CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-20400

    Last Modified: 21 Nov 2024

    Ubee DVW2108 6.28.1017 and DVW2110 6.28.2012 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20401

    Last Modified: 21 Nov 2024

    Zoom 5352 v5.5.8.6Y devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20387

    Last Modified: 21 Nov 2024

    Bnmux BCW700J 5.20.7, BCW710J 5.30.6a, and BCW710J2 5.30.16 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20389

    Last Modified: 21 Nov 2024

    D-Link DCM-604 DCM604_C1_ViaCabo_1.04_20130606 and DCM-704 EU_DCM-704_1.10 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20395

    Last Modified: 21 Nov 2024

    NETWAVE MNG6200 C4835805jrc12FU121413.cpr devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20396

    Last Modified: 21 Nov 2024

    NET&SYS MNG2120J 5.76.1006c and MNG6300 5.83.6305jrc2 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    8.8
    High

    CVE-2018-20402

    Last Modified: 21 Nov 2024

    Safe Software FME Server through 2018.1 creates and enables three additional accounts in addition to the initial administrator account. The passwords to the three accounts are the same as the usernames, which are guest, user, and author. Logging in with these accounts will grant any user the default privilege roles that were also created for each of the accounts.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20380

    Last Modified: 21 Nov 2024

    Ambit DDW2600 5.100.1009, DDW2602 5.105.1003, T60C926 4.64.1012, and U10C019 5.66.1026 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20383

    Last Modified: 21 Nov 2024

    ARRIS DG950A 7.10.145 and DG950S 7.10.145.EURO devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20384

    Last Modified: 21 Nov 2024

    iNovo Broadband IB-8120-W21 139.4410mp1.004200.002 and IB-8120-W21E1 139.4410mp1.3921132mp1.899.004404.004 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20386

    Last Modified: 21 Nov 2024

    ARRIS SBG6580-2 D30GW-SEAEAGLE-1.5.2.5-GA-00-NOSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20390

    Last Modified: 21 Nov 2024

    Kaonmedia CG2001-AN22A 1.2.1, CG2001-UDBNA 3.0.8, and CG2001-UN2NA 3.0.8 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20393

    Last Modified: 21 Nov 2024

    Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU, CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC, DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a, TC7110.AR STD3.38.03, TC7110.B STC8.62.02, TC7110.D STDB.79.02, TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT, and TC7200.TH2v2 SC05.00.22 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20398

    Last Modified: 21 Nov 2024

    Skyworth CM5100 V1.1.0, CM5100-440 V1.2.1, CM5100-511 4.1.0.14, CM5100-GHD00 V1.2.2, and CM5100.g2 4.1.0.17 devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests.

    Published: 23 Dec 2018
    5.5
    Medium

    CVE-2018-20374

    Last Modified: 21 Nov 2024

    An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the use_section1 function in tccasm.c.

    Published: 23 Dec 2018
    5.5
    Medium

    CVE-2018-20375

    Last Modified: 21 Nov 2024

    An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the sym_pop function in tccgen.c.

    Published: 23 Dec 2018
    5.5
    Medium

    CVE-2018-20376

    Last Modified: 21 Nov 2024

    An issue was discovered in Tiny C Compiler (aka TinyCC or TCC) 0.9.27. Compiling a crafted source file leads to an 8 byte out of bounds write in the asm_parse_directive function in tccasm.c.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20377

    Last Modified: 21 Nov 2024

    Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default admin value. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.

    Published: 23 Dec 2018
    5.4
    Medium

    CVE-2018-20368

    Last Modified: 21 Nov 2024

    The Master Slider plugin 3.2.7 and 3.5.1 for WordPress has XSS via the wp-admin/admin-ajax.php Name input field of the MSPanel.Settings value on Callback.

    Published: 23 Dec 2018
    5.4
    Medium

    CVE-2018-20370

    Last Modified: 21 Nov 2024

    SZ NetChat before 7.9 has XSS in the MyName input field of the Options module. Attackers are able to inject commands to compromise the enabled HTTP server web frontend.

    Published: 23 Dec 2018
    9.8
    Critical

    CVE-2018-20371

    Last Modified: 21 Nov 2024

    PhotoRange Photo Vault 1.2 appends the password to the URI for authorization, which makes it easier for remote attackers to bypass intended GET restrictions via a brute-force approach, as demonstrated by "GET /login.html__passwd1" and "GET /login.html__passwd2" and so on.

    Published: 23 Dec 2018
    5.4
    Medium

    CVE-2018-20372

    Last Modified: 21 Nov 2024

    TP-Link TD-W8961ND devices allow XSS via the hostname of a DHCP client.

    Published: 23 Dec 2018
    5.4
    Medium

    CVE-2018-20373

    Last Modified: 21 Nov 2024

    Tenda ADSL modem routers 1.0.1 allow XSS via the hostname of a DHCP client.

    Published: 23 Dec 2018
    7.8
    High

    CVE-2018-20331

    Last Modified: 21 Nov 2024

    Local attackers can trigger a Kernel Pool Buffer Overflow in Antiy AVL ATool v1.0.0.22. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the processing of IOCTL 0x80002004 by the ssdt.sys kernel driver. The bug is caused by failure to properly validate the length of the user-supplied data. An attacker can leverage this vulnerability to execute arbitrary code in the context of the kernel, which could lead to privilege escalation. A failed exploit could lead to denial of service.

    Published: 23 Dec 2018
    6.1
    Medium

    CVE-2018-20369

    Last Modified: 21 Nov 2024

    Barracuda Message Archiver 2018 has XSS in the error_msg exception-handling value for the ldap_user parameter to the cgi-mod/ldap_load_entry.cgi module. The injection point of the issue is the Add_Update module.

