CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-19067

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password for the factory~ account.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19069

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The CGIProxy.fcgi?cmd=setTelnetSwitch feature is authorized for the root user with a password of toor.

    Published: 7 Nov 2018
    7.2
    High

    CVE-2018-19070

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. They allow remote attackers to execute arbitrary OS commands via shell metacharacters in the usrName parameter of a CGIProxy.fcgi addAccount action.

    Published: 7 Nov 2018
    5.3
    Medium

    CVE-2018-19075

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The firewall feature makes it easier for remote attackers to ascertain credentials and firewall rules because invalid credentials lead to error -2, whereas rule-based blocking leads to error -8.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19079

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SystemReboot method allows unauthenticated reboot.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19083

    Last Modified: 21 Nov 2024

    WeCenter 3.2.0 through 3.2.2 has XSS in the views/default/question/index.tpl.html htmlspecialchars_decode function via the /?/publish/ajax/publish_question/ question_content parameter.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19063

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The admin account has a blank password.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19064

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ftpuser1 account has a blank password, which cannot be changed.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19066

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The exported device configuration is encrypted with the hardcoded Pxift* password in some cases.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19076

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP).

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19077

    Last Modified: 21 Nov 2024

    An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. RtspServer allows remote attackers to cause a denial of service (daemon hang or restart) via a negative integer in the RTSP Content-Length header.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-19061

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 SP2 has SQL Injection via the dede\co_do.php ids parameter.

    Published: 7 Nov 2018
    9.6
    Critical

    CVE-2018-18590

    Last Modified: 21 Nov 2024

    A potential remote code execution and information disclosure vulnerability exists in Micro Focus Operations Bridge containerized suite versions 2017.11, 2018.02, 2018.05, 2018.08. This vulnerability could allow for information disclosure.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19056

    Last Modified: 21 Nov 2024

    pandao Editor.md 1.5.0 has DOM XSS via input starting with a "<<" substring, which is mishandled during construction of an A element.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19057

    Last Modified: 21 Nov 2024

    SimpleMDE 1.11.2 has XSS via an onerror attribute of a crafted IMG element, or via certain input with [ and ( characters, which is mishandled during construction of an A element.

    Published: 7 Nov 2018
    9.8
    Critical

    CVE-2018-8021

    Last Modified: 21 Nov 2024

    Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

    Published: 7 Nov 2018
    7.2
    High

    CVE-2018-19053

    Last Modified: 21 Nov 2024

    PbootCMS 1.2.2 allows remote attackers to execute arbitrary PHP code by specifying a .php filename in a "SET GLOBAL general_log_file" statement, followed by a SELECT statement containing this PHP code.

    Published: 7 Nov 2018
    10
    Critical

    CVE-2018-19047

    Last Modified: 21 Nov 2024

    mPDF through 7.1.6, if deployed as a web application that accepts arbitrary HTML, allows SSRF, as demonstrated by a '<img src="http://192.168' substring that triggers a call to getImage in Image/ImageProcessor.php. NOTE: the software maintainer disputes this, stating "If you allow users to pass HTML without sanitising it, you're asking for trouble.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-19052

    Last Modified: 21 Nov 2024

    An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19050

    Last Modified: 21 Nov 2024

    MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword langset parameter.

    Published: 7 Nov 2018
    6.1
    Medium

    CVE-2018-19051

    Last Modified: 21 Nov 2024

    MetInfo 6.1.3 has XSS via the admin/index.php?a=dogetpassword abt_type parameter.

    Published: 7 Nov 2018
    5.5
    Medium

    CVE-2018-19364

    Last Modified: 21 Nov 2024

    hw/9pfs/cofile.c and hw/9pfs/9p.c in QEMU can modify an fid path while it is being accessed by a second thread, leading to (for example) a use-after-free outcome.

