CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2018-18942

    Last Modified: 21 Nov 2024

    In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.

    Published: 5 Nov 2018
    4.8
    Medium

    CVE-2018-18927

    Last Modified: 21 Nov 2024

    An issue was discovered in PublicCMS V4.0. It allows XSS by modifying the page_list "attached" attribute (which typically has 'class="icon-globe icon-large"' in its value), as demonstrated by an 'UPDATE sys_module SET attached = "[XSS]" WHERE id="page_list"' statement.

    Published: 4 Nov 2018
    9.8
    Critical

    CVE-2018-18926

    Last Modified: 21 Nov 2024

    Gitea before 1.5.4 allows remote code execution because it does not properly validate session IDs. This is related to session ID handling in the go-macaron/session code for Macaron.

    Published: 4 Nov 2018
    9.8
    Critical

    CVE-2018-18925

    Last Modified: 21 Nov 2024

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.

    Published: 4 Nov 2018
    8.8
    High

    CVE-2018-18924

    Last Modified: 21 Nov 2024

    The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image" error message.

    Published: 4 Nov 2018
    4.8
    Medium

    CVE-2018-18919

    Last Modified: 21 Nov 2024

    The WP Editor.md plugin 10.0.1 for WordPress allows XSS via the comment area.

    Published: 4 Nov 2018
    6.1
    Medium

    CVE-2018-18909

    Last Modified: 21 Nov 2024

    xhEditor 1.2.2 allows XSS via JavaScript code in the SRC attribute of an IFRAME element within the editor's source-code view.

    Published: 3 Nov 2018
    9.8
    Critical

    CVE-2018-18903

    Last Modified: 21 Nov 2024

    Vanilla 2.6.x before 2.6.4 allows remote code execution.

    Published: 3 Nov 2018
    4.7
    Medium

    CVE-2018-19854

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel before 4.19.3. crypto_report_one() and related functions in crypto/crypto_user.c (the crypto user configuration API) do not fully initialize structures that are copied to userspace, potentially leaking sensitive memory to user programs. NOTE: this is a CVE-2013-2547 regression but with easier exploitability because the attacker does not need a capability (however, the system must have the CONFIG_CRYPTO_USER kconfig option).

    Published: 3 Nov 2018
    8.8
    High

    CVE-2018-11062

    Last Modified: 21 Nov 2024

    Integrated Data Protection Appliance versions 2.0, 2.1, and 2.2 contain undocumented accounts named 'support' and 'admin' that are protected with default passwords. These accounts have limited privileges and can access certain system files only. A malicious user with the knowledge of the default passwords may potentially log in to the system and gain read and write access to certain system files.

    Published: 2 Nov 2018
    9
    Critical

    CVE-2018-15762

    Last Modified: 21 Nov 2024

    Pivotal Operations Manager, versions 2.0.x prior to 2.0.24, versions 2.1.x prior to 2.1.15, versions 2.2.x prior to 2.2.7, and versions 2.3.x prior to 2.3.1, grants all users a scope which allows for privilege escalation. A remote malicious user who has been authenticated may create a new client with administrator privileges for Opsman.

    Published: 2 Nov 2018
    8.2
    High

    CVE-2018-7798

    Last Modified: 29 May 2026

    A Insufficient Verification of Data Authenticity (CWE-345) vulnerability exists in the Modicon M221, all versions, which could cause a change of IPv4 configuration (IP address, mask and gateway) when remotely connected to the device.

    Published: 2 Nov 2018
    7.5
    High

    CVE-2018-3898

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the ssid_dst field.

    Published: 2 Nov 2018
    7.5
    High

    CVE-2018-3899

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the QR code scanning functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted QR Code can cause a buffer overflow, resulting in code execution. The trans_info call can overwrite a buffer of size 0x104, which is more than enough to overflow the return address from the password_dst field

    Published: 2 Nov 2018
    6.8
    Medium

    CVE-2018-3920

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the firmware update functionality of the Yi Home Camera 27US 1.8.7.0D. A specially crafted 7-Zip file can cause a CRC collision, resulting in a firmware update and code execution. An attacker can insert an SDcard to trigger this vulnerability.

    Published: 2 Nov 2018
    7.5
    High

    CVE-2018-3935

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the UDP network functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can allocate unlimited memory, resulting in denial of service. An attacker can send a set of packets to trigger this vulnerability.

    Published: 2 Nov 2018
    7.8
    High

    CVE-2018-7799

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.

