CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-12392

    Last Modified: 25 Nov 2025

    When manipulating user events in nested loops while opening a document through script, it is possible to trigger a potentially exploitable crash due to poor event handling. This vulnerability affects Firefox < 63, Firefox ESR < 60.3, and Thunderbird < 60.3.

    Published: 23 Oct 2018
    8.8
    High

    CVE-2018-12389

    Last Modified: 25 Nov 2025

    Mozilla developers and community members reported memory safety bugs present in Firefox ESR 60.2. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox ESR < 60.3 and Thunderbird < 60.3.

    Published: 23 Oct 2018
    8.8
    High

    CVE-2018-18581

    Last Modified: 21 Nov 2024

    An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer over-read in internalPrintf in miniz/lupng.c.

    Published: 22 Oct 2018
    8.8
    High

    CVE-2018-18582

    Last Modified: 21 Nov 2024

    An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c during a write operation for data obtained from a palette.

    Published: 22 Oct 2018
    8.8
    High

    CVE-2018-18583

    Last Modified: 21 Nov 2024

    An issue has been found in LuPng through 2017-03-10. It is a heap-based buffer overflow in insertByte in miniz/lupng.c during a write operation for data obtained from a swap.

    Published: 22 Oct 2018
    6.1
    Medium

    CVE-2018-18578

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 SP2 allows XSS via the plus/qrcode.php type parameter.

    Published: 22 Oct 2018
    6.1
    Medium

    CVE-2018-18579

    Last Modified: 21 Nov 2024

    Reflected XSS exists in DedeCMS 5.7 SP2 via the /member/pm.php folder parameter.

    Published: 22 Oct 2018
    9.8
    Critical

    CVE-2018-13114

    Last Modified: 21 Nov 2024

    Missing authentication and improper input validation in KERUI Wifi Endoscope Camera (YPC99) allow an attacker to execute arbitrary commands (with a length limit of 19 characters) via the "ssid" value, as demonstrated by ssid:;ping 192.168.1.2 in the body of a SETSSID command.

    Published: 22 Oct 2018
    6.5
    Medium

    CVE-2018-13115

    Last Modified: 21 Nov 2024

    Lack of an authentication mechanism in KERUI Wifi Endoscope Camera (YPC99) allows an attacker to watch or block the camera stream. The RTSP server on port 7070 accepts the command STOP to stop streaming, and the command SETSSID to disconnect a user.

    Published: 22 Oct 2018
    6.1
    Medium

    CVE-2018-12246

    Last Modified: 21 Nov 2024

    Symantec Web Isolation (WI) 1.11 prior to 1.11.21 is susceptible to a reflected cross-site scripting (XSS) vulnerability. A remote attacker can target end users protected by WI with social engineering attacks using crafted URLs for legitimate web sites. A successful attack allows injecting malicious JavaScript code into the website's rendered copy running inside the end user's web browser. It does not allow injecting code into the real (isolated) copy of the website running on the WI Threat Isolation Engine.

    Published: 22 Oct 2018
    8.8
    High

    CVE-2018-15704

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP request to broadweb/system/opcImg.asp.

    Published: 22 Oct 2018
    6.1
    Medium

    CVE-2018-15703

    Last Modified: 21 Nov 2024

    Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by tricking a victim to supply malicious HTML or JavaScript code to WebAccess, which is then reflected back to the victim and executed by the web browser.

    Published: 22 Oct 2018
    8.8
    High

    CVE-2018-1850

    Last Modified: 21 Nov 2024

    IBM Security Access Manager Appliance 9.0.3.1, 9.0.4.0 and 9.0.5.0 could allow unauthorized administration operations when Advanced Access Control services are running. IBM X-Force ID: 150998.

    Published: 22 Oct 2018
    6.1
    Medium

    CVE-2018-18553

    Last Modified: 21 Nov 2024

    Leanote 2.6.1 has XSS via the Blog Basic Setting title field, which is mishandled during rendering of the "likes" page.

    Published: 22 Oct 2018
    9.8
    Critical

    CVE-2018-8788

    Last Modified: 21 Nov 2024

    FreeRDP prior to version 2.0.0-rc4 contains an Out-Of-Bounds Write of up to 4 bytes in function nsc_rle_decode() that results in a memory corruption and possibly even a remote code execution.

    Published: 22 Oct 2018
    7.5
    High

    CVE-2018-8789

    Last Modified: 21 Nov 2024

    FreeRDP prior to version 2.0.0-rc4 contains several Out-Of-Bounds Reads in the NTLM Authentication module that results in a Denial of Service (segfault).

