CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-18754

    Last Modified: 21 Nov 2024

    ZyXEL VMG3312-B10B 1.00(AAPP.7) devices have a backdoor root account with the tTn3+Z@!Sr0O+ password hash in the etc/default.cfg file.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2018-18753

    Last Modified: 21 Nov 2024

    Typecho V1.1 allows remote attackers to send shell commands via base64-encoded serialized data, as demonstrated by SSRF.

    Published: 28 Oct 2018
    5.4
    Medium

    CVE-2018-18733

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Catfish CMS 4.8.30, related to "write source code," a similar issue to CVE-2018-13999.

    Published: 28 Oct 2018
    5.4
    Medium

    CVE-2018-18736

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in catfish blog 2.0.33, related to "write source code."

    Published: 28 Oct 2018
    7.5
    High

    CVE-2018-18737

    Last Modified: 21 Nov 2024

    An XXE issue was discovered in Douchat 4.0.4 because Data\notify.php calls simplexml_load_string. This can also be used for SSRF.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18738

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Categories.php?pid=1&lgid=1 category_key parameter.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18739

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_Products.php?lgid=1 Keywords field.

    Published: 28 Oct 2018
    8.8
    High

    CVE-2018-18742

    Last Modified: 21 Nov 2024

    A CSRF issue was discovered in SEMCMS 3.4 via the admin/SEMCMS_User.php?Class=add&CF=user URI.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18743

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via the second text field to the admin/SEMCMS_Categories.php?pid=1&lgid=1 URI.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18745

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Menu.php?lgid=1 during editing.

    Published: 28 Oct 2018
    5.5
    Medium

    CVE-2018-18749

    Last Modified: 21 Nov 2024

    data-tools through 2017-07-26 has an Integer Overflow leading to an incorrect end value for the write_wchars function.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2016-10731

    Last Modified: 21 Nov 2024

    ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.

    Published: 28 Oct 2018
    8.8
    High

    CVE-2018-18734

    Last Modified: 21 Nov 2024

    A CSRF issue was discovered in admin/Index/addmanageuser.html in Catfish CMS 4.8.30.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18741

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via admin/SEMCMS_Download.php?lgid=1 during editing.

    Published: 28 Oct 2018
    10
    Critical

    CVE-2018-18748

    Last Modified: 4 Aug 2025

    Sandboxie 5.26 allows a Sandbox Escape via an "import os" statement, followed by os.system("cmd") or os.system("powershell"), within a .py file. NOTE: the vendor disputes this issue because the observed behavior is consistent with the product's intended functionality

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2016-10734

    Last Modified: 21 Nov 2024

    ProjectSend (formerly cFTP) r582 allows Insecure Direct Object Reference via includes/actions.log.export.php.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2016-10732

    Last Modified: 21 Nov 2024

    ProjectSend (formerly cFTP) r582 allows authentication bypass via a direct request for users.php, home.php, edit-file.php?file_id=1, or process-zip-download.php, or add_user_form_* parameters to users-add.php.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2016-10733

    Last Modified: 21 Nov 2024

    ProjectSend (formerly cFTP) r582 allows directory traversal via file=../ in the process-zip-download.php query string.

    Published: 28 Oct 2018
    8.8
    High

    CVE-2018-18735

    Last Modified: 21 Nov 2024

    A CSRF issue was discovered in admin/Index/tiquan in catfish blog 2.0.33.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18740

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via the first input field to the admin/SEMCMS_Link.php?lgid=1 URI.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18744

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in SEMCMS 3.4 via the fifth text box to the admin/SEMCMS_Main.php URI.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2019-5413

    Last Modified: 21 Nov 2024

    An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18720

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18721

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18723

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18724

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in index.php/admin/category/editcategory?id=73 in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18725

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in admin/banner/editbanner?id=20 in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18726

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in admin/sitelink/editsitelink?id=16 in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2018-18728

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC9 V15.03.05.19(6318)_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. They allow remote code execution via shell metacharacters in the usbName field to the __fastcall function with a POST request.

    Published: 28 Oct 2018
    7.5
    High

    CVE-2018-18730

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'startIp' and 'endIp' parameters for a post request, each value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

    Published: 28 Oct 2018
    7.5
    High

    CVE-2018-18731

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceMac' parameter for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

    Published: 28 Oct 2018
    7.5
    High

    CVE-2018-18732

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'ntpServer' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2018-18751

    Last Modified: 21 Nov 2024

    An issue was discovered in GNU gettext 0.19.8. There is a double free in default_add_message in read-catalog.c, related to an invalid free in po_gram_parse in po-gram-gen.y, as demonstrated by lt-msgfmt.

