CVE Feed

    Dashboard / CVE

    6.8
    Medium

    CVE-2018-20342

    Last Modified: 21 Nov 2024

    The Floureon IP Camera SP012 provides a root terminal on a UART serial interface without proper access control. This allows attackers with physical access to execute arbitrary commands with root privileges.

    Published: 21 Dec 2018
    5.5
    Medium

    CVE-2018-5201

    Last Modified: 21 Nov 2024

    Hancom Office 2018 10.0.0.8214 and earlier, Hancom Office NEO 9.6.1.10472 and earlier, Hancom Office 2014 9.1.1.4540 and earlier, Hancom Office 2010 8.5.8.1724 and earlier versions have a heap overflow vulnerability when handling Compound File in document. This result in a program crash or denial of service conditions.

    Published: 21 Dec 2018
    7.8
    High

    CVE-2018-5202

    Last Modified: 21 Nov 2024

    SKCertService 2.5.5 and earlier contains a vulnerability that could allow remote attacker to execute arbitrary code. This vulnerability exists due to the way .dll files are loaded by SKCertService. It allows an attacker to load a .dll of the attacker's choosing that could execute arbitrary code without the user's knowledge.

    Published: 21 Dec 2018
    7.5
    High

    CVE-2018-18331

    Last Modified: 21 Nov 2024

    A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.

    Published: 21 Dec 2018
    8.8
    High

    CVE-2018-5196

    Last Modified: 21 Nov 2024

    Alzip 10.76.0.0 and earlier is vulnerable to a stack overflow caused by improper bounds checking. By persuading a victim to open a specially-crafted LZH archive file, a attacker could execute arbitrary code execution.

    Published: 21 Dec 2018
    7.5
    High

    CVE-2018-18332

    Last Modified: 21 Nov 2024

    A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.

    Published: 21 Dec 2018
    6.5
    Medium

    CVE-2018-18330

    Last Modified: 21 Nov 2024

    An Address Bar Spoofing vulnerability in Trend Micro Dr. Safety for Android (Consumer) versions 3.0.1324 and below could allow an attacker to potentially trick a victim into visiting a malicious URL using address bar spoofing on the Private Browser of the app on vulnerable installations.

    Published: 21 Dec 2018
    —
    Unknown

    CVE-2018-11794

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it did not affect any released versions. Notes: none

    Published: 21 Dec 2018
    7.5
    High

    CVE-2018-20332

    Last Modified: 21 Nov 2024

    An issue has been discovered in the OpenWebif plugin through 1.2.4 for Enigma2 based devices. Reading of arbitrary files is possible with /file?action=download&file= followed by a full pathname, and listing of arbitrary directories is possible with /file?action=download&dir= followed by a full pathname. This is related to plugin/controllers/file.py in the e2openplugin-OpenWebif project.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-20338

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager 12.3 before build 123239 allows SQL injection in the Alarms section.

    Published: 21 Dec 2018
    6.1
    Medium

    CVE-2018-20339

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager 12.3 before build 123239 allows XSS in the Notes column of the Alarms section.

    Published: 21 Dec 2018
    5.4
    Medium

    CVE-2018-20327

    Last Modified: 21 Nov 2024

    Chamilo LMS version 1.11.8 contains XSS in main/template/default/admin/gradebook_list.tpl in the gradebook dependencies tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

    Published: 21 Dec 2018
    8.1
    High

    CVE-2018-20329

    Last Modified: 21 Nov 2024

    Chamilo LMS version 1.11.8 contains a main/inc/lib/CoursesAndSessionsCatalog.class.php SQL injection, allowing users with access to the sessions catalogue (which may optionally be made public) to extract and/or modify database information.

    Published: 21 Dec 2018
    5.4
    Medium

    CVE-2018-20328

    Last Modified: 21 Nov 2024

    Chamilo LMS version 1.11.8 contains XSS in main/social/group_view.php in the social groups tool, allowing authenticated users to affect other users, under specific conditions of permissions granted by administrators. This is considered "low risk" due to the nature of the feature it exploits.

    Published: 21 Dec 2018
    6.5
    Medium

    CVE-2018-20364

    Last Modified: 21 Nov 2024

    LibRaw::copy_bayer in libraw_cxx.cpp in LibRaw 0.19.1 has a NULL pointer dereference.

    Published: 21 Dec 2018
    6.5
    Medium

    CVE-2018-20365

    Last Modified: 21 Nov 2024

    LibRaw::raw2image() in libraw_cxx.cpp has a heap-based buffer overflow.

