CVE Feed

    Dashboard / CVE

    5.5
    Medium

    CVE-2018-15925

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-15953

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-15968

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12880

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12834

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12839

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12846

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have a heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    6.5
    Medium

    CVE-2018-12856

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-12862

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12871

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-12874

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-15923

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-15926

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-15931

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-15937

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an untrusted pointer dereference vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    5.5
    Medium

    CVE-2018-15943

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-15944

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 12 Oct 2018
    9.8
    Critical

    CVE-2018-17890

    Last Modified: 21 Nov 2024

    NUUO CMS all versions 3.1 and prior, The application uses insecure and outdated software components for functionality, which could allow arbitrary code execution.

    Published: 12 Oct 2018
    8.8
    High

    CVE-2018-17892

    Last Modified: 21 Nov 2024

    NUUO CMS all versions 3.1 and prior, The application implements a method of user account control that causes standard account security features to not be utilized as intended, which could allow user account compromise and may allow for remote code execution.

    Published: 12 Oct 2018
    7.5
    High

    CVE-2018-17898

    Last Modified: 21 Nov 2024

    Yokogawa STARDOM Controllers FCJ,FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The controller application fails to prevent memory exhaustion by unauthorized requests. This could allow an attacker to cause the controller to become unstable.

    Published: 12 Oct 2018
    9.8
    Critical

    CVE-2018-17900

    Last Modified: 21 Nov 2024

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for remote access to controllers.

    Published: 12 Oct 2018
    9.8
    Critical

    CVE-2018-17888

    Last Modified: 21 Nov 2024

    NUUO CMS all versions 3.1 and prior, The application uses a session identification mechanism that could allow attackers to obtain the active session ID, which could allow arbitrary remote code execution.

    Published: 12 Oct 2018
    9.8
    Critical

    CVE-2018-17894

    Last Modified: 21 Nov 2024

    NUUO CMS all versions 3.1 and prior, The application creates default accounts that have hard-coded passwords, which could allow an attacker to gain privileged access.

    Published: 12 Oct 2018
    8.1
    High

    CVE-2018-17896

    Last Modified: 21 Nov 2024

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The affected controllers utilize hard-coded credentials which may allow an attacker gain unauthorized access to the maintenance functions and obtain or modify information. This attack can be executed only during maintenance work.

    Published: 12 Oct 2018
    5.3
    Medium

    CVE-2018-17902

    Last Modified: 21 Nov 2024

    Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to the remote management functions.

    Published: 12 Oct 2018
    7.5
    High

    CVE-2018-8890

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Management Console of BlackBerry UEM 12.8.0 and 12.8.1 could allow an attacker to take over a UEM user's session and perform administrative actions in the context of the user.

    Published: 12 Oct 2018
    7.5
    High

    CVE-2018-12469

    Last Modified: 21 Nov 2024

    Incorrect handling of an invalid value for an HTTP request parameter by Directory Server (aka Enterprise Server Administration web UI) in Micro Focus Enterprise Developer and Enterprise Server 2.3 Update 2 and earlier, 3.0 before Patch Update 12, and 4.0 before Patch Update 2 causes a null pointer dereference (CWE-476) and subsequent denial of service due to process termination.

    Published: 12 Oct 2018
    7.1
    High

    CVE-2018-1844

    Last Modified: 21 Nov 2024

    IBM FileNet Content Manager 5.2.1 and 5.5.0 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 150904.

    Published: 12 Oct 2018
    6.5
    Medium

    CVE-2018-1770

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, 8.5, and 9.0 could allow a remote attacker to traverse directories on the system. An attacker could send a specially-crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 148686.

    Published: 12 Oct 2018
    5.4
    Medium

    CVE-2018-1534

    Last Modified: 25 Mar 2025

    IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142432.

    Published: 12 Oct 2018
    5.4
    Medium

    CVE-2018-1533

    Last Modified: 25 Mar 2025

    IBM Rational Publishing Engine 6.0.5 and 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 142431.

    Published: 12 Oct 2018
    6.1
    Medium

    CVE-2018-1673

    Last Modified: 21 Nov 2024

    IBM WebSphere Portal 7.0, 8.0, 8.5, and 9.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145108.

    Published: 12 Oct 2018
    5.3
    Medium

    CVE-2018-1838

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 8.5 and 9.0 in IBM Cloud could allow a remote attacker to obtain sensitive information caused by improper handling of passwords. IBM X-Force ID: 150811.

    Published: 12 Oct 2018
    4.4
    Medium

    CVE-2017-1231

    Last Modified: 21 Nov 2024

    IBM BigFix Platform 9.5 - 9.5.9 stores user credentials in plain in clear text which can be read by a local user. IBM X-Force ID: 123910.

