CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-19182

    Last Modified: 21 Nov 2024

    Engelsystem before commit hash 2e28336 allows CSRF.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-19615

    Last Modified: 21 Nov 2024

    Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted user’s web browser to gain access to the affected device.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-19799

    Last Modified: 21 Nov 2024

    Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.

    Published: 26 Dec 2018
    7.5
    High

    CVE-2018-20404

    Last Modified: 21 Nov 2024

    ETK_E900.sys, a SmartETK driver for VIA Technologies EPIA-E900 system board, is vulnerable to denial of service attack via IOCTL 0x9C402048, which calls memmove and constantly fails on an arbitrary (uncontrollable) address, resulting in an eternal hang or a BSoD.

    Published: 26 Dec 2018
    7.8
    High

    CVE-2018-18536

    Last Modified: 21 Nov 2024

    The GLCKIo and Asusgio low-level drivers in ASUS Aura Sync v1.07.22 and earlier expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

    Published: 26 Dec 2018
    8.1
    High

    CVE-2018-19616

    Last Modified: 21 Nov 2024

    An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-20486

    Last Modified: 21 Nov 2024

    MetInfo 6.x through 6.1.3 has XSS via the /admin/login/login_check.php url_array[] parameter.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-20485

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-20484

    Last Modified: 21 Nov 2024

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-0724

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0723.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-0723

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Q'center Virtual Appliance 1.8.1014 and earlier versions could allow remote attackers to inject Javascript code in the compromised application, a different vulnerability than CVE-2018-0724.

    Published: 26 Dec 2018
    3.4
    Low

    CVE-2018-17957

    Last Modified: 21 Nov 2024

    The YaST2 RMT module for configuring the SUSE Repository Mirroring Tool (RMT) before 1.1.2 exposed MySQL database passwords on process commandline, allowing local attackers to access or corrupt the RMT database.

    Published: 26 Dec 2018
    7.5
    High

    CVE-2018-20478

    Last Modified: 21 Nov 2024

    An issue was discovered in S-CMS 1.0. It allows reading certain files, such as PHP source code, via the admin/download.php DownName parameter with a mixed-case extension, as demonstrated by a DownName=download.Php value.

    Published: 26 Dec 2018
    9.8
    Critical

    CVE-2018-20479

    Last Modified: 21 Nov 2024

    An issue was discovered in S-CMS 1.0. It allows SQL Injection via the wap_index.php?type=newsinfo S_id parameter.

    Published: 26 Dec 2018
    9.8
    Critical

    CVE-2018-20480

    Last Modified: 21 Nov 2024

    An issue was discovered in S-CMS 1.0. It allows SQL Injection via the js/pic.php P_id parameter.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-20476

    Last Modified: 21 Nov 2024

    An issue was discovered in S-CMS 3.0. It allows XSS via the admin/demo.php T_id parameter.

    Published: 26 Dec 2018
    9.8
    Critical

    CVE-2018-20477

    Last Modified: 21 Nov 2024

    An issue was discovered in S-CMS 3.0. It allows SQL Injection via the bank/callback1.php P_no field.

    Published: 26 Dec 2018
    4.7
    Medium

    CVE-2018-20482

    Last Modified: 21 Nov 2024

    GNU Tar through 1.30, when --sparse is used, mishandles file shrinkage during read access, which allows local users to cause a denial of service (infinite read loop in sparse_dump_region in sparse.c) by modifying a file that is supposed to be archived by a different user's process (e.g., a system backup running as root).

    Published: 26 Dec 2018
    7.8
    High

    CVE-2018-20483

    Last Modified: 21 Nov 2024

    set_file_metadata in xattr.c in GNU Wget before 1.20.1 stores a file's origin URL in the user.xdg.origin.url metadata attribute of the extended attributes of the downloaded file, which allows local users to obtain sensitive information (e.g., credentials contained in the URL) by reading this attribute, as demonstrated by getfattr. This also applies to Referer information in the user.xdg.referrer.url metadata attribute. According to 2016-07-22 in the Wget ChangeLog, user.xdg.origin.url was partially based on the behavior of fwrite_xattr in tool_xattr.c in curl.