    Published: 2 Nov 2018
    6.8
    Medium

    CVE-2018-3890

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw and command injection, resulting in code execution. An attacker can insert an SD card to trigger this vulnerability.

    Published: 2 Nov 2018
    8.1
    High

    CVE-2018-3892

    Last Modified: 21 Nov 2024

    An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this vulnerability.

    Published: 2 Nov 2018
    4.6
    Medium

    CVE-2018-3891

    Last Modified: 21 Nov 2024

    An exploitable firmware downgrade vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted file can cause a logic flaw, resulting in a firmware downgrade. An attacker can insert an SD card to trigger this vulnerability.

    Published: 2 Nov 2018
    9.8
    Critical

    CVE-2018-3934

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the firmware update functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted set of UDP packets can cause a logic flaw, resulting in an authentication bypass. An attacker can sniff network traffic and send a set of packets to trigger this vulnerability.

    Published: 2 Nov 2018
    5.5
    Medium

    CVE-2018-1552

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 10.0 and 11.0 allows a remote attacker to execute arbitrary code on the system, caused by a missing restriction in which file types can be uploaded to the control room. By uploading a malicious file and tricking a victim to run it, an attacker could exploit this vulnerability to execute arbitrary code on the system. IBM X-Force ID: 142889.

    Published: 2 Nov 2018
    9.8
    Critical

    CVE-2018-17918

    Last Modified: 21 Nov 2024

    Circontrol CirCarLife all versions prior to 4.3.1, authentication to the device can be bypassed by entering the URL of a specific page.

    Published: 2 Nov 2018
    7.1
    High

    CVE-2018-1846

    Last Modified: 21 Nov 2024

    IBM Rational Engineering Lifecycle Manager 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150945.

    Published: 2 Nov 2018
    6.2
    Medium

    CVE-2018-1876

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could under certain cases, display the password in a Control Room log file after installation. IBM X-Force ID: 151707.

    Published: 2 Nov 2018
    5.3
    Medium

    CVE-2018-1878

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could disclose sensitive information in a web request that could aid in future attacks against the system. IBM X-Force ID: 151714.

    Published: 2 Nov 2018
    7.1
    High

    CVE-2018-1835

    Last Modified: 21 Nov 2024

    IBM Daeja ViewONE Professional, Standard & Virtual 5 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150514.

    Published: 2 Nov 2018
    9.8
    Critical

    CVE-2018-17922

    Last Modified: 21 Nov 2024

    Circontrol CirCarLife all versions prior to 4.3.1, the PAP credentials of the device are stored in clear text in a log file that is accessible without authentication.

    Published: 2 Nov 2018
    6.2
    Medium

    CVE-2018-1877

    Last Modified: 21 Nov 2024

    IBM Robotic Process Automation with Automation Anywhere 11 could store highly sensitive information in the form of unencrypted passwords that would be available to a local user. IBM X-Force ID: 151713.

    Published: 2 Nov 2018
    5.4
    Medium

    CVE-2017-1609

    Last Modified: 21 Nov 2024

    IBM Quality Manager (RQM) 5.0 through 5.0.2 and 6.0 through 6.0.6 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 132929.

    Published: 2 Nov 2018
    4.1
    Medium

    CVE-2018-1788

    Last Modified: 21 Nov 2024

    IBM Spectrum Protect Server 7.1 and 8.1 could disclose highly sensitive information via trace logs to a local privileged user. IBM X-Force ID: 148873.

    Published: 2 Nov 2018
    7.5
    High

    CVE-2018-17912

    Last Modified: 21 Nov 2024

    An XXE vulnerability exists in CASE Suite Versions 3.10 and prior when processing parameter entities, which may allow remote file disclosure.

    Published: 2 Nov 2018
    9.8
    Critical

    CVE-2018-17914

    Last Modified: 21 Nov 2024

    InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine Edition) runtime.

    Published: 2 Nov 2018
    9.8
    Critical

    CVE-2018-17916

    Last Modified: 21 Nov 2024

    InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. If InduSoft Web Studio remote communication security was not enabled, or a password was left blank, a remote user could send a carefully crafted packet to invoke an arbitrary process, with potential for code to be executed. The code would be executed under the privileges of the InduSoft Web Studio or InTouch Edge HMI runtime and could lead to a compromise of the InduSoft Web Studio or InTouch Edge HMI server machine.

