CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-19560

    Last Modified: 21 Nov 2024

    BageCMS 3.1.3 has CSRF via upload/index.php?r=admini/admin/ownerUpdate to modify a user account.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19562

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPok 4.9.015. admin.php?c=update&f=unzip allows remote attackers to execute arbitrary code via a "Login Background > Program Upgrade > Compressed Packet Upgrade" action in which a .php file is inside a ZIP archive.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19550

    Last Modified: 21 Nov 2024

    Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.

    Published: 26 Nov 2018
    9.8
    Critical

    CVE-2018-19557

    Last Modified: 21 Nov 2024

    An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.

    Published: 26 Nov 2018
    9.8
    Critical

    CVE-2018-19558

    Last Modified: 21 Nov 2024

    An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19545

    Last Modified: 21 Nov 2024

    JEECMS 9.3 has CSRF via the api/admin/role/save URI to add a user.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19549

    Last Modified: 21 Nov 2024

    Interspire Email Marketer through 6.1.6 has SQL Injection via a tagids Delete action to Dynamiccontenttags.php.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19552

    Last Modified: 21 Nov 2024

    Interspire Email Marketer through 6.1.6 has SQL Injection via a deleteblock blockid[] request to Dynamiccontenttags.php.

    Published: 26 Nov 2018
    5.4
    Medium

    CVE-2018-19554

    Last Modified: 21 Nov 2024

    An issue was discovered in Dotcms through 5.0.3. Attackers may perform XSS attacks via the inode, identifier, or fieldName parameter in html/js/dotcms/dijit/image/image_tool.jsp.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19561

    Last Modified: 21 Nov 2024

    sikcms 1.1 has CSRF via admin.php?m=Admin&c=Users&a=userAdd to add an administrator account.

    Published: 26 Nov 2018
    7.2
    High

    CVE-2018-19537

    Last Modified: 21 Nov 2024

    TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.

    Published: 26 Nov 2018
    9.8
    Critical

    CVE-2018-19530

    Last Modified: 21 Nov 2024

    HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when configured with an xml.codec=httl.spi.codecs.XstreamCodec setting.

    Published: 26 Nov 2018
    9.8
    Critical

    CVE-2018-19528

    Last Modified: 21 Nov 2024

    TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted DNS packets to port 53/udp.

    Published: 26 Nov 2018
    9.8
    Critical

    CVE-2018-19531

    Last Modified: 21 Nov 2024

    HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsafely when configured without an xml.codec= setting.

    Published: 26 Nov 2018
    8.8
    High

    CVE-2018-19532

    Last Modified: 21 Nov 2024

    A NULL pointer dereference vulnerability exists in the function PdfTranslator::setTarget() in pdftranslator.cpp of PoDoFo 0.9.6, while creating the PdfXObject, as demonstrated by podofoimpose. It allows an attacker to cause Denial of Service.

    Published: 26 Nov 2018
    5.5
    Medium

    CVE-2018-19840

    Last Modified: 21 Nov 2024

    The function WavpackPackInit in pack_utils.c in libwavpack.a in WavPack through 5.1.0 allows attackers to cause a denial-of-service (resource exhaustion caused by an infinite loop) via a crafted wav audio file because WavpackSetConfiguration64 mishandles a sample rate of zero.

    Published: 26 Nov 2018
    5.5
    Medium

    CVE-2018-18397

    Last Modified: 21 Nov 2024

    The userfaultfd implementation in the Linux kernel before 4.19.7 mishandles access control for certain UFFDIO_ ioctl calls, as demonstrated by allowing local users to write data into holes in a tmpfs file (if the user has read-only access to that file, and that file contains holes), related to fs/userfaultfd.c and mm/userfaultfd.c.

    Published: 26 Nov 2018
    6.5
    Medium

    CVE-2018-19587

    Last Modified: 21 Nov 2024

    In Cesanta Mongoose 6.13, a SIGSEGV exists in the mongoose.c mg_mqtt_add_session() function.

    Published: 26 Nov 2018
    5.5
    Medium

    CVE-2018-14646

    Last Modified: 21 Nov 2024

    The Linux kernel before 4.15-rc8 was found to be vulnerable to a NULL pointer dereference bug in the __netlink_ns_capable() function in the net/netlink/af_netlink.c file. A local attacker could exploit this when a net namespace with a netnsid is assigned to cause a kernel panic and a denial of service.

