CVE Feed

    Dashboard / CVE

    4.8
    Medium

    CVE-2018-19600

    Last Modified: 21 Nov 2024

    Rhymix CMS 1.9.8.1 allows XSS via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.

    Published: 3 Jan 2019
    9.1
    Critical

    CVE-2018-19601

    Last Modified: 21 Nov 2024

    Rhymix CMS 1.9.8.1 allows SSRF via an index.php?module=admin&act=dispModuleAdminFileBox SVG upload.

    Published: 3 Jan 2019
    6.1
    Medium

    CVE-2018-19414

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to inject arbitrary web script or HTML via the (1) keyword parameter to groups.php; (2) username parameter to login.php; or (3) date parameter to search.php.

    Published: 3 Jan 2019
    6.5
    Medium

    CVE-2018-19505

    Last Modified: 21 Nov 2024

    Remedy AR System Server in BMC Remedy 7.1 may fail to set the correct user context in certain impersonation scenarios, which can allow a user to act with the identity of a different user, because userdata.js in the WOI:WorkOrderConsole component allows a username substitution involving a UserData_Init call.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-19862

    Last Modified: 21 Nov 2024

    Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued.

    Published: 3 Jan 2019
    6.1
    Medium

    CVE-2018-19993

    Last Modified: 21 Nov 2024

    A reflected cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote attackers to inject arbitrary web script or HTML via the transphrase parameter to public/notice.php.

    Published: 3 Jan 2019
    8.8
    High

    CVE-2018-19994

    Last Modified: 21 Nov 2024

    An error-based SQL injection vulnerability in product/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the desiredstock parameter.

    Published: 3 Jan 2019
    5.4
    Medium

    CVE-2018-19995

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to user/card.php.

    Published: 3 Jan 2019
    8.8
    High

    CVE-2018-19998

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in user/card.php in Dolibarr version 8.0.2 allows remote authenticated users to execute arbitrary SQL commands via the employee parameter.

    Published: 3 Jan 2019
    6.1
    Medium

    CVE-2018-14481

    Last Modified: 21 Nov 2024

    Osclass 3.7.4 has XSS via the query string to index.php, a different vulnerability than CVE-2014-6280.

    Published: 3 Jan 2019
    7.8
    High

    CVE-2019-3575

    Last Modified: 21 Nov 2024

    Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-19415

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in Plikli CMS 4.0.0 allow remote attackers to execute arbitrary SQL commands via the (1) id parameter to join_group.php or (2) comment_id parameter to story.php.

    Published: 3 Jan 2019
    5.4
    Medium

    CVE-2018-19992

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in Dolibarr 8.0.2 allows remote authenticated users to inject arbitrary web script or HTML via the "address" (POST) or "town" (POST) parameter to adherents/type.php.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2018-19523

    Last Modified: 21 Nov 2024

    DriverAgent 2.2015.7.14, which includes DrvAgent64.sys 1.0.0.1, allows a user to send an IOCTL (0x80002068) with a user defined buffer size. If the size of the buffer is less than 512 bytes, then the driver will overwrite the next pool header if there is one next to the user buffer's pool.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-19861

    Last Modified: 21 Nov 2024

    Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-20512

    Last Modified: 21 Nov 2024

    EPON CPE-WiFi devices 2.0.4-X000 are vulnerable to escalation of privileges by sending cooLogin=1, cooUser=admin, and timestamp=-1 cookies.

    Published: 3 Jan 2019
    5.4
    Medium

    CVE-2018-20663

    Last Modified: 21 Nov 2024

    The Reporting Addon (aka Reports Addon) through 2019-01-02 for CUBA Platform through 6.10.x has Persistent XSS via the "Reports > Reports" name field.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-20664

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus 5.x before build 5701 has XXE via an uploaded product license.

    Published: 3 Jan 2019
    10
    Critical

    CVE-2019-3905

    Last Modified: 30 May 2025

    Zoho ManageEngine ADSelfService Plus 5.x before build 5703 has SSRF.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-17161

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.2-STABLE(r348229), 11.2-RELEASE-p7, 12.0-STABLE(r342228), and 12.0-RELEASE-p1, insufficient validation of network-provided data in bootpd may make it possible for a malicious attacker to craft a bootp packet which could cause a stack buffer overflow. It is possible that the buffer overflow could lead to a Denial of Service or remote code execution.

    Published: 3 Jan 2019
    5.9
    Medium

    CVE-2018-16870

    Last Modified: 21 Nov 2024

    It was found that wolfssl before 3.15.7 is vulnerable to a new variant of the Bleichenbacher attack to perform downgrade attacks against TLS. This may lead to leakage of sensible data.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18327

    Last Modified: 21 Nov 2024

    Security keys are logged when any WCDMA call is configured or reconfigured in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 430, SD 450, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18319

    Last Modified: 21 Nov 2024

    Information leak in UIM API debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18321

    Last Modified: 21 Nov 2024

    Security keys used by the terminal and NW for a session could be leaked in snapdragon mobile in versions MDM9650, MDM9655, SD 835, SDA660.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18324

    Last Modified: 21 Nov 2024

    Cryptographic key material leaked in debug messages - GERAN in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, SD 855, SDX24, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-11004

    Last Modified: 21 Nov 2024

    A non-secure user may be able to access certain registers in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    7.8
    High