    Published: 28 Oct 2018
    5.5
    Medium

    CVE-2018-19209

    Last Modified: 21 Nov 2024

    Netwide Assembler (NASM) 2.14rc15 has a NULL pointer dereference in the function find_label in asm/labels.c that will lead to a DoS attack.

    Published: 28 Oct 2018
    6.5
    Medium

    CVE-2018-19210

    Last Modified: 21 Nov 2024

    In LibTIFF 4.0.9, there is a NULL pointer dereference in the TIFFWriteDirectorySec function in tif_dirwrite.c that will lead to a denial of service attack, as demonstrated by tiffset.

    Published: 28 Oct 2018
    6.5
    Medium

    CVE-2018-19218

    Last Modified: 21 Nov 2024

    In LibSass 3.5-stable, there is an illegal address access at Sass::Parser::parse_css_variable_value_token that will lead to a DoS attack.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18717

    Last Modified: 21 Nov 2024

    An issue was discovered in Eleanor CMS through 2015-03-19. XSS exists via the ajax.php?direct=admin&file=autocomplete&query=[XSS] URI.

    Published: 28 Oct 2018
    5.5
    Medium

    CVE-2018-19211

    Last Modified: 21 Nov 2024

    In ncurses 6.1, there is a NULL pointer dereference at function _nc_parse_entry in parse_entry.c that will lead to a denial of service attack. The product proceeds to the dereference code path even after a "dubious character `*' in name or alias field" detection.

    Published: 28 Oct 2018
    7.8
    High

    CVE-2018-19214

    Last Modified: 21 Nov 2024

    Netwide Assembler (NASM) 2.14rc15 has a heap-based buffer over-read in expand_mmac_params in asm/preproc.c for insufficient input.

    Published: 28 Oct 2018
    4.8
    Medium

    CVE-2018-18722

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.

    Published: 28 Oct 2018
    7.5
    High

    CVE-2018-18727

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnerability in the router's web server -- httpd. While processing the 'deviceList' parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

    Published: 28 Oct 2018
    9.8
    Critical

    CVE-2018-18729

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a heap-based buffer overflow vulnerability in the router's web server -- httpd. While processing the 'mac' parameter for a post request, the value is directly used in a strcpy to a variable placed on the heap, which can leak sensitive information or even hijack program control flow.

    Published: 28 Oct 2018
    6.5
    Medium

    CVE-2018-19208

    Last Modified: 21 Nov 2024

    In libwpd 0.10.2, there is a NULL pointer dereference in the function WP6ContentListener::defineTable in WP6ContentListener.cpp that will lead to a denial of service attack. This is related to WPXTable.h.

    Published: 28 Oct 2018
    5.5
    Medium

    CVE-2018-18710

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.19. An information leak in cdrom_ioctl_select_disc in drivers/cdrom/cdrom.c could be used by local attackers to read kernel memory because a cast from unsigned long to int interferes with bounds checking. This is similar to CVE-2018-10940 and CVE-2018-16658.

    Published: 27 Oct 2018
    8.8
    High

    CVE-2018-18711

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.

    Published: 27 Oct 2018
    8.8
    High

    CVE-2018-18712

    Last Modified: 5 May 2025

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.

    Published: 27 Oct 2018
    7.5
    High

    CVE-2018-18713

    Last Modified: 21 Nov 2024

    The function down_sql_action() in /admin/model/database.class.php in PHPYun 4.6 allows remote attackers to read arbitrary files via directory traversal in an m=database&c=down_sql&name=../ URI.

    Published: 27 Oct 2018
    7.5
    High

    CVE-2018-18708

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromAddressNat" for a post request, the value is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

    Published: 27 Oct 2018
    7.5
    High

    CVE-2018-18706

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "page" parameter of the function "fromDhcpListClient" for a request, it is directly used in a sprintf to a local variable placed on the stack, which overrides the return address of the function.

    Published: 27 Oct 2018
    7.5
    High

    CVE-2018-18707

    Last Modified: 21 Nov 2024

    An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. It is a buffer overflow vulnerability in the router's web server -- httpd. When processing the "ssid" parameter for a post request, the value is directly used in a strcpy to a local variable placed on the stack, which overrides the return address of the function.

    Published: 27 Oct 2018