    Published: 26 Nov 2018
    5.5
    Medium

    CVE-2018-19519

    Last Modified: 21 Nov 2024

    In tcpdump 4.9.2, a stack-based buffer over-read exists in the print_prefix function of print-hncp.c via crafted packet data because of missing initialization.

    Published: 25 Nov 2018
    8.8
    High

    CVE-2018-19520

    Last Modified: 21 Nov 2024

    An issue was discovered in SDCMS 1.6 with PHP 5.x. app/admin/controller/themecontroller.php uses a check_bad function in an attempt to block certain PHP functions such as eval, but does not prevent use of preg_replace 'e' calls, allowing users to execute arbitrary code by leveraging access to admin template management.

    Published: 25 Nov 2018
    8.8
    High

    CVE-2018-20330

    Last Modified: 21 Nov 2024

    The tjLoadImage function in libjpeg-turbo 2.0.1 has an integer overflow with a resultant heap-based buffer overflow via a BMP image because multiplication of pitch and height is mishandled, as demonstrated by tjbench.

    Published: 25 Nov 2018
    5.3
    Medium

    CVE-2018-16862

    Last Modified: 21 Nov 2024

    A security flaw was found in the Linux kernel in a way that the cleancache subsystem clears an inode after the final file truncation (removal). The new file created with the same inode may contain leftover pages from cleancache and the old file data instead of the new one.

    Published: 24 Nov 2018
    7.8
    High

    CVE-2018-19502

    Last Modified: 21 Nov 2024

    An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a heap-based buffer overflow in the function excluded_channels() in libfaad/syntax.c.

    Published: 23 Nov 2018
    7.8
    High

    CVE-2018-19503

    Last Modified: 21 Nov 2024

    An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There was a stack-based buffer overflow in the function calculate_gain() in libfaad/sbr_hfadj.c.

    Published: 23 Nov 2018
    7.8
    High

    CVE-2018-19504

    Last Modified: 21 Nov 2024

    An issue was discovered in Freeware Advanced Audio Decoder 2 (FAAD2) 2.8.1. There is a NULL pointer dereference in ifilter_bank() in libfaad/filtbank.c.

    Published: 23 Nov 2018
    7.2
    High

    CVE-2018-19499

    Last Modified: 21 Nov 2024

    Vanilla before 2.5.5 and 2.6.x before 2.6.2 allows Remote Code Execution because authenticated administrators have a reachable call to unserialize in the Gdn_Format class.

    Published: 23 Nov 2018
    9.8
    Critical

    CVE-2018-19468

    Last Modified: 21 Nov 2024

    HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/index.php?load=login&act=act_login URI.

    Published: 23 Nov 2018
    6.1
    Medium

    CVE-2018-19469

    Last Modified: 21 Nov 2024

    ArticleCMS through 2017-02-19 has XSS via the /update_personal_infomation realname or email parameter.

    Published: 23 Nov 2018
    5.5
    Medium

    CVE-2018-19567

    Last Modified: 21 Nov 2024

    A floating point exception in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.

    Published: 23 Nov 2018
    5.5
    Medium

    CVE-2018-19568

    Last Modified: 21 Nov 2024

    A floating point exception in kodak_radc_load_raw in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code.

    Published: 23 Nov 2018
    7.1
    High

    CVE-2018-19565

    Last Modified: 21 Nov 2024

    A buffer over-read in crop_masked_pixels in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

    Published: 23 Nov 2018
    7.1
    High

    CVE-2018-19566

    Last Modified: 21 Nov 2024

    A heap buffer over-read in parse_tiff_ifd in dcraw through 9.28 could be used by attackers able to supply malicious files to crash an application that bundles the dcraw code or leak private information.

    Published: 23 Nov 2018
    8.8
    High

    CVE-2018-1000858

    Last Modified: 21 Nov 2024

    GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be exploitable via Victim must perform a WKD request, e.g. enter an email address in the composer window of Thunderbird/Enigmail. This vulnerability appears to have been fixed in after commit 4a4bb874f63741026bd26264c43bb32b1099f060.

    Published: 23 Nov 2018
    6.5
    Medium

    CVE-2018-19607

    Last Modified: 21 Nov 2024

    Exiv2::isoSpeed in easyaccess.cpp in Exiv2 v0.27-RC2 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted file.