    Published: 7 Nov 2018
    7.5
    High

    CVE-2018-12415

    Last Modified: 21 Nov 2024

    The Central Administration server (emsca) component of TIBCO Software Inc.'s TIBCO Enterprise Message Service, TIBCO Enterprise Message Service - Community Edition, and TIBCO Enterprise Message Service - Developer Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Enterprise Message Service: versions 8.4.0 and below, TIBCO Enterprise Message Service - Community Edition: versions 8.4.0 and below, and TIBCO Enterprise Message Service - Developer Edition: versions 8.4.0 and below.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-12414

    Last Modified: 21 Nov 2024

    The Rendezvous Routing Daemon (rvrd), Rendezvous Secure Routing Daemon (rvrsd), Rendezvous Secure Daemon (rvsd), Rendezvous Cache (rvcache), and Rendezvous Daemon Manager (rvdm) components of TIBCO Software Inc.'s TIBCO Rendezvous, TIBCO Rendezvous Developer Edition, TIBCO Rendezvous for z/Linux, TIBCO Rendezvous for z/OS, TIBCO Rendezvous Network Server, TIBCO Substation ES contain vulnerabilities which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO Rendezvous: versions up to and including 8.4.5, TIBCO Rendezvous Developer Edition: versions up to and including 8.4.5, TIBCO Rendezvous for z/Linux: versions up to and including 8.4.5, TIBCO Rendezvous for z/OS: versions up to and including 8.4.5, TIBCO Rendezvous Network Server: versions up to and including 1.1.2, and TIBCO Substation ES: versions up to and including 2.12.2.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-12413

    Last Modified: 21 Nov 2024

    The Schema repository server (tibschemad) component of TIBCO Software Inc.'s TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Community Edition: 1.0.0, and TIBCO Messaging - Apache Kafka Distribution - Schema Repository - Enterprise Edition: 1.0.0.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-12412

    Last Modified: 21 Nov 2024

    The realm server (tibrealmserver) component of TIBCO Software Inc. TIBCO FTL - Community Edition, TIBCO FTL - Developer Edition, and TIBCO FTL - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc. TIBCO FTL - Community Edition: versions up to and including 5.4.0, TIBCO FTL - Developer Edition: versions up to and including 5.4.0, TIBCO FTL - Enterprise Edition: versions up to and including 5.4.0.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-12411

    Last Modified: 21 Nov 2024

    The administrative daemon (tibdgadmind) of TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition, TIBCO ActiveSpaces - Developer Edition, and TIBCO ActiveSpaces - Enterprise Edition contains a vulnerability which may allow an attacker to perform cross-site request forgery (CSRF) attacks. Affected releases are TIBCO Software Inc.'s TIBCO ActiveSpaces - Community Edition: 3.3.0; 3.4.0; 3.5.0, TIBCO ActiveSpaces - Developer Edition: 3.0.0; 3.1.0; 3.3.0; 3.4.0; 3.5.0, and TIBCO ActiveSpaces - Enterprise Edition: 3.0.0; 3.1.0; 3.2.0; 3.3.0; 3.4.0; 3.5.0.

    Published: 6 Nov 2018
    7.2
    High

    CVE-2018-17186

    Last Modified: 21 Nov 2024

    An administrator with workflow definition entitlements can use DTD to perform malicious operations, including but not limited to file read, file write, and code execution.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-16475

    Last Modified: 21 Nov 2024

    A Path Traversal in Knightjs versions <= 0.0.1 allows an attacker to read content of arbitrary files on a remote server.

    Published: 6 Nov 2018
    5.3
    Medium

    CVE-2018-16473

    Last Modified: 21 Nov 2024

    A path traversal in takeapeek module versions <=0.2.2 allows an attacker to list directory and files.

    Published: 6 Nov 2018
    6.1
    Medium

    CVE-2018-16474

    Last Modified: 21 Nov 2024

    A stored xss in tianma-static module versions <=1.0.4 allows an attacker to execute arbitrary javascript.

