CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2019-3497

    Last Modified: 21 Nov 2024

    An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. The tools/ping Ping feature of the Diagnostic Tools component is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.

    Published: 18 Mar 2019
    8.8
    High

    CVE-2019-3496

    Last Modified: 21 Nov 2024

    An issue was discovered on Wifi-soft UniBox controller 3.x devices. The tools/controller/diagnostic_tools_controller Diagnostic Tools Controller is vulnerable to Remote Command Execution, allowing an attacker to execute arbitrary system commands on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.

    Published: 18 Mar 2019
    8.8
    High

    CVE-2019-3495

    Last Modified: 21 Nov 2024

    An issue was discovered on Wifi-soft UniBox controller 0.x through 2.x devices. network/mesh/edit-nds.php is vulnerable to arbitrary file upload, allowing an attacker to upload .php files and execute code on the server with root user privileges. Authentication for accessing this component can be bypassed by using Hard coded credentials.

    Published: 18 Mar 2019
    8.8
    High

    CVE-2018-20556

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.

    Published: 18 Mar 2019
    9.8
    Critical

    CVE-2018-20555

    Last Modified: 21 Nov 2024

    The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.

    Published: 18 Mar 2019
    9.8
    Critical

    CVE-2018-20526

    Last Modified: 21 Nov 2024

    Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

    Published: 18 Mar 2019
    9.1
    Critical

    CVE-2018-20525

    Last Modified: 21 Nov 2024

    Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2016-9166

    Last Modified: 21 Nov 2024

    NetIQ eDirectory versions prior to 9.0.2, under some circumstances, could be susceptible to downgrade of communication security.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2018-11789

    Last Modified: 21 Nov 2024

    When accessing the heron-ui webpage, people can modify the file paths outside of the current container to access any file on the host. Example woule be modifying the parameter path= to go to the directory you would like to view. i.e. ..%2F..%2F..%2F..%2F..%2F..%2Fetc%2Fpasswd.

    Published: 18 Mar 2019
    6.5
    Medium

    CVE-2019-16707

    Last Modified: 21 Nov 2024

    Hunspell 1.7.0 has an invalid read operation in SuggestMgr::leftcommonsubstring in suggestmgr.cxx.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-9936

    Last Modified: 21 Nov 2024

    In SQLite 3.27.2, running fts5 prefix queries inside a transaction could trigger a heap-based buffer over-read in fts5HashEntrySort in sqlite3.c, which may lead to an information leak. This is related to ext/fts5/fts5_hash.c.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-10894

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the GSS-API dissector could crash. This was addressed in epan/dissectors/packet-gssapi.c by ensuring that a valid dissector is called.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-10900

    Last Modified: 21 Nov 2024

    In Wireshark 3.0.0, the Rbm dissector could go into an infinite loop. This was addressed in epan/dissectors/file-rbm.c by handling unknown object types safely.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-9937

    Last Modified: 21 Nov 2024

    In SQLite 3.27.2, interleaving reads and writes in a single transaction with an fts5 virtual table will lead to a NULL Pointer Dereference in fts5ChunkIterate in sqlite3.c. This is related to ext/fts5/fts5_hash.c and ext/fts5/fts5_index.c.

    Published: 18 Mar 2019
    7.5
    High

    CVE-2019-10896

    Last Modified: 21 Nov 2024

    In Wireshark 2.4.0 to 2.4.13, 2.6.0 to 2.6.7, and 3.0.0, the DOF dissector could crash. This was addressed in epan/dissectors/packet-dof.c by properly handling generated IID and OID bytes.

    Published: 18 Mar 2019
    9.8
    Critical

    CVE-2018-19514

    Last Modified: 21 Nov 2024

    In Webgalamb through 7.0, an arbitrary code execution vulnerability could be exploited remotely without authentication. Exploitation requires authentication bypass to access administrative functions of the site to upload a crafted CSV file with a malicious payload that becomes part of a PHP eval() expression in the subscriber.php file.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-19513

    Last Modified: 21 Nov 2024

    In Webgalamb through 7.0, log files are exposed to the internet with predictable files/logs/sql_error_log/YYYY-MM-DD-sql_error_log.log filenames. The log file could contain sensitive client data (email addresses) and also facilitates exploitation of SQL injection errors.

    Published: 17 Mar 2019
    7.2
    High

    CVE-2018-19512

    Last Modified: 21 Nov 2024

    In Webgalamb through 7.0, a system/ajax.php "wgmfile restore" directory traversal vulnerability could lead to arbitrary code execution by authenticated administrator users, because PHP files are restored under the document root directory.

    Published: 17 Mar 2019
    6.5
    Medium

    CVE-2018-19511

    Last Modified: 21 Nov 2024

    wg7.php in Webgalamb 7.0 lacks security measures to prevent CSRF attacks, as demonstrated by wg7.php?options=1 to change the administrator password.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-19510

    Last Modified: 21 Nov 2024

    subscriber.php in Webgalamb through 7.0 is vulnerable to SQL injection via the Client-IP HTTP request header.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-19509

    Last Modified: 21 Nov 2024

    wg7.php in Webgalamb 7.0 makes opportunistic calls to htmlspecialchars() instead of using a templating engine with proper contextual encoding. Because it is possible to insert arbitrary strings into the database, any JavaScript could be executed by the administrator, leading to XSS.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-19498

    Last Modified: 21 Nov 2024

    The Simplenia Pages plugin 2.6.0 for Atlassian Bitbucket Server has XSS.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-16519

    Last Modified: 21 Nov 2024

    COYO 9.0.8, 10.0.11 and 12.0.4 has cross-site scripting (XSS) via URLs used by "iFrame" widgets.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2018-20323

    Last Modified: 21 Nov 2024

    www/soap/application/MCSoap/Logs.php in MailCleaner Community Edition 2018.08 allows remote attackers to execute arbitrary OS commands.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-19488

    Last Modified: 21 Nov 2024

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_reset_pass() function through the admin-ajax.php file, which allows remote unauthenticated attackers to reset the password of a user's account.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-19487

    Last Modified: 21 Nov 2024

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.

