CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-15591

    Last Modified: 21 Nov 2024

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can bypass Application Whitelisting restrictions to execute arbitrary code by leveraging multiple unspecified attack vectors.

    Published: 15 Oct 2018
    7.8
    High

    CVE-2018-15593

    Last Modified: 21 Nov 2024

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can decrypt the encrypted datastore or relay server password by leveraging an unspecified attack vector.

    Published: 15 Oct 2018
    7.8
    High

    CVE-2018-15592

    Last Modified: 21 Nov 2024

    An issue was discovered in Ivanti Workspace Control before 10.3.10.0 and RES One Workspace. A local authenticated user can execute processes with elevated privileges via an unspecified attack vector.

    Published: 15 Oct 2018
    6.1
    Medium

    CVE-2018-18361

    Last Modified: 21 Nov 2024

    An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html allows XSS via the name parameter, as demonstrated by a value beginning with home_content and containing a crafted SRC attribute of an IMG element.

    Published: 15 Oct 2018
    7.7
    High

    CVE-2018-1744

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148423.

    Published: 15 Oct 2018
    7.1
    High

    CVE-2018-1747

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 2.5, 2.6, 2.7, and 3.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 148428.

    Published: 15 Oct 2018
    7.5
    High

    CVE-2018-18323

    Last Modified: 21 Nov 2024

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

    Published: 15 Oct 2018
    6.1
    Medium

    CVE-2018-18324

    Last Modified: 21 Nov 2024

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.

    Published: 15 Oct 2018
    9.8
    Critical

    CVE-2018-18322

    Last Modified: 21 Nov 2024

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.

    Published: 15 Oct 2018
    9.8
    Critical

    CVE-2018-18319

    Last Modified: 21 Nov 2024

    An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?function=command&class=remote&Cc='ls' URI. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution

    Published: 15 Oct 2018
    9.8
    Critical

    CVE-2018-18320

    Last Modified: 21 Nov 2024

    An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Merlin.PHP is designed only for use on a trusted intranet network, and intentionally allows remote code execution

    Published: 15 Oct 2018
    7.5
    High

    CVE-2018-18318

    Last Modified: 21 Nov 2024

    The /dev/block/mmcblk0rpmb driver kernel module on Qiku 360 Phone N6 Pro 1801-A01 devices allows attackers to cause a denial of service (NULL pointer dereference and device crash) via a crafted 0xc0d8b300 ioctl call.

    Published: 15 Oct 2018
    8.8
    High

    CVE-2018-18316

    Last Modified: 21 Nov 2024

    emlog v6.0.0 has CSRF via the admin/user.php?action=new URI.

    Published: 15 Oct 2018
    8.8
    High

    CVE-2018-18317

    Last Modified: 21 Nov 2024

    DESHANG DSCMS 1.1 has CSRF via the public/index.php/admin/admin/add.html URI.

    Published: 15 Oct 2018
    7.5
    High

    CVE-2018-18315

    Last Modified: 21 Nov 2024

    com/mossle/cdn/CdnController.java in lemon 1.9.0 allows attackers to upload arbitrary files because the copyMultipartFileToFile method in CdnUtils only checks for a ../ substring, and does not validate the file type and spaceName parameter.

    Published: 15 Oct 2018
    6.1
    Medium

    CVE-2018-18296

    Last Modified: 21 Nov 2024

    MetInfo 6.1.2 has XSS via the /admin/index.php bigclass parameter in an n=column&a=doadd action.

    Published: 15 Oct 2018
    6.1
    Medium

    CVE-2018-18260

    Last Modified: 21 Nov 2024

    In the 2.4 version of Camaleon CMS, Stored XSS has been discovered. The profile image in the User settings section can be run in the update / upload area via /admin/media/upload?actions=false. NOTE: the vendor reports that they are "unable to reproduce the reported issue on any version."

    Published: 15 Oct 2018
    5.3
    Medium

    CVE-2018-18287

    Last Modified: 21 Nov 2024

    On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page.