    Published: 2 Nov 2018
    7.5
    High

    CVE-2018-16472

    Last Modified: 21 Nov 2024

    A prototype pollution attack in cached-path-relative versions <=1.0.1 allows an attacker to inject properties on Object.prototype which are then inherited by all the JS objects through the prototype chain causing a DoS attack.

    Published: 2 Nov 2018
    3.1
    Low

    CVE-2018-16849

    Last Modified: 21 Nov 2024

    A flaw was found in openstack-mistral. By manipulating the SSH private key filename, the std.ssh action can be used to disclose the presence of arbitrary files within the filesystem of the executor running the action. Since std.ssh private_key_filename can take an absolute path, it can be used to assess whether or not a file exists on the executor's filesystem.

    Published: 2 Nov 2018
    6.5
    Medium

    CVE-2018-18915

    Last Modified: 21 Nov 2024

    There is an infinite loop in the Exiv2::Image::printIFDStructure function of image.cpp in Exiv2 0.27-RC1. A crafted input will lead to a remote denial of service attack.

    Published: 2 Nov 2018
    4.8
    Medium

    CVE-2018-10586

    Last Modified: 21 Nov 2024

    NetGain Enterprise Manager (EM) is affected by multiple Stored Cross-Site Scripting (XSS) vulnerabilities in versions before 10.1.12.

    Published: 1 Nov 2018
    7.8
    High

    CVE-2018-18695

    Last Modified: 21 Nov 2024

    M2SOFT Report Designer Viewer 5.0 allows a Buffer Overflow with Extended Instruction Pointer (EIP) control via a crafted MRD file.

    Published: 1 Nov 2018
    6.1
    Medium

    CVE-2018-18775

    Last Modified: 21 Nov 2024

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.

    Published: 1 Nov 2018
    6.1
    Medium

    CVE-2018-18776

    Last Modified: 21 Nov 2024

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.

    Published: 1 Nov 2018
    9.8
    Critical

    CVE-2018-6012

    Last Modified: 21 Nov 2024

    The 'Weather Service' feature of the Green Electronics RainMachine Mini-8 (2nd generation) allows an attacker to inject arbitrary Python code via the 'Add new weather data source' upload function.

    Published: 1 Nov 2018
    8.8
    High

    CVE-2018-6907

    Last Modified: 21 Nov 2024

    A Cross Site Request Forgery (CSRF) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to control the RainMachine device via the REST API.

    Published: 1 Nov 2018
    6.5
    Medium

    CVE-2018-6909

    Last Modified: 21 Nov 2024

    A missing X-Frame-Options header in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application could be used by a remote attacker for clickjacking, as demonstrated by triggering an API page request.

    Published: 1 Nov 2018
    7.8
    High

    CVE-2018-18714

    Last Modified: 21 Nov 2024

    RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This can lead to denial of service (DoS) or code execution with root privileges.

    Published: 1 Nov 2018
    9.8
    Critical

    CVE-2018-6908

    Last Modified: 21 Nov 2024

    An authentication bypass vulnerability exists in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allowing an unauthenticated attacker to perform authenticated actions on the device via a 127.0.0.1:port value in the HTTP 'Host' header, as demonstrated by retrieving credentials.

    Published: 1 Nov 2018
    7.2
    High

    CVE-2018-10587

    Last Modified: 21 Nov 2024

    NetGain Enterprise Manager (EM) is affected by OS Command Injection vulnerabilities in versions before 10.0.57. These vulnerabilities could allow remote authenticated attackers to inject arbitrary code, resulting in remote code execution.

    Published: 1 Nov 2018
    4.3
    Medium

    CVE-2018-18777

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.

    Published: 1 Nov 2018
    8.1
    High

    CVE-2018-6011

    Last Modified: 21 Nov 2024

    The time-based one-time-password (TOTP) function in the application logic of the Green Electronics RainMachine Mini-8 (2nd generation) uses the administrator's password hash to generate a 6-digit temporary passcode that can be used for remote and local access, aka a "Use of Password Hash Instead of Password for Authentication" issue. This is exploitable by an attacker who discovers a hash value in the rainmachine-settings.sqlite file.

    Published: 1 Nov 2018
    6.1
    Medium

    CVE-2018-6906

    Last Modified: 21 Nov 2024

    A persistent Cross Site Scripting (XSS) vulnerability in the Green Electronics RainMachine Mini-8 (2nd Generation) and Touch HD 12 web application allows an attacker to inject arbitrary JavaScript via the REST API.

    Published: 1 Nov 2018