    Published: 17 Mar 2019
    7.2
    High

    CVE-2018-15906

    Last Modified: 21 Nov 2024

    SolarWinds Serv-U FTP Server 15.1.6 allows remote authenticated users to execute arbitrary code by leveraging the Import feature and modifying a CSV file.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-15818

    Last Modified: 21 Nov 2024

    An issue was discovered in Repute ARForms 3.5.1 and prior. An attacker is able to delete any file on the server with web server privileges by sending a malicious request to admin-ajax.php.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-19276

    Last Modified: 21 Nov 2024

    OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

    Published: 17 Mar 2019
    5.4
    Medium

    CVE-2018-19191

    Last Modified: 21 Nov 2024

    Webmin 1.890 has XSS via /config.cgi?webmin, the /shell/index.cgi history parameter, /shell/index.cgi?stripped=1, or the /webminlog/search.cgi uall or mall parameter.

    Published: 17 Mar 2019
    3.8
    Low

    CVE-2018-15532

    Last Modified: 21 Nov 2024

    SynTP.sys in Synaptics Touchpad drivers before 2018-06-06 allows local users to obtain sensitive information about freed kernel addresses.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-19158

    Last Modified: 21 Nov 2024

    ColossusCoinXT through 1.0.5 (a chain-based proof-of-stake cryptocurrency) allows a remote denial of service, exploitable by an attacker who acquires even a small amount of stake/coins in the system. The attacker sends invalid headers/blocks, which are stored on the victim's disk.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2018-14575

    Last Modified: 21 Nov 2024

    Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-18898

    Last Modified: 21 Nov 2024

    The email-ingestion feature in Best Practical Request Tracker 4.1.13 through 4.4 allows denial of service by remote attackers via an algorithmic complexity attack on email address parsing.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-14486

    Last Modified: 21 Nov 2024

    DNN (formerly DotNetNuke) 9.1.1 allows cross-site scripting (XSS) via XML.

    Published: 17 Mar 2019
    5.4
    Medium

    CVE-2018-18882

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can inject arbitrary script via setup.html in the web interface.

    Published: 17 Mar 2019
    6.5
    Medium

    CVE-2018-18881

    Last Modified: 21 Nov 2024

    A Denial of Service (DOS) issue was discovered in ControlByWeb X-320M-I Web-Enabled Instrumentation-Grade Data Acquisition module 1.05 with firmware revision v1.05. An authenticated user can configure invalid network settings, stopping TCP based communications to the device. A physical factory reset is required to restore the device to an operational state.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2018-20221

    Last Modified: 21 Nov 2024

    Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.

    Published: 17 Mar 2019
    7.5
    High

    CVE-2018-20220

    Last Modified: 21 Nov 2024

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.

    Published: 17 Mar 2019
    8.1
    High

    CVE-2018-20219

    Last Modified: 21 Nov 2024

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.

    Published: 17 Mar 2019
    9.8
    Critical

    CVE-2018-20218

    Last Modified: 21 Nov 2024

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-20212

    Last Modified: 21 Nov 2024

    bin/statistics in TWiki 6.0.2 allows cross-site scripting (XSS) via the webs parameter.

    Published: 17 Mar 2019
    8.8
    High

    CVE-2018-18862

    Last Modified: 21 Nov 2024

    BMC Remedy Mid-Tier 7.1.00 and 9.1.02.003 for BMC Remedy AR System has Incorrect Access Control in ITAM forms, as demonstrated by TLS%3APLR-Configuration+Details/Default+Admin+View/, AST%3AARServerConnection/Default+Admin+View/, and AR+System+Administration%3A+Server+Information/Default+Admin+View/.

    Published: 17 Mar 2019
    9.9
    Critical

    CVE-2018-20162

    Last Modified: 21 Nov 2024

    Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7425

    Last Modified: 21 Nov 2024

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/linkdownalertConfig.jsp" file in the task parameter.

    Published: 17 Mar 2019
    6.8
    Medium

    CVE-2018-20340

    Last Modified: 21 Nov 2024

    Yubico libu2f-host 1.1.6 contains unchecked buffers in devs.c, which could enable a malicious token to exploit a buffer overflow. An attacker could use this to attempt to execute malicious code using a crafted USB device masquerading as a security token on a computer where the affected library is currently in use. It is not possible to perform this attack with a genuine YubiKey.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7424

    Last Modified: 21 Nov 2024

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/index.jsp" file in the view GET parameter or any of these POST parameters: autorefTime, section, snapshot, viewOpt, viewAll, view, or groupSelName. The latter is related to CVE-2009-3903.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2018-20141

    Last Modified: 21 Nov 2024

    AbanteCart 1.2.12 has reflected cross-site scripting (XSS) via the sort parameter, as demonstrated by a /apparel--accessories?sort= substring.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7423

    Last Modified: 21 Nov 2024

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/editProfile.jsp" file in the userName parameter.

    Published: 17 Mar 2019
    6.1
    Medium

    CVE-2019-7422

    Last Modified: 21 Nov 2024

    XSS exists in Zoho ManageEngine Netflow Analyzer Professional v7.0.0.2 in the Administration zone "/netflow/jspui/addMailSettings.jsp" file in the gF parameter.

    Published: 17 Mar 2019