CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-18552

    Last Modified: 21 Nov 2024

    ServersCheck Monitoring Software through 14.3.3 allows local users to cause a denial of service (menu functionality loss) by creating an LNK file that points to a second LNK file, if this second LNK file is associated with a Start menu. Ultimately, this behavior comes from a Directory Traversal bug (via the sensor_details.html id parameter) that allows creating empty files in arbitrary directories.

    Published: 24 Oct 2018
    5.9
    Medium

    CVE-2018-18567

    Last Modified: 21 Nov 2024

    AudioCodes 440HD and 450HD devices 3.1.2.89 and earlier allows man-in-the-middle attackers to obtain sensitive credential information by leveraging failure to validate X.509 certificates when used with an on-premise installation with Skype for Business.

    Published: 24 Oct 2018
    8.8
    High

    CVE-2018-9281

    Last Modified: 21 Nov 2024

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site Scripting vulnerabilities. This flaw could be triggered by driving an administrator logged into the Eaton application to a specially crafted web page. This attack could be done silently.

    Published: 24 Oct 2018
    9.8
    Critical

    CVE-2018-18476

    Last Modified: 21 Nov 2024

    mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-18547

    Last Modified: 21 Nov 2024

    Vesta Control Panel through 0.9.8-22 has XSS via the edit/web/ domain parameter, the list/backup/ backup parameter, the list/rrd/ period parameter, the list/directory/ dir_a parameter, or the filename to the list/directory/ URI.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-18548

    Last Modified: 21 Nov 2024

    ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-18635

    Last Modified: 21 Nov 2024

    www/guis/admin/application/controllers/UserController.php in the administration login interface in MailCleaner CE 2018.08 and 2018.09 allows XSS via the admin/login/user/message/ PATH_INFO.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-18636

    Last Modified: 21 Nov 2024

    XSS exists in cgi-bin/webcm on D-link DSL-2640T routers via the var:RelaodHref or var:conid parameter.

    Published: 24 Oct 2018
    4.9
    Medium

    CVE-2018-9279

    Last Modified: 21 Nov 2024

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage.

    Published: 24 Oct 2018
    4.9
    Medium

    CVE-2018-9280

    Last Modified: 21 Nov 2024

    An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-12650

    Last Modified: 2 Mar 2026

    Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'.

    Published: 24 Oct 2018
    4.8
    Medium

    CVE-2018-18517

    Last Modified: 21 Nov 2024

    Citrix NetScaler Gateway 10.5.x before 10.5.69.003, 11.1.x before 11.1.59.004, 12.0.x before 12.0.58.7, and 12.1.x before 12.1.49.1 has XSS.

    Published: 24 Oct 2018
    7.8
    High

    CVE-2018-14812

    Last Modified: 21 Nov 2024

    An uncontrolled search path element (DLL Hijacking) vulnerability has been identified in Fuji Electric Energy Savings Estimator versions V.1.0.2.0 and prior. Exploitation of this vulnerability could give an attacker access to the system with the same level of privilege as the application that utilizes the malicious DLL.

    Published: 24 Oct 2018
    7.8
    High

    CVE-2018-18013

    Last Modified: 21 Nov 2024

    * Xen Mobile through 10.8.0 includes a service listening on port 5001 within its firewall that accepts unauthenticated input. If this service is supplied with raw serialised Java objects, it deserialises them back into Java objects in memory, giving rise to a remote code execution vulnerability. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.

    Published: 24 Oct 2018
    4.8
    Medium

    CVE-2018-18014

    Last Modified: 21 Nov 2024

    * Lack of authentication in Citrix Xen Mobile through 10.8 allows low-privileged local users to execute system commands as root by making requests to private services listening on ports 8000, 30000 and 30001. NOTE: the vendor disputes that this is a vulnerability, stating it is "already mitigated by the internal firewall that limits access to configuration services to localhost.

    Published: 24 Oct 2018
    9.8
    Critical

    CVE-2018-11792

    Last Modified: 21 Nov 2024

    In Apache Impala before 3.0.1, ALTER TABLE/VIEW RENAME required ALTER on the old table. This may pose a potential security risk, such as having ALTER on a table and ALL on a particular database allows a user to move the table to a database with ALL, which will automatically grant that user with ALL privilege on that table due to the privilege inherited from the database.