    Published: 23 Nov 2018
    8.8
    High

    CVE-2018-19463

    Last Modified: 21 Nov 2024

    zb_system/function/lib/upload.php in Z-BlogPHP through 1.5.1 allows remote attackers to execute arbitrary PHP code by using the image/jpeg content type in an upload to the zb_system/admin/index.php?act=UploadMng URI. NOTE: The vendor's position is "We have no dynamic including. No one can run PHP by uploading an image in current version." It also requires authentication

    Published: 22 Nov 2018
    4.8
    Medium

    CVE-2018-19464

    Last Modified: 21 Nov 2024

    Discuz! X3.4 allows XSS via admin.php because admincp/admincp_setting.php and template\default\common\footer.htm mishandles statcode field from third-party stats code.

    Published: 22 Nov 2018
    7.2
    High

    CVE-2018-19457

    Last Modified: 21 Nov 2024

    Logicspice FAQ Script 2.9.7 allows uploading arbitrary files, which leads to remote command execution via admin/faqs/faqimages with a .php file.

    Published: 22 Nov 2018
    7.5
    High

    CVE-2018-19458

    Last Modified: 21 Nov 2024

    In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.

    Published: 22 Nov 2018
    7.8
    High

    CVE-2018-19459

    Last Modified: 21 Nov 2024

    Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.

    Published: 22 Nov 2018
    5.9
    Medium

    CVE-2018-19443

    Last Modified: 21 Nov 2024

    The client in Tryton 5.x before 5.0.1 tries to make a connection to the bus in cleartext instead of encrypted under certain circumstances in bus.py and jsonrpc.py. This connection attempt fails, but it contains in the header the current session of the user. This session could then be stolen by a man-in-the-middle.

    Published: 22 Nov 2018
    6.1
    Medium

    CVE-2018-19433

    Last Modified: 21 Nov 2024

    ShowDoc 2.4.1 has XSS via the lang parameter because install/database.php mishandles the $cur_lang value.

    Published: 22 Nov 2018
    7.2
    High

    CVE-2018-19434

    Last Modified: 21 Nov 2024

    An issue was discovered on the "Bank Account Matching - Receipts" screen of the General Ledger component in webERP 4.15. BankMatching.php has Blind SQL injection via the AmtClear_ parameter.

    Published: 22 Nov 2018
    7.2
    High

    CVE-2018-19435

    Last Modified: 21 Nov 2024

    An issue was discovered in the Sales component in webERP 4.15. SalesInquiry.php has SQL Injection via the SortBy parameter.

    Published: 22 Nov 2018
    7.2
    High

    CVE-2018-19436

    Last Modified: 21 Nov 2024

    An issue was discovered in the Manufacturing component in webERP 4.15. CollectiveWorkOrderCost.php has Blind SQL Injection via the SearchParts parameter.

    Published: 22 Nov 2018
    8.8
    High

    CVE-2018-19437

    Last Modified: 21 Nov 2024

    UCMS 1.4.7 allows remote authenticated users to change the administrator password because $_COOKIE['admin_'.cookiehash] is used for arbitrary cookie values that are set and not empty.

    Published: 22 Nov 2018
    6.5
    Medium

    CVE-2018-19432

    Last Modified: 21 Nov 2024

    An issue was discovered in libsndfile 1.0.28. There is a NULL pointer dereference in the function sf_write_int in sndfile.c, which will lead to a denial of service.

    Published: 22 Nov 2018
    4.7
    Medium

    CVE-2018-19489

    Last Modified: 21 Nov 2024

    v9fs_wstat in hw/9pfs/9p.c in QEMU allows guest OS users to cause a denial of service (crash) because of a race condition during file renaming.

    Published: 22 Nov 2018
    6.5
    Medium

    CVE-2018-20532

    Last Modified: 21 Nov 2024

    There is a NULL pointer dereference at ext/testcase.c (function testcase_read) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.

    Published: 22 Nov 2018
    6.5
    Medium

    CVE-2018-20533

    Last Modified: 21 Nov 2024

    There is a NULL pointer dereference at ext/testcase.c (function testcase_str2dep_complex) in libsolvext.a in libsolv through 0.7.2 that will cause a denial of service.

    Published: 22 Nov 2018