    Published: 22 Oct 2018
    9.8
    Critical

    CVE-2018-8784

    Last Modified: 21 Nov 2024

    FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress_segment() that results in a memory corruption and probably even a remote code execution.

    Published: 22 Oct 2018
    5.5
    Medium

    CVE-2018-18954

    Last Modified: 21 Nov 2024

    The pnv_lpc_do_eccb function in hw/ppc/pnv_lpc.c in Qemu before 3.1 allows out-of-bounds write or read access to PowerNV memory.

    Published: 22 Oct 2018
    5.5
    Medium

    CVE-2018-18700

    Last Modified: 21 Nov 2024

    An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions d_name(), d_encoding(), and d_local_name() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.

    Published: 22 Oct 2018
    9.8
    Critical

    CVE-2018-8785

    Last Modified: 21 Nov 2024

    FreeRDP prior to version 2.0.0-rc4 contains a Heap-Based Buffer Overflow in function zgfx_decompress() that results in a memory corruption and probably even a remote code execution.

    Published: 22 Oct 2018
    9.8
    Critical

    CVE-2018-8786

    Last Modified: 21 Nov 2024

    FreeRDP prior to version 2.0.0-rc4 contains an Integer Truncation that leads to a Heap-Based Buffer Overflow in function update_read_bitmap_update() and results in a memory corruption and probably even a remote code execution.

    Published: 22 Oct 2018
    9.8
    Critical

    CVE-2018-8787

    Last Modified: 21 Nov 2024

    FreeRDP prior to version 2.0.0-rc4 contains an Integer Overflow that leads to a Heap-Based Buffer Overflow in function gdi_Bitmap_Decompress() and results in a memory corruption and probably even a remote code execution.

    Published: 22 Oct 2018
    8.8
    High

    CVE-2018-18550

    Last Modified: 21 Nov 2024

    ServersCheck Monitoring Software before 14.3.4 allows SQL Injection by an authenticated user.

    Published: 21 Oct 2018
    6.1
    Medium

    CVE-2018-18545

    Last Modified: 21 Nov 2024

    Fiyo CMS 2.0.7 has XSS via the dapur\apps\app_user\edit_user.php name parameter.

    Published: 21 Oct 2018
    9.8
    Critical

    CVE-2018-18546

    Last Modified: 21 Nov 2024

    ThinkPHP 3.2.4 has SQL Injection via the order parameter because the Library/Think/Db/Driver.class.php parseOrder function mishandles the key variable.

    Published: 21 Oct 2018
    7.5
    High

    CVE-2018-1000850

    Last Modified: 21 Nov 2024

    Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.

    Published: 21 Oct 2018
    5.5
    Medium

    CVE-2018-18607

    Last Modified: 21 Nov 2024

    An issue was discovered in elf_link_input_bfd in elflink.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in elf_link_input_bfd when used for finding STT_TLS symbols without any TLS section. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.

    Published: 21 Oct 2018
    5.5
    Medium

    CVE-2018-18605

    Last Modified: 21 Nov 2024

    A heap-based buffer over-read issue was discovered in the function sec_merge_hash_lookup in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31, because _bfd_add_merge_section mishandles section merges when size is not a multiple of entsize. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.

    Published: 21 Oct 2018
    5.5
    Medium

    CVE-2018-18606

    Last Modified: 21 Nov 2024

    An issue was discovered in the merge_strings function in merge.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in _bfd_add_merge_section when attempting to merge sections with large alignments. A specially crafted ELF allows remote attackers to cause a denial of service, as demonstrated by ld.

    Published: 21 Oct 2018
    5.5
    Medium

    CVE-2018-18701

    Last Modified: 21 Nov 2024

    An issue was discovered in cp-demangle.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a stack consumption vulnerability resulting from infinite recursion in the functions next_is_type_qual() and cplus_demangle_type() in cp-demangle.c. Remote attackers could leverage this vulnerability to cause a denial-of-service via an ELF file, as demonstrated by nm.

    Published: 21 Oct 2018
    7.5
    High

    CVE-2018-18541

    Last Modified: 21 Nov 2024

    In Teeworlds before 0.6.5, connection packets could be forged. There was no challenge-response involved in the connection build up. A remote attacker could send connection packets from a spoofed IP address and occupy all server slots, or even use them for a reflection attack using map download packets.