    Published: 24 Oct 2018
    6.5
    Medium

    CVE-2018-11785

    Last Modified: 21 Nov 2024

    Missing authorization check in Apache Impala before 3.0.1 allows a Kerberos-authenticated but unauthorized user to inject random data into a running query, leading to wrong results for a query.

    Published: 24 Oct 2018
    7.8
    High

    CVE-2018-15442

    Last Modified: 26 Nov 2024

    A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools.

    Published: 24 Oct 2018
    8.1
    High

    CVE-2018-17935

    Last Modified: 21 Nov 2024

    All versions of Telecrane F25 Series Radio Controls before 00.0A use fixed codes that are reproducible by sniffing and re-transmission. This can lead to unauthorized replay of a command, spoofing of an arbitrary message, or keeping the controlled load in a permanent "stop" state.

    Published: 24 Oct 2018
    5.4
    Medium

    CVE-2018-1541

    Last Modified: 21 Nov 2024

    IBM WebSphere Commerce Enterprise V7, V8, and V9 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142596.

    Published: 24 Oct 2018
    8.8
    High

    CVE-2018-18883

    Last Modified: 21 Nov 2024

    An issue was discovered in Xen 4.9.x through 4.11.x, on Intel x86 platforms, allowing x86 HVM and PVH guests to cause a host OS denial of service (NULL pointer dereference) or possibly have unspecified other impact because nested VT-x is not properly restricted.

    Published: 24 Oct 2018
    6.5
    Medium

    CVE-2018-1000873

    Last Modified: 21 Nov 2024

    Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.

    Published: 24 Oct 2018
    7.5
    High

    CVE-2018-11804

    Last Modified: 21 Nov 2024

    Spark's Apache Maven-based build includes a convenience script, 'build/mvn', that downloads and runs a zinc server to speed up compilation. It has been included in release branches since 1.3.x, up to and including master. This server will accept connections from external hosts by default. A specially-crafted request to the zinc server could cause it to reveal information in files readable to the developer account running the build. Note that this issue does not affect end users of Spark, only developers building Spark from source code.

    Published: 24 Oct 2018
    9.8
    Critical

    CVE-2018-19486

    Last Modified: 21 Nov 2024

    Git before 2.19.2 on Linux and UNIX executes commands from the current working directory (as if '.' were at the end of $PATH) in certain cases involving the run_command() API and run-command.c, because there was a dangerous change from execvp to execv during 2017.

    Published: 24 Oct 2018
    6.1
    Medium

    CVE-2018-12901

    Last Modified: 21 Nov 2024

    A vulnerability in the conferencing component of Mitel ST 14.2, versions GA29 (19.49.9400.0) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack due to insufficient validation for the signin.php page. A successful exploit could allow an attacker to execute arbitrary scripts.

    Published: 23 Oct 2018
    6.1
    Medium

    CVE-2018-16226

    Last Modified: 21 Nov 2024

    A vulnerability in the web admin component of Mitel MiVoice Office 400, versions R5.0 HF3 (v8839a1) and earlier, could allow an unauthenticated attacker to conduct a reflected cross-site scripting (XSS) attack, due to insufficient validation for the start.asp page. A successful exploit could allow the attacker to execute arbitrary scripts to access sensitive browser-based information.

    Published: 23 Oct 2018
    6.1
    Medium

    CVE-2018-16235

    Last Modified: 21 Nov 2024

    Telligent Community 6.x, 7.x, 8.x, 9.x before 9.2.10.11796, 10.1.x before 10.1.10.11792, and 10.2.x before 10.2.3.4725 has XSS via the Feed RSS widget.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-17445

    Last Modified: 21 Nov 2024

    A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-17446

    Last Modified: 21 Nov 2024

    A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-17447

    Last Modified: 21 Nov 2024

    An Information Exposure Through Log Files issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-17448

    Last Modified: 21 Nov 2024

    An Incorrect Access Control issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

    Published: 23 Oct 2018
    6.1
    Medium

    CVE-2018-18437

    Last Modified: 21 Nov 2024

    In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-18467

    Last Modified: 21 Nov 2024

    An issue was discovered in Daniel Gultsch Conversations 2.3.4. It is possible to spoof a custom message to an existing opened conversation by sending an intent.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-18475

    Last Modified: 21 Nov 2024

    Zoho ManageEngine OpManager before 12.3 build 123214 allows Unrestricted Arbitrary File Upload.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-7429

    Last Modified: 21 Nov 2024

    Splunkd in Splunk Enterprise 6.2.x before 6.2.14 6.3.x before 6.3.11, and 6.4.x before 6.4.8; and Splunk Light before 6.5.0 allow remote attackers to cause a denial of service via a malformed HTTP request.