    Published: 26 Dec 2018
    6.5
    Medium

    CVE-2018-20551

    Last Modified: 21 Nov 2024

    A reachable Object::getString assertion in Poppler 0.72.0 allows attackers to cause a denial of service due to construction of invalid rich media annotation assets in the AnnotRichMedia class in Annot.c.

    Published: 26 Dec 2018
    6.1
    Medium

    CVE-2018-20464

    Last Modified: 21 Nov 2024

    There is a reflected XSS vulnerability in the CMS Made Simple 2.2.8 admin/myaccount.php. This vulnerability is triggered upon an attempt to modify a user's mailbox with the wrong format. The response contains the user's previously entered email address.

    Published: 25 Dec 2018
    7.2
    High

    CVE-2018-20465

    Last Modified: 21 Nov 2024

    Craft CMS through 3.0.34 allows remote authenticated administrators to read sensitive information via server-side template injection, as demonstrated by a {% string for craft.app.config.DB.user and craft.app.config.DB.password in the URI Format of the Site Settings, which causes a cleartext username and password to be displayed in a URI field.

    Published: 25 Dec 2018
    6.1
    Medium

    CVE-2018-20462

    Last Modified: 21 Nov 2024

    An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. A cross-site scripting (XSS) vulnerability allows remote attackers to inject arbitrary web script or HTML via the jsmol.php data parameter.

    Published: 25 Dec 2018
    7.5
    High

    CVE-2018-20463

    Last Modified: 21 Nov 2024

    An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20455

    Last Modified: 21 Nov 2024

    In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash via a stack-based buffer overflow) by crafting an input file, a related issue to CVE-2018-20456.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20456

    Last Modified: 21 Nov 2024

    In radare2 prior to 3.1.1, the parseOperand function inside libr/asm/p/asm_x86_nz.c may allow attackers to cause a denial of service (application crash in libr/util/strbuf.c via a stack-based buffer over-read) by crafting an input file, a related issue to CVE-2018-20455.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20461

    Last Modified: 21 Nov 2024

    In radare2 prior to 3.1.1, core_anal_bytes in libr/core/cmd_anal.c allows attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting a binary file.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20457

    Last Modified: 21 Nov 2024

    In radare2 through 3.1.3, the assemble function inside libr/asm/p/asm_arm_cs.c allows attackers to cause a denial-of-service (application crash via an r_num_calc out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20459.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20458

    Last Modified: 21 Nov 2024

    In radare2 prior to 3.1.1, r_bin_dyldcache_extract in libr/bin/format/mach0/dyldcache.c may allow attackers to cause a denial-of-service (application crash caused by out-of-bounds read) by crafting an input file.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20459

    Last Modified: 21 Nov 2024

    In radare2 through 3.1.3, the armass_assemble function in libr/asm/arch/arm/armass.c allows attackers to cause a denial-of-service (application crash by out-of-bounds read) by crafting an arm assembly input because a loop uses an incorrect index in armass.c and certain length validation is missing in armass64.c, a related issue to CVE-2018-20457.

    Published: 25 Dec 2018
    5.5
    Medium

    CVE-2018-20460

    Last Modified: 21 Nov 2024

    In radare2 prior to 3.1.2, the parseOperands function in libr/asm/arch/arm/armass64.c allows attackers to cause a denial-of-service (application crash caused by stack-based buffer overflow) by crafting an input file.

    Published: 25 Dec 2018
    6.5
    Medium

    CVE-2018-20451

    Last Modified: 21 Nov 2024

    The process_file function in reader.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

    Published: 25 Dec 2018
    6.5
    Medium

    CVE-2018-20453

    Last Modified: 21 Nov 2024

    The getlong function in numutils.c in libdoc through 2017-10-23 has a heap-based buffer over-read that allows attackers to cause a denial of service (application crash) via a crafted file.

