CVE Feed

    Dashboard / CVE

    7.3
    High

    CVE-2018-0181

    Last Modified: 21 Nov 2024

    A vulnerability in the Redis implementation used by the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software could allow an unauthenticated, remote attacker to modify key-value pairs for short-lived events stored by the Redis server. The vulnerability is due to improper authentication when accessing the Redis server. An unauthenticated attacker could exploit this vulnerability by modifying key-value pairs stored within the Redis server database. An exploit could allow the attacker to reduce the efficiency of the Cisco Policy Suite for Mobile and Cisco Policy Suite Diameter Routing Agent software.

    Published: 10 Jan 2019
    8.8
    High

    CVE-2018-1000412

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Jira Plugin 3.0.1 and earlier in JiraSite.java that allows attackers with Overall/Read access to have Jenkins connect to an attacker-specified URL using attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 9 Jan 2019
    5.4
    Medium

    CVE-2018-1000413

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in configfiles.jelly, providerlist.jelly that allows users with the ability to configure configuration files to insert arbitrary HTML into some pages in Jenkins.

    Published: 9 Jan 2019
    8.1
    High

    CVE-2018-1000414

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Jenkins Config File Provider Plugin 3.1 and earlier in ConfigFilesManagement.java, FolderConfigFileAction.java that allows creating and editing configuration file definitions.

    Published: 9 Jan 2019
    8.8
    High

    CVE-2018-1000418

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to send test notifications to an attacker-specified HipChat server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 9 Jan 2019
    6.5
    Medium

    CVE-2018-1000420

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

    Published: 9 Jan 2019
    6.5
    Medium

    CVE-2018-1000421

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Mesos Plugin 0.17.1 and earlier in MesosCloud.java that allows attackers with Overall/Read access to initiate a test connection to an attacker-specified Mesos server with attacker-specified credentials IDs obtained through another method, capturing credentials stored in Jenkins.

    Published: 9 Jan 2019
    7.8
    High

    CVE-2018-1000424

    Last Modified: 21 Nov 2024

    An insufficiently protected credentials vulnerability exists in Jenkins Artifactory Plugin 2.16.1 and earlier in ArtifactoryBuilder.java, CredentialsConfig.java that allows attackers with local file system access to obtain old credentials configured for the plugin before it integrated with Credentials Plugin.

    Published: 9 Jan 2019
    7.8
    High

    CVE-2018-1000425

    Last Modified: 21 Nov 2024

    An insufficiently protected credentials vulnerability exists in Jenkins SonarQube Scanner Plugin 2.8 and earlier in SonarInstallation.java that allows attackers with local file system access to obtain the credentials used to connect to SonarQube.

    Published: 9 Jan 2019
    6.1
    Medium

    CVE-2018-1000426

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins Git Changelog Plugin 2.6 and earlier in GitChangelogSummaryDecorator/summary.jelly, GitChangelogLeftsideBuildDecorator/badge.jelly, GitLogJiraFilterPostPublisher/config.jelly, GitLogBasicChangelogPostPublisher/config.jelly that allows attackers able to control the Git history parsed by the plugin to have Jenkins render arbitrary HTML on some pages.

    Published: 9 Jan 2019
    6.1
    Medium

    CVE-2016-10736

    Last Modified: 21 Nov 2024

    The "Social Pug - Easy Social Share Buttons" plugin before 1.2.6 for WordPress allows XSS via the wp-admin/admin.php?page=dpsp-toolkit dpsp_message_class parameter.

    Published: 9 Jan 2019
    8.1
    High

    CVE-2018-1000417

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Jenkins Email Extension Template Plugin 1.0 and earlier in ExtEmailTemplateManagement.java that allows creating or removing templates.

    Published: 9 Jan 2019
    6.5
    Medium

    CVE-2018-1000419

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins HipChat Plugin 2.2.0 and earlier in HipChatNotifier.java that allows attackers with Overall/Read access to obtain credentials IDs for credentials stored in Jenkins.

    Published: 9 Jan 2019
    6.1
    Medium

    CVE-2018-20681

    Last Modified: 21 Nov 2024

    mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output devices (such as additionally attached graphical outputs via HDMI, VGA, DVI, etc.) the content of a screensaver-locked session can be revealed. In some scenarios, the attacker can execute applications, such as by clicking with a mouse.

    Published: 9 Jan 2019
    5.4
    Medium

    CVE-2018-1000415

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins Rebuilder Plugin 1.28 and earlier in RebuildAction/BooleanParameterValue.jelly, RebuildAction/ExtendedChoiceParameterValue.jelly, RebuildAction/FileParameterValue.jelly, RebuildAction/LabelParameterValue.jelly, RebuildAction/ListSubversionTagsParameterValue.jelly, RebuildAction/MavenMetadataParameterValue.jelly, RebuildAction/NodeParameterValue.jelly, RebuildAction/PasswordParameterValue.jelly, RebuildAction/RandomStringParameterValue.jelly, RebuildAction/RunParameterValue.jelly, RebuildAction/StringParameterValue.jelly, RebuildAction/TextParameterValue.jelly, RebuildAction/ValidatingStringParameterValue.jelly that allows users with Job/Configuration permission to insert arbitrary HTML into rebuild forms.