    Published: 23 Dec 2018
    6.1
    Medium

    CVE-2018-20367

    Last Modified: 21 Nov 2024

    The "mall some commodity details: commodity consultation" component in WSTMart 2.0.8_181212 has stored XSS via the consultContent parameter, as demonstrated by the index.php/home/goodsconsult/add.html URI.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-19863

    Last Modified: 21 Nov 2024

    An issue was discovered in 1Password 7.2.3.BETA before 7.2.3.BETA-3 on macOS. A mistake in error logging resulted in instances where sensitive data passed from Safari to 1Password could be logged locally on the user's machine. This data could include usernames and passwords that a user manually entered into Safari.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20357

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was discovered in sbr_process_channel of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20358

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in the lt_prediction function of libfaad/lt_predict.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20359

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in the sbrDecodeSingleFramePS function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20360

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in the sbr_process_channel function of libfaad/sbr_dec.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20361

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in the hf_assembly function of libfaad/sbr_hfadj.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash, which leads to denial of service.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20362

    Last Modified: 21 Nov 2024

    A NULL pointer dereference was discovered in ifilter_bank of libfaad/filtbank.c in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.8. The vulnerability causes a segmentation fault and application crash because adding to windowed output is mishandled in the EIGHT_SHORT_SEQUENCE case.

    Published: 22 Dec 2018
    6.1
    Medium

    CVE-2018-20351

    Last Modified: 21 Nov 2024

    The Markdown component in Evernote (Chinese) before 8.3.2 on macOS allows stored XSS, aka MAC-832.

    Published: 22 Dec 2018
    6.5
    Medium

    CVE-2018-17197

    Last Modified: 21 Nov 2024

    A carefully crafted or corrupt sqlite file can cause an infinite loop in Apache Tika's SQLite3Parser in versions 1.8-1.19.1 of Apache Tika.

    Published: 22 Dec 2018
    5.5
    Medium

    CVE-2018-20348

    Last Modified: 21 Nov 2024

    libpff_item_tree_create_node in libpff_item_tree.c in libpff before experimental-20180714 allows attackers to cause a denial of service (infinite recursion) via a crafted file, related to libfdata_tree_get_node_value in libfdata_tree.c.

    Published: 22 Dec 2018
    6.5
    Medium

    CVE-2018-20349

    Last Modified: 21 Nov 2024

    The igraph_i_strdiff function in igraph_trie.c in igraph through 0.7.1 has an NULL pointer dereference that allows attackers to cause a denial of service (application crash) via a crafted object.

    Published: 22 Dec 2018
    7.8
    High

    CVE-2018-19322

    Last Modified: 7 Nov 2025

    The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

    Published: 21 Dec 2018
    7.8
    High

    CVE-2018-19320

    Last Modified: 7 Nov 2025

    The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-19323

    Last Modified: 7 Nov 2025

    The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

    Published: 21 Dec 2018
    8.8
    High

    CVE-2018-20193

    Last Modified: 21 Nov 2024

    Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1R5 (build 9627) 4.2 Release (build 7631). This occurs because appropriate controls are not performed. Specifically, it is possible for a readonly user to change the administrator user password by making a local copy of the /dana-admin/user/update.cgi page, changing the "user" value, and saving the changes.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-18007

    Last Modified: 21 Nov 2024

    atbox.htm on D-Link DSL-2770L devices allows remote unauthenticated attackers to discover admin credentials.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-18009

    Last Modified: 21 Nov 2024

    dirary0.js on D-Link DIR-140L, DIR-640L devices allows remote unauthenticated attackers to discover admin credentials.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-18008

    Last Modified: 21 Nov 2024

    spaces.htm on multiple D-Link devices (DSL, DIR, DWR) allows remote unauthenticated attackers to discover admin credentials.

    Published: 21 Dec 2018
    7.8
    High

    CVE-2018-19321

    Last Modified: 7 Nov 2025

    The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

    Published: 21 Dec 2018
    6.1
    Medium

    CVE-2018-16778

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Jenzabar v8.2.1 through 9.2.0 allows remote attackers to inject arbitrary web script or HTML via the query parameter (aka the Search Field).

    Published: 21 Dec 2018
    6.1
    Medium

    CVE-2018-20322

    Last Modified: 21 Nov 2024

    LimeSurvey version 3.15.5 contains a Cross-site scripting (XSS) vulnerability in Survey Resource zip upload, resulting in Javascript code execution against LimeSurvey administrators. Fixed in version 3.15.6.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-20325

    Last Modified: 21 Nov 2024

    There is a vulnerability in load() method in definitions/parser.py in the Danijar Hafner definitions package for Python. It can execute arbitrary python commands resulting in command execution.

    Published: 21 Dec 2018
    7.2
    High

    CVE-2018-20226

    Last Modified: 21 Nov 2024

    An organization administrator can add a super administrator in THEHIVE PROJECT Cortex before 2.1.3 due to the lack of overriding the Role.toString method.

    Published: 21 Dec 2018
    5.3
    Medium

    CVE-2018-20345

    Last Modified: 21 Nov 2024

    Incorrect access control in StackStorm API (st2api) in StackStorm before 2.9.2 and 2.10.x before 2.10.1 allows an attacker (who has a StackStorm account and is authenticated against the StackStorm API) to retrieve datastore items for other users by utilizing the /v1/keys "?scope=all" and "?user=<username>" query filter parameters. Enterprise editions with RBAC enabled are not affected.

    Published: 21 Dec 2018