    Published: 20 Oct 2018
    6.1
    Medium

    CVE-2018-18540

    Last Modified: 21 Nov 2024

    TeaKKi 2.7 allows XSS via a crafted onerror attribute for a picture's URL.

    Published: 20 Oct 2018
    9.8
    Critical

    CVE-2018-12666

    Last Modified: 21 Nov 2024

    SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B devices improperly identifies users only by the authentication level sent in the cookies, which allow remote attackers to bypass authentication and gain administrator access by setting the authLevel cookie to 255.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-12667

    Last Modified: 21 Nov 2024

    The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) is affected by an improper authentication vulnerability that allows requests to be made to back-end CGI scripts without a valid session. This vulnerability could be used to read and modify the configuration. The vulnerability affects all versions.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-12668

    Last Modified: 21 Nov 2024

    SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices have a Hard-coded Password.

    Published: 19 Oct 2018
    8.8
    High

    CVE-2018-12669

    Last Modified: 21 Nov 2024

    SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow remote authenticated users to reset arbitrary accounts via a request to web/cgi-bin/hi3510/param.cgi.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-12670

    Last Modified: 21 Nov 2024

    SV3C L-SERIES HD CAMERA V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B devices allow OS Command Injection.

    Published: 19 Oct 2018
    9.8
    Critical

    CVE-2018-12671

    Last Modified: 21 Nov 2024

    An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including all password sets set within the camera. This information can then be used to gain access to the web interface.

    Published: 19 Oct 2018
    5.4
    Medium

    CVE-2018-12672

    Last Modified: 21 Nov 2024

    The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B) does not perform proper validation on user-supplied input and is vulnerable to cross-site scripting attacks. If proper authorization was implemented, this vulnerability could be leveraged to perform actions on behalf of another user or the administrator.

    Published: 19 Oct 2018
    7.5
    High

    CVE-2018-12673

    Last Modified: 21 Nov 2024

    An attacker with remote access to the SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) web interface can disclose information about the camera including camera hardware, wireless network, and local area network information.

    Published: 19 Oct 2018
    6.1
    Medium

    CVE-2018-12675

    Last Modified: 21 Nov 2024

    The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) does not perform origin checks on URLs that the camera's web interface redirects a user to. This can be leveraged to send a user to an unexpected endpoint.

    Published: 19 Oct 2018
    7.8
    High

    CVE-2018-18026

    Last Modified: 21 Nov 2024

    IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

    Published: 19 Oct 2018
    8.1
    High

    CVE-2018-18224

    Last Modified: 21 Nov 2024

    A vulnerability exists in the file reading procedure in Open Design Alliance Drawings SDK 2019Update1 on non-Windows platforms in which attackers could perform read operations past the end, or before the beginning, of the intended buffer. This can allow attackers to obtain sensitive information from process memory or cause a crash.

    Published: 19 Oct 2018
    4.8
    Medium

    CVE-2018-18416

    Last Modified: 21 Nov 2024

    LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/update URI.

    Published: 19 Oct 2018
    5.4
    Medium

    CVE-2018-18417

    Last Modified: 21 Nov 2024

    In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

    Published: 19 Oct 2018
    5.4
    Medium

    CVE-2018-18419

    Last Modified: 21 Nov 2024

    Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.

    Published: 19 Oct 2018
    8.8
    High

    CVE-2018-18420

    Last Modified: 21 Nov 2024

    Cross-Site Request Forgery (CSRF) vulnerability was discovered in the 8.3 version of Zenario Content Management System via the admin/organizer.ajax.php?path=zenario__content%2Fpanels%2Fcontent URI.

    Published: 19 Oct 2018
    7.5
    High

    CVE-2018-18428

    Last Modified: 21 Nov 2024

    TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.

    Published: 19 Oct 2018
    5.7
    Medium

    CVE-2018-12674

    Last Modified: 21 Nov 2024

    The SV3C HD Camera (L-SERIES V2.3.4.2103-S50-NTD-B20170508B and V2.3.4.2103-S50-NTD-B20170823B) stores the username and password within the cookies of a session. If an attacker gained access to these session cookies, it would be possible to gain access to the username and password of the logged-in account.

    Published: 19 Oct 2018
    8.1
    High

    CVE-2018-18223

    Last Modified: 21 Nov 2024

    Open Design Alliance Drawings SDK 2019Update1 has a vulnerability during the reading of malformed files, allowing attackers to obtain sensitive information from process memory or cause a crash.

    Published: 19 Oct 2018