    Published: 9 Jan 2019
    6.1
    Medium

    CVE-2018-1000416

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting vulnerability exists in Jenkins Job Config History Plugin 2.18 and earlier in all Jelly files that shows arbitrary attacker-specified HTML in Jenkins to users with Job/Configure access.

    Published: 9 Jan 2019
    6.5
    Medium

    CVE-2018-1000422

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java that allows attackers to have Jenkins perform a connection test, connecting to an attacker-specified server with attacker-specified credentials and connection settings.

    Published: 9 Jan 2019
    7.8
    High

    CVE-2018-1000423

    Last Modified: 21 Nov 2024

    An insufficiently protected credentials vulnerability exists in Jenkins Crowd 2 Integration Plugin 2.0.0 and earlier in CrowdSecurityRealm.java, CrowdConfigurationService.java that allows attackers with local file system access to obtain the credentials used to connect to Crowd 2.

    Published: 9 Jan 2019
    5.4
    Medium

    CVE-2018-20682

    Last Modified: 21 Nov 2024

    Fork CMS 5.0.6 allows stored XSS via the private/en/settings facebook_admin_ids parameter (aka "Admin ids" input in the Facebook section).

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0625

    Last Modified: 21 Nov 2024

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via formSysCmd parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0626

    Last Modified: 21 Nov 2024

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via sysCmd in formWsc parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0627

    Last Modified: 21 Nov 2024

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0628

    Last Modified: 21 Nov 2024

    Aterm WG1200HP firmware Ver1.0.31 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0629

    Last Modified: 21 Nov 2024

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via HTTP request and response.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0631

    Last Modified: 21 Nov 2024

    Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary OS commands via targetAPSsid parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0633

    Last Modified: 21 Nov 2024

    Buffer overflow in Aterm W300P Ver1.0.13 and earlier allows attacker with administrator rights to execute arbitrary code via submit-url parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0635

    Last Modified: 21 Nov 2024

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via filename parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0636

    Last Modified: 21 Nov 2024

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via FactoryPassword parameter of a certain URL, different URL from CVE-2018-0634.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0639

    Last Modified: 21 Nov 2024

    Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary OS commands via tools_firmware.cgi date parameter, time parameter, and offset parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0640

    Last Modified: 21 Nov 2024

    Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via netWizard.cgi date parameter, time parameter, and offset parameter.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-0641

    Last Modified: 21 Nov 2024

    Buffer overflow in Aterm HC100RC Ver1.0.1 and earlier allows attacker with administrator rights to execute arbitrary code via tools_system.cgi date parameter, time parameter, and offset parameter.

    Published: 9 Jan 2019
    6.8
    Medium

    CVE-2018-0665

    Last Modified: 21 Nov 2024

    Yamaha routers RT57i Rev.8.00.95 and earlier, RT58i Rev.9.01.51 and earlier, NVR500 Rev.11.00.36 and earlier, RTX810 Rev.11.01.31 and earlier, allow an administrative user to embed arbitrary scripts to the configuration data through a certain form field of the configuration page, which may be executed on another administrative user's web browser. This is a different vulnerability from CVE-2018-0666.

    Published: 9 Jan 2019
    9.8
    Critical

    CVE-2018-0668

    Last Modified: 21 Nov 2024

    Buffer overflow in INplc-RT 3.08 and earlier allows remote attackers to cause denial-of-service (DoS) condition that may result in executing arbtrary code via unspecified vectors.

    Published: 9 Jan 2019
    9.8
    Critical

    CVE-2018-0669

    Last Modified: 21 Nov 2024

    INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability than CVE-2018-0670.

    Published: 9 Jan 2019
    9.8
    Critical

    CVE-2018-0670

    Last Modified: 21 Nov 2024

    INplc-RT 3.08 and earlier allows remote attackers to bypass authentication to execute an arbitrary command through the protocol-compliant traffic. This is a different vulnerability than CVE-2018-0669.

    Published: 9 Jan 2019
    6.7
    Medium

    CVE-2018-0671

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability in INplc-RT 3.08 and earlier allows an attacker with administrator rights to execute arbitrary code on the Windows system via unspecified vectors.

    Published: 9 Jan 2019
    6.8
    Medium

    CVE-2018-0677

    Last Modified: 21 Nov 2024

    BN-SDWBP3 firmware version 1.0.9 and earlier allows attacker with administrator rights on the same network segment to execute arbitrary OS commands via unspecified vectors.

