 2024)
CSRF in /admin/user/manage/add in QuickAppsCMS 2.0.0-beta2 allows an unauthorized remote attacker to create an account with admin privileges.
0