    CVE-2017-18141

    Last Modified: 21 Nov 2024

    When a 3rd party TEE has been loaded it is possible for the non-secure world to create a secure monitor call which will give it access to privileged functions meant to only be accessible from the TEE in Snapdragon Automobile, Snapdragon Mobile and Snapdragon Wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9650, MDM9655, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    7.8
    High

    CVE-2017-18320

    Last Modified: 21 Nov 2024

    QSEE unload attempt on a 3rd party TEE without previously loading results in a data abort in snapdragon automobile and snapdragon mobile in versions MSM8996AU, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016, SXR1130.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18322

    Last Modified: 21 Nov 2024

    Cryptographic key material leaked in WCDMA debug messages in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 800, SD 810, SD 820, SD 835, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18323

    Last Modified: 21 Nov 2024

    Cryptographic key material leaked in TDSCDMA RRC debug messages in snapdragon automobile, snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9615, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 430, SD 450, SD 615/16/SD 415, SD 625, SD 650/52, SD 712 / SD 710 / SD 670, SD 820, SD 820A, SD 835, SD 845 / SD 850, SDA660, SDX20, SXR1130.

    Published: 3 Jan 2019
    5.5
    Medium

    CVE-2017-18326

    Last Modified: 21 Nov 2024

    Cryptographic keys are printed in modem debug messages in snapdragon mobile and snapdragon wear in versions MDM9607, MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 800, SD 810, SD 820, SD 835, SDA660, SDM630, SDM660, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    7.8
    High

    CVE-2017-18328

    Last Modified: 21 Nov 2024

    Use after free in QSH client rule processing in snapdragon mobile and snapdragon wear in versions MDM9206, MDM9607, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 625, SD 636, SD 820, SD 835, SDA660, SDM630, SDM660, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    7.8
    High

    CVE-2017-18329

    Last Modified: 21 Nov 2024

    Possible Buffer overflow when transmitting an RTP packet in snapdragon automobile and snapdragon wear in versions MDM9615, MDM9625, MDM9635M, MDM9640, MDM9645, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 425, SD 427, SD 430, SD 435, SD 450, SD 615/16/SD 415, SD 625, SD 636, SD 650/52, SD 712 / SD 710 / SD 670, SD 810, SD 820, SD 835, SD 845 / SD 850, SDA660, SDM630, SDM660, Snapdragon_High_Med_2016, SXR1130

    Published: 3 Jan 2019
    7.8
    High

    CVE-2017-18330

    Last Modified: 21 Nov 2024

    Buffer overflow in AES-CCM and AES-GCM encryption via initialization vector in snapdragon automobile, snapdragon mobile and snapdragon wear in versions IPQ8074, MDM9206, MDM9607, MDM9635M, MDM9640, MDM9650, MDM9655, MSM8909W, MSM8996AU, SD 210/SD 212/SD 205, SD 410/12, SD 425, SD 427, SD 430, SD 435, SD 439 / SD 429, SD 450, SD 615/16/SD 415, SD 625, SD 632, SD 636, SD 650/52, SD 810, SD 820, SD 820A, SD 835, SDA660, SDM439, SDM630, SDM660, SDX24, Snapdragon_High_Med_2016.

    Published: 3 Jan 2019
    9.8
    Critical

    CVE-2018-17172

    Last Modified: 21 Nov 2024

    The web application on Xerox AltaLink B80xx before 100.008.028.05200, C8030/C8035 before 100.001.028.05200, C8045/C8055 before 100.002.028.05200, and C8070 before 100.003.028.05200 allows unauthenticated command injection.

    Published: 3 Jan 2019
    5.3
    Medium

    CVE-2018-18893

    Last Modified: 21 Nov 2024

    Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.

    Published: 3 Jan 2019
    7.5
    High

    CVE-2019-3580

    Last Modified: 21 Nov 2024

    OpenRefine through 3.1 allows arbitrary file write because Directory Traversal can occur during the import of a crafted project file.

    Published: 3 Jan 2019
    7.8
    High

    CVE-2018-20131

    Last Modified: 21 Nov 2024

    The Code42 app before 6.8.4, as used in Code42 for Enterprise, on Linux installs with overly permissive permissions on the /usr/local/crashplan/log directory. This allows a user to manipulate symbolic links to escalate privileges, or show the contents of sensitive files that a regular user would not have access to.

    Published: 3 Jan 2019
    5.6
    Medium

    CVE-2019-7308

    Last Modified: 21 Nov 2024

    kernel/bpf/verifier.c in the Linux kernel before 4.20.6 performs undesirable out-of-bounds speculation on pointer arithmetic in various cases, including cases of different branches with different state or limits to sanitize, leading to side-channel attacks.

    Published: 3 Jan 2019
    4.4
    Medium

    CVE-2019-8906

    Last Modified: 21 Nov 2024

    do_core_note in readelf.c in libmagic.a in file 5.35 has an out-of-bounds read because memcpy is misused.

    Published: 3 Jan 2019
    8.8
    High

    CVE-2019-8907

    Last Modified: 21 Nov 2024

    do_core_note in readelf.c in libmagic.a in file 5.35 allows remote attackers to cause a denial of service (stack corruption and application crash) or possibly have unspecified other impact.

    Published: 3 Jan 2019
    —
    Unknown

    CVE-2017-14810

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14808

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14809

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14811

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14812

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14813

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14814

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14815

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019
    —
    Unknown

    CVE-2017-14816

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: The CNA or individual who requested this candidate did not associate it with any vulnerability during 2017. Notes: none

    Published: 2 Jan 2019