    Published: 25 Dec 2018
    6.1
    Medium

    CVE-2018-20454

    Last Modified: 21 Nov 2024

    An issue was discovered in 74cms v4.2.111. upload/index.php?c=resume&a=resume_list has XSS via the key parameter.

    Published: 25 Dec 2018
    6.5
    Medium

    CVE-2018-20450

    Last Modified: 21 Nov 2024

    The read_MSAT function in ole.c in libxls 1.4.0 has a double free that allows attackers to cause a denial of service (application crash) via a crafted file, a different vulnerability than CVE-2017-2897.

    Published: 25 Dec 2018
    8.8
    High

    CVE-2018-20452

    Last Modified: 21 Nov 2024

    The read_MSAT_body function in ole.c in libxls 1.4.0 has an invalid free that allows attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted file, because of inconsistent memory management (new versus free) in ole2_read_header in ole.c.

    Published: 25 Dec 2018
    5.4
    Medium

    CVE-2018-20448

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20438

    Last Modified: 21 Nov 2024

    Technicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20439

    Last Modified: 21 Nov 2024

    Technicolor DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20440

    Last Modified: 21 Nov 2024

    Technicolor CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20441

    Last Modified: 21 Nov 2024

    Technicolor TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20442

    Last Modified: 21 Nov 2024

    Technicolor TC7110.B STC8.62.02 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20443

    Last Modified: 21 Nov 2024

    Technicolor TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20444

    Last Modified: 21 Nov 2024

    Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.10001 and 1.3.6.1.4.1.4413.2.2.2.1.18.1.2.3.4.1.2.10001 SNMP requests.

    Published: 25 Dec 2018
    9.8
    Critical

    CVE-2018-20445

    Last Modified: 21 Nov 2024

    D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.4413.2.2.2.1.5.4.1.14.1.3.32 and iso.3.6.1.4.1.4413.2.2.2.1.5.4.2.4.1.2.32 SNMP requests.

    Published: 25 Dec 2018
    7.5
    High

    CVE-2018-20437

    Last Modified: 21 Nov 2024

    An issue was discovered in the fileDownload function in the CommonController class in FEBS-Shiro before 2018-11-05. An attacker can download a file via a request of the form /common/download?filename=1.jsp&delete=false. NOTE: the software maintainer disputes the significance of this report because the product uses a JAR archive for deployment, and this contains application.yml with configuration data

    Published: 25 Dec 2018
    8.1
    High

    CVE-2018-20436

    Last Modified: 21 Nov 2024

    The "secret chat" feature in Telegram 4.9.1 for Android has a "side channel" in which Telegram servers send GET requests for URLs typed while composing a chat message, before that chat message is sent. There are also GET requests to other URLs on the same web server. This also affects one or more other Telegram products, such as Telegram Web-version 0.7.0. In addition, it can be interpreted as an SSRF issue. NOTE: a third party has reported that potentially unwanted behavior is caused by misconfiguration of the "Secret chats > Preview links" setting

    Published: 24 Dec 2018
    8.8
    High

    CVE-2018-20249

    Last Modified: 21 Nov 2024

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref entries using the DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.

    Published: 24 Dec 2018
    9.8
    Critical

    CVE-2018-20248

    Last Modified: 21 Nov 2024

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing invalid xref table pointers or invalid xref table data using the LoadFromFile, LoadFromString, LoadFromStream, DAOpenFile or DAOpenFileReadOnly functions may result in an access violation caused by out of bounds memory access.

    Published: 24 Dec 2018
    7.8
    High

    CVE-2018-20247

    Last Modified: 21 Nov 2024

    In Foxit Quick PDF Library (all versions prior to 16.12), issue where loading a malformed or malicious PDF containing a recursive page tree structure using the LoadFromFile, LoadFromString or LoadFromStream functions results in a stack overflow.

    Published: 24 Dec 2018