    Published: 9 Jan 2019
    8.8
    High

    CVE-2018-0689

    Last Modified: 21 Nov 2024

    HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A firmware versions released prior to 2017 August 1, EP-708A firmware versions released prior to 2017 August 7, EP-709A firmware versions released prior to 2017 June 12, EP-777A firmware versions released prior to 2017 August 1, EP-807AB/AW/AR firmware versions released prior to 2017 August 1, EP-808AB/AW/AR firmware versions released prior to 2017 August 7, EP-879AB/AW/AR firmware versions released prior to 2017 June 12, EP-907F firmware versions released prior to 2017 August 1, EP-977A3 firmware versions released prior to 2017 August 1, EP-978A3 firmware versions released prior to 2017 August 7, EP-979A3 firmware versions released prior to 2017 June 12, EP-M570T firmware versions released prior to 2017 September 6, EW-M5071FT firmware versions released prior to 2017 November 2, EW-M660FT firmware versions released prior to 2018 April 19, EW-M770T firmware versions released prior to 2017 September 6, PF-70 firmware versions released prior to 2018 April 20, PF-71 firmware versions released prior to 2017 July 18, PF-81 firmware versions released prior to 2017 September 14, PX-048A firmware versions released prior to 2017 July 4, PX-049A firmware versions released prior to 2017 September 11, PX-437A firmware versions released prior to 2017 July 24, PX-M350F firmware versions released prior to 2018 February 23, PX-M5040F firmware versions released prior to 2017 November 20, PX-M5041F firmware versions released prior to 2017 November 20, PX-M650A firmware versions released prior to 2017 October 17, PX-M650F firmware versions released prior to 2017 October 17, PX-M680F firmware versions released prior to 2017 June 29, PX-M7050F firmware versions released prior to 2017 October 13, PX-M7050FP firmware versions released prior to 2017 October 13, PX-M7050FX firmware versions released prior to 2017 November 7, PX-M7070FX firmware versions released prior to 2017 April 27, PX-M740F firmware versions released prior to 2017 December 4, PX-M741F firmware versions released prior to 2017 December 4, PX-M780F firmware versions released prior to 2017 June 29, PX-M781F firmware versions released prior to 2017 June 27, PX-M840F firmware versions released prior to 2017 November 16, PX-M840FX firmware versions released prior to 2017 December 8, PX-M860F firmware versions released prior to 2017 October 25, PX-S05B/W firmware versions released prior to 2018 March 9, PX-S350 firmware versions released prior to 2018 February 23, PX-S5040 firmware versions released prior to 2017 November 20, PX-S7050 firmware versions released prior to 2018 February 21, PX-S7050PS firmware versions released prior to 2018 February 21, PX-S7050X firmware versions released prior to 2017 November 7, PX-S7070X firmware versions released prior to 2017 April 27, PX-S740 firmware versions released prior to 2017 December 3, PX-S840 firmware versions released prior to 2017 November 16, PX-S840X firmware versions released prior to 2017 December 8, PX-S860 firmware versions released prior to 2017 December 7) may allow a remote attackers to lead a user to a phishing site or execute an arbitrary script on the user's web browser.

    Published: 9 Jan 2019
    7.5
    High

    CVE-2018-0702

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Mailwise 5.0.0 to 5.4.5 allows remote attackers to delete arbitrary files via unspecified vectors.

    Published: 9 Jan 2019
    7.5
    High

    CVE-2018-0703

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Office 10.0.0 to 10.8.1 allows remote attackers to delete arbitrary files via HTTP requests.

    Published: 9 Jan 2019
    5.4
    Medium

    CVE-2018-16164

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Event Calendar WD version 1.1.21 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jan 2019
    8.8
    High

    CVE-2018-16166

    Last Modified: 21 Nov 2024

    LogonTracer 1.2.0 and earlier allows remote attackers to conduct XML External Entity (XXE) attacks via unspecified vectors.

    Published: 9 Jan 2019
    9.8
    Critical

    CVE-2018-16167

    Last Modified: 21 Nov 2024

    LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 9 Jan 2019
    9.8
    Critical

    CVE-2018-16168

    Last Modified: 21 Nov 2024

    LogonTracer 1.2.0 and earlier allows remote attackers to conduct Python code injection attacks via unspecified vectors.

    Published: 9 Jan 2019
    8.1
    High

    CVE-2018-16170

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 for Windows allows remote authenticated attackers to read arbitrary files via unspecified vectors.

    Published: 9 Jan 2019
    8.8
    High

    CVE-2018-16171

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Cybozu Remote Service 3.0.0 to 3.1.8 allows remote attackers to execute Java code file on the server via unspecified vectors.

    Published: 9 Jan 2019
    6.5
    Medium

    CVE-2018-16172

    Last Modified: 21 Nov 2024

    Improper countermeasure against clickjacking attack in client certificates management screen was discovered in Cybozu Remote Service 3.0.0 to 3.1.8, that allows remote attackers to trick a user to delete the registered client certificate.

    Published: 9 Jan 2019
    6.1
    Medium

    CVE-2018-16173

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 9 Jan 2019
    6.1
    Medium

    CVE-2018-16174

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in LearnPress prior to version 3.1.0 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.

    Published: 9 Jan 2019
    7.2
    High

    CVE-2018-16175

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the LearnPress prior to version 3.1.0 allows attacker with administrator rights to execute arbitrary SQL commands via unspecified vectors.

    Published: 9 Jan 2019