    Published: 21 Dec 2018
    9.8
    Critical

    CVE-2018-20318

    Last Modified: 21 Nov 2024

    An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.

    Published: 21 Dec 2018
    4.7
    Medium

    CVE-2018-16885

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel that allows the userspace to call memcpy_fromiovecend() and similar functions with a zero offset and buffer length which causes the read beyond the buffer boundaries, in certain cases causing a memory access fault and a system halt by accessing invalid memory address. This issue only affects kernel version 3.10.x as shipped with Red Hat Enterprise Linux 7.

    Published: 21 Dec 2018
    7.8
    High

    CVE-2018-18629

    Last Modified: 21 Nov 2024

    An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.

    Published: 20 Dec 2018
    5.4
    Medium

    CVE-2018-14846

    Last Modified: 21 Nov 2024

    The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-18388

    Last Modified: 21 Nov 2024

    eScan Agent Application (MWAGENT.EXE) 4.0.2.98 in MicroWorld Technologies eScan 14.0 allows remote or local attackers to execute arbitrary commands by sending a carefully crafted payload to TCP port 2222.

    Published: 20 Dec 2018
    7
    High

    CVE-2018-18767

    Last Modified: 21 Nov 2024

    An issue was discovered in D-Link 'myDlink Baby App' version 2.04.06. Whenever actions are performed from the app (e.g., change camera settings or play lullabies), it communicates directly with the Wi-Fi camera (D-Link 825L firmware 1.08) with the credentials (username and password) in base64 cleartext. An attacker could conduct an MitM attack on the local network and very easily obtain these credentials.

    Published: 20 Dec 2018
    7.2
    High

    CVE-2018-19239

    Last Modified: 21 Nov 2024

    TRENDnet TEW-673GRU v1.00b40 devices have an OS command injection vulnerability in the start_arpping function of the timer binary, which allows remote attackers to execute arbitrary commands via three parameters (dhcpd_start, dhcpd_end, and lan_ipaddr) passed to the apply.cgi binary through a POST request.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-19240

    Last Modified: 21 Nov 2024

    Buffer overflow in network.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-19241

    Last Modified: 21 Nov 2024

    Buffer overflow in video.cgi on TRENDnet TV-IP110WN V1.2.2 build 68, V1.2.2.65, and V1.2.2 build 64 and TV-IP121WN V1.2.2 build 28 devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (without authentication).

    Published: 20 Dec 2018
    8.8
    High

    CVE-2018-19242

    Last Modified: 21 Nov 2024

    Buffer overflow in apply.cgi on TRENDnet TEW-632BRP 1.010B32 and TEW-673GRU devices allows attackers to hijack the control flow to any attacker-specified location by crafting a POST request payload (with authentication).

    Published: 20 Dec 2018
    5.9
    Medium

    CVE-2018-17247

    Last Modified: 21 Nov 2024

    Elasticsearch Security versions 6.5.0 and 6.5.1 contain an XXE flaw in Machine Learning's find_file_structure API. If a policy allowing external network access has been added to Elasticsearch's Java Security Manager then an attacker could send a specially crafted request capable of leaking content of local files on the Elasticsearch node. This could allow a user to access information that they should not have access to.

    Published: 20 Dec 2018
    6.1
    Medium

    CVE-2018-12651

    Last Modified: 2 Mar 2026

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the ShiftEmployeeSearch.aspx prntFrmName or prntDDLCntrlName parameter.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2017-9732

    Last Modified: 21 Nov 2024

    The read_packet function in knc (Kerberised NetCat) before 1.11-1 is vulnerable to denial of service (memory exhaustion) that can be exploited remotely without authentication, possibly affecting another services running on the targeted host.

    Published: 20 Dec 2018
    6.1
    Medium

    CVE-2018-16627

    Last Modified: 21 Nov 2024

    panel/login in Kirby v2.5.12 allows Host header injection via the "forget password" feature.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-18399

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the "ContentPlaceHolder1_uxTitle" component in ArchiveNews.aspx in jco.ir KARMA 6.0.0 allows a remote attacker to execute arbitrary SQL commands via the "id" parameter.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-18441

    Last Modified: 21 Nov 2024

    D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: <Camera-IP>/common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hw_version, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-18442

    Last Modified: 21 Nov 2024

    D-Link DCS-825L devices with firmware 1.08 do not employ a suitable mechanism to prevent denial-of-service (DoS) attacks. An attacker can harm the device availability (i.e., live-online video/audio streaming) by using the hping3 tool to perform an IPv4 flood attack. Verified attacks includes SYN flooding, UDP flooding, ICMP flooding, and SYN-ACK flooding.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-1160

    Last Modified: 13 Feb 2026

    Netatalk before 3.1.12 is vulnerable to an out of bounds write in dsi_opensess.c. This is due to lack of bounds checking on attacker controlled data. A remote unauthenticated attacker can leverage this vulnerability to achieve arbitrary code execution.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-15720

    Last Modified: 21 Nov 2024

    Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-15721

    Last Modified: 21 Nov 2024

    The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-18871

    Last Modified: 21 Nov 2024

    Missing password verification in the web interface on Gigaset Maxwell Basic VoIP phones with firmware 2.22.7 would allow a remote attacker (in the same network as the device) to change the admin password without authentication (and without knowing the original password).