    Published: 14 Oct 2018
    4.8
    Medium

    CVE-2018-18290

    Last Modified: 21 Nov 2024

    An issue was discovered in nc-cms through 2017-03-10. index.php?action=edit_html&name=home_content allows XSS via the HTML Source Editor. NOTE: the vendor disputes this because the form requires administrator privileges, and entering JavaScript is supported functionality

    Published: 14 Oct 2018
    7.5
    High

    CVE-2018-18289

    Last Modified: 21 Nov 2024

    The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files.

    Published: 14 Oct 2018
    6.1
    Medium

    CVE-2018-18291

    Last Modified: 21 Nov 2024

    A cross site scripting (XSS) vulnerability on ASUS RT-AC58U 3.0.0.4.380_6516 devices allows remote attackers to inject arbitrary web script or HTML via Advanced_ASUSDDNS_Content.asp, Advanced_WSecurity_Content.asp, Advanced_Wireless_Content.asp, Logout.asp, Main_Login.asp, MobileQIS_Login.asp, QIS_wizard.htma, YandexDNS.asp, ajax_status.xml, apply.cgi, clients.asp, disk.asp, disk_utility.asp, or internet.asp.

    Published: 14 Oct 2018
    5.4
    Medium

    CVE-2018-1000816

    Last Modified: 21 Nov 2024

    Grafana version confirmed for 5.2.4 and 5.3.0 contains a Cross Site Scripting (XSS) vulnerability in Influxdb and Graphite query editor that can result in Running arbitrary js code in victims browser.. This attack appear to be exploitable via Authenticated user must click on the input field where the payload was previously inserted..

    Published: 14 Oct 2018
    8.8
    High

    CVE-2018-18557

    Last Modified: 21 Nov 2024

    LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode out-of-bounds write.

    Published: 14 Oct 2018
    5.5
    Medium

    CVE-2018-18309

    Last Modified: 21 Nov 2024

    An issue was discovered in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.31. An invalid memory address dereference was discovered in read_reloc in reloc.c. The vulnerability causes a segmentation fault and application crash, which leads to denial of service, as demonstrated by objdump, because of missing _bfd_clear_contents bounds checking.

    Published: 13 Oct 2018
    6.1
    Medium

    CVE-2018-18282

    Last Modified: 21 Nov 2024

    Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.

    Published: 12 Oct 2018
    6.1
    Medium

    CVE-2018-10141

    Last Modified: 21 Nov 2024

    GlobalProtect Portal Login page in Palo Alto Networks PAN-OS before 8.1.4 allows an unauthenticated attacker to inject arbitrary JavaScript or HTML.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-18274

    Last Modified: 21 Nov 2024

    A issue was found in pdfalto 0.2. There is a heap-based buffer overflow in the TextPage::addAttributsNode function in XmlAltoOutputDev.cc.

    Published: 12 Oct 2018
    6.6
    Medium

    CVE-2018-15755

    Last Modified: 21 Nov 2024

    Cloud Foundry CF Networking Release, versions 2.11.0 prior to 2.16.0, contain an internal api endpoint vulnerable to SQL injection between Diego cells and the policy server. A remote authenticated malicious user with mTLS certs can issue arbitrary SQL queries and gain access to the policy server.

    Published: 12 Oct 2018
    6.1
    Medium

    CVE-2018-16210

    Last Modified: 13 Jun 2025

    WAGO 750-88X and WAGO 750-89X Ethernet Controller devices, versions 01.09.18(13) and before, have XSS in the SNMP configuration via the webserv/cplcfg/snmp.ssi SNMP_DESC or SNMP_LOC_SNMP_CONT field.

    Published: 12 Oct 2018
    6.1
    Medium

    CVE-2018-18271

    Last Modified: 21 Nov 2024

    XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.

    Published: 12 Oct 2018
    6.1
    Medium

    CVE-2018-18270

    Last Modified: 21 Nov 2024

    XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12759

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12769

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12831

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12832

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12835

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12836

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12837

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12838

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a stack overflow vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12841

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a double free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12842

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an integer overflow vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12843

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12845

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12847

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12851

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12852

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12853

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a buffer errors vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12857

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12858

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a type confusion vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12859

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018