    Published: 23 Oct 2018
    6.5
    Medium

    CVE-2018-7431

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in the Splunk Django App in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.6, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote authenticated users to read arbitrary files via unspecified vectors.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-15497

    Last Modified: 21 Nov 2024

    The Mitel MiVoice 5330e VoIP device is affected by memory corruption flaws in the SIP/SDP packet handling functionality. An attacker can exploit this issue remotely, by sending a particular pattern of SIP/SDP packets, to cause a denial of service state in the affected devices and probably remote code execution.

    Published: 23 Oct 2018
    8.8
    High

    CVE-2018-17873

    Last Modified: 21 Nov 2024

    An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-17877

    Last Modified: 21 Nov 2024

    A lottery smart contract implementation for Greedy 599, an Ethereum gambling game, generates a random value that is predictable via an external contract call. The developer used the extcodesize() function to prevent a malicious contract from being called, but the attacker can bypass it by writing the core code in the constructor of their exploit code. Therefore, it allows attackers to always win and get rewards.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-17968

    Last Modified: 21 Nov 2024

    A gambling smart contract implementation for RuletkaIo, an Ethereum gambling game, generates a random value that is predictable by an external contract call. The developer wrote a random() function that uses a block timestamp and block hash from the Ethereum blockchain. This can be predicted by writing the same random function code in an exploit contract to determine the deadSeat value.

    Published: 23 Oct 2018
    6.1
    Medium

    CVE-2018-7427

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Splunk Web in Splunk Enterprise 6.0.x before 6.0.14, 6.1.x before 6.1.13, 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-7432

    Last Modified: 21 Nov 2024

    Splunk Enterprise 6.2.x before 6.2.14, 6.3.x before 6.3.10, 6.4.x before 6.4.7, and 6.5.x before 6.5.3; and Splunk Light before 6.6.0 allow remote attackers to cause a denial of service via a crafted HTTP request.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-17444

    Last Modified: 21 Nov 2024

    A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-14806

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.1 and earlier has a path traversal vulnerability which may allow an attacker to execute arbitrary code.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-14816

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.1 and earlier has several stack-based buffer overflow vulnerabilities that have been identified, which may allow an attacker to execute arbitrary code.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-14820

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.1 and earlier has a .dll component that is susceptible to external control of file name or path vulnerability, which may allow an arbitrary file deletion when processing.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2018-18628

    Last Modified: 21 Nov 2024

    An issue was discovered in Pippo 1.11.0. The function SerializationSessionDataTranscoder.decode() calls ObjectInputStream.readObject() to deserialize a SessionData object without checking the object types. An attacker can create a malicious object, base64 encode it, and place it in the PIPPO_SESSION field of a cookie. Sending this cookie may lead to remote code execution.

    Published: 23 Oct 2018
    9.8
    Critical

    CVE-2017-18349

    Last Modified: 21 Nov 2024

    parseObject in Fastjson before 1.2.25, as used in FastjsonEngine in Pippo 1.11.0 and other products, allows remote attackers to execute arbitrary code via a crafted JSON request, as demonstrated by a crafted rmi:// URI in the dataSourceName field of HTTP POST data to the Pippo /json URI, which is mishandled in AjaxApplication.java.

    Published: 23 Oct 2018
    7.8
    High

    CVE-2018-14828

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.1 and earlier has an improper privilege management vulnerability, which may allow an attacker to access those files and perform actions at a system administrator level.

    Published: 23 Oct 2018
    7.5
    High

    CVE-2018-18626

    Last Modified: 21 Nov 2024

    An issue was discovered in PHPYun V4.6. There is a vulnerability that can delete any file or directory via the "admin/index.php?m=database&c=del" sql parameter because del_action() in admin/model/database.class.php mishandles this parameter.

    Published: 23 Oct 2018