    Published: 6 Nov 2018
    5.4
    Medium

    CVE-2018-17184

    Last Modified: 21 Nov 2024

    A malicious user with enough administration entitlements can inject html-like elements containing JavaScript statements into Connector names, Report names, AnyTypeClass keys and Policy descriptions. When another user with enough administration entitlements edits one of the Entities above via Admin Console, the injected JavaScript code is executed.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-14667

    Last Modified: 3 Nov 2025

    The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

    Published: 6 Nov 2018
    9.8
    Critical

    CVE-2018-9356

    Last Modified: 21 Nov 2024

    In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74950468.

    Published: 6 Nov 2018
    7.8
    High

    CVE-2018-9357

    Last Modified: 21 Nov 2024

    In BNEP_Write of bnep_api.cc, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with User execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74947856.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9359

    Last Modified: 21 Nov 2024

    In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74196706.

    Published: 6 Nov 2018
    7.8
    High

    CVE-2018-9385

    Last Modified: 21 Nov 2024

    In driver_override_store of bus.c, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-74128061 References: Upstream kernel.

    Published: 6 Nov 2018
    7.8
    High

    CVE-2018-9427

    Last Modified: 21 Nov 2024

    In CopyToOMX of OMXNodeInstance.cpp there is a possible out-of-bounds write due to an incorrect bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-77486542.

    Published: 6 Nov 2018
    5
    Medium

    CVE-2018-9438

    Last Modified: 21 Nov 2024

    When a device connects only over WiFi VPN, the device may not receive security updates due to some incorrect checks. This could lead to a local denial of service of security updates with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.1 Android ID: A-78644887.

    Published: 6 Nov 2018
    5.5
    Medium

    CVE-2018-9444

    Last Modified: 21 Nov 2024

    In ih264d_video_decode of ih264d_api.c there is a possible resource exhaustion due to an infinite loop. This could lead to remote temporary device denial of service (remote hang or reboot) with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android ID: A-63521984.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9448

    Last Modified: 21 Nov 2024

    In avct_bcb_msg_ind of avct_bcb_act.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-79944113.

    Published: 6 Nov 2018
    8.8
    High

    CVE-2018-9450

    Last Modified: 21 Nov 2024

    In avrc_proc_vendor_command of avrc_api.cc, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-79541338.

    Published: 6 Nov 2018
    5.5
    Medium

    CVE-2018-9451

    Last Modified: 21 Nov 2024

    In DynamicRefTable::load of ResourceTypes.cpp, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-79488511.

    Published: 6 Nov 2018
    5.5
    Medium

    CVE-2018-9454

    Last Modified: 21 Nov 2024

    In bnep_data_ind of bnep_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78286118.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9455

    Last Modified: 21 Nov 2024

    In sdpu_extract_attr_seq of sdp_utils.cc, there is a possible out of bounds read due to an incorrect bounds check. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-78136677.

    Published: 6 Nov 2018
    7.8
    High

    CVE-2018-9458

    Last Modified: 21 Nov 2024

    In computeFocusedWindow of RootWindowContainer.java, and related functions, there is possible interception of keypresses due to focus being on the wrong window. This could lead to local escalation of privilege revealing the user's keypresses while the screen was locked with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android ID: A-71786287.

    Published: 6 Nov 2018
    7.8
    High

    CVE-2018-9488

    Last Modified: 21 Nov 2024

    In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-110107376.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9489

    Last Modified: 21 Nov 2024

    When wifi is switched, function sendNetworkStateChangeBroadcast of WifiStateMachine.java broadcasts an intent including detailed wifi network information. This could lead to information disclosure with no execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-77286245.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9360

    Last Modified: 21 Nov 2024

    In process_l2cap_cmd of l2c_main.cc, there is a possible out of bounds read due to a missing bounds check. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74201143.

    Published: 6 Nov 2018
    7.5
    High

    CVE-2018-9362

    Last Modified: 21 Nov 2024

    In processMessagePart of InboundSmsHandler.java, there is a possible remote denial of service due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-72298611.

    Published: 6 Nov 2018