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-15723

    Last Modified: 21 Nov 2024

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo).

    Published: 20 Dec 2018
    8.1
    High

    CVE-2018-15722

    Last Modified: 21 Nov 2024

    The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2018-19005

    Last Modified: 21 Nov 2024

    Cscape, Version 9.80.75.3 SP3 and prior. An improper input validation vulnerability has been identified that may be exploited by processing specially crafted POC files lacking user input validation. This may allow an attacker to read confidential information and remotely execute arbitrary code.

    Published: 20 Dec 2018
    6.5
    Medium

    CVE-2018-1000883

    Last Modified: 21 Nov 2024

    Elixir Plug Plug version All contains a Header Injection vulnerability in Connection that can result in Given a cookie value, Headers can be added. This attack appear to be exploitable via Crafting a value to be sent as a cookie. This vulnerability appears to have been fixed in >= 1.3.5 or ~> 1.2.5 or ~> 1.1.9 or ~> 1.0.6.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-1000885

    Last Modified: 21 Nov 2024

    PHKP version including commit 88fd9cfdf14ea4b6ac3e3967feea7bcaabb6f03b contains a Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in function pgp_exec() phkp.php:98 that can result in It is possible to manipulate gpg-keys or execute commands remotely. This attack appear to be exploitable via HKP-Api: /pks/lookup?search.

    Published: 20 Dec 2018
    7.2
    High

    CVE-2018-15329

    Last Modified: 21 Nov 2024

    On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, or Enterprise Manager 3.1.1, when authenticated administrative users run commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

    Published: 20 Dec 2018
    7.8
    High

    CVE-2018-15331

    Last Modified: 21 Nov 2024

    On BIG-IP AAM 13.0.0 or 12.1.0-12.1.3.7, the dcdb_convert utility used by BIG-IP AAM fails to drop group permissions when executing helper scripts, which could be used to leverage attacks against the BIG-IP system.

    Published: 20 Dec 2018
    4.8
    Medium

    CVE-2018-8888

    Last Modified: 21 Nov 2024

    A stored cross-site scripting (XSS) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.10.0 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.

    Published: 20 Dec 2018
    4.8
    Medium

    CVE-2018-8891

    Last Modified: 21 Nov 2024

    Multiple stored cross-site scripting (XSS) vulnerabilities in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to store script commands that could later be executed in the context of another Management Console administrator.

    Published: 20 Dec 2018
    9.8
    Critical

    CVE-2018-1000884

    Last Modified: 21 Nov 2024

    Vesta CP version Prior to commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- any release prior to 0.9.8-18 contains a CWE-208 / Information Exposure Through Timing Discrepancy vulnerability in Password reset code -- web/reset/index.php, line 51 that can result in Possible to determine password reset codes, attacker is able to change administrator password. This attack appear to be exploitable via Unauthenticated network connectivity. This vulnerability appears to have been fixed in After commit f6f6f9cfbbf2979e301956d1c6ab5c44386822c0 -- release version 0.9.8-19.

    Published: 20 Dec 2018
    7.5
    High

    CVE-2018-15330

    Last Modified: 21 Nov 2024

    On BIG-IP 14.0.0-14.0.0.2, 13.0.0-13.1.1.1, or 12.1.0-12.1.3.7, when a virtual server using the inflate functionality to process a gzip bomb as a payload, the BIG-IP system will experience a fatal error and may cause the Traffic Management Microkernel (TMM) to produce a core file.

    Published: 20 Dec 2018
    6.5
    Medium

    CVE-2018-8892

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability in the Management Console of BlackBerry UEM versions earlier than 12.9.1 could allow an attacker to make modifications to the UEM settings in the context of a Management Console administrator.

    Published: 20 Dec 2018
    6.1
    Medium

    CVE-2018-1000868

    Last Modified: 21 Nov 2024

    WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The victim user must click a malicous link. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.

    Published: 20 Dec 2018