    Published: 12 Oct 2018
    8.6
    High

    CVE-2018-18284

    Last Modified: 21 Nov 2024

    Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving the 1Policy operator.

    Published: 12 Oct 2018
    7.8
    High

    CVE-2018-17927

    Last Modified: 21 Nov 2024

    In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple out-of-bounds write vulnerabilities may be exploited by processing specially crafted project files lacking user input validation, which may cause the system to write outside the intended buffer area and may allow remote code execution.

    Published: 11 Oct 2018
    7.8
    High

    CVE-2018-17929

    Last Modified: 21 Nov 2024

    In Delta Industrial Automation TPEditor, TPEditor Versions 1.90 and prior, multiple stack-based buffer overflow vulnerabilities may be exploited by processing specially crafted project files lacking user input validation before copying data from project files onto the stack and may allow an attacker to remotely execute arbitrary code.

    Published: 11 Oct 2018
    7.8
    High

    CVE-2018-12441

    Last Modified: 21 Nov 2024

    The CorsairService Service in Corsair Utility Engine is installed with insecure default permissions, which allows unprivileged local users to execute arbitrary commands via modification of the CorsairService BINARY_PATH_NAME, leading to complete control of the affected system. The issue exists due to the Windows "Everyone" group being granted SERVICE_ALL_ACCESS permissions to the CorsairService Service.

    Published: 11 Oct 2018
    7.5
    High

    CVE-2018-18257

    Last Modified: 21 Nov 2024

    An issue was discovered in BageCMS 3.1.3. An attacker can delete any files and folders on the web server via an index.php?r=admini/template/batch&command=deleteFile&fileName= or index.php?r=admini/template/batch&command=deleteFolder&folderName=../ directory traversal URI.

    Published: 11 Oct 2018
    9.8
    Critical

    CVE-2018-18258

    Last Modified: 21 Nov 2024

    An issue was discovered in BageCMS 3.1.3. The attacker can execute arbitrary PHP code on the web server and can read any file on the web server via an index.php?r=admini/template/updateTpl&filename= URI.

    Published: 11 Oct 2018
    7.5
    High

    CVE-2018-15766

    Last Modified: 21 Nov 2024

    On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially create insecure password on their device. This value is defined during the installation of the "Encryption Management Agent" or "EMAgent" application. There are no other known values modified.

    Published: 11 Oct 2018
    9.8
    Critical

    CVE-2018-9206

    Last Modified: 12 Aug 2026

    Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

    Published: 11 Oct 2018
    8.8
    High

    CVE-2018-18215

    Last Modified: 21 Nov 2024

    In youke365 v1.1.5, admin/user.html has a CSRF vulnerability that can add an user account.

    Published: 11 Oct 2018
    9.8
    Critical

    CVE-2018-18242

    Last Modified: 21 Nov 2024

    youke365 v1.1.5 has SQL injection via admin/login.html, as demonstrated by username=admin&pass=123456&code=9823&act=login&submit=%E7%99%BB+%E9%99%86.

    Published: 11 Oct 2018
    7.8
    High

    CVE-2018-12449

    Last Modified: 21 Nov 2024

    The Whale browser installer 0.4.3.0 and earlier versions allows DLL hijacking.

    Published: 11 Oct 2018
    6.5
    Medium

    CVE-2018-1708

    Last Modified: 21 Nov 2024

    IBM Spectrum Symphony 7.1.2 and 7.2.0.2 could allow an authenticated user to obtain sensitive user information such as passwords through the WebUI. IBM X-Force ID: 146343.

    Published: 11 Oct 2018
    5.9
    Medium

    CVE-2018-1724

    Last Modified: 21 Nov 2024

    IBM Spectrum LSF 9.1.1 9.1.2, 9.1.3, and 10.1 could allow a local user to change their job user at job submission time due to improper file permission settings. IBM X-Force ID: 147439.

    Published: 11 Oct 2018
    7.5
    High

    CVE-2018-1745

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 2.7 and 3.0 could allow an unauthenticated user to restart the SKLM server due to missing authentication. IBM X-Force ID: 148424.

    Published: 11 Oct 2018
    5.4
    Medium

    CVE-2018-1706

    Last Modified: 21 Nov 2024

    IBM Spectrum Symphony 7.2.0.2 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 146341.

    Published: 11 Oct 2018
    7.1
    High

    CVE-2018-1738

    Last Modified: 21 Nov 2024

    IBM Security Key Lifecycle Manager 2.6, 2.7, 3.0 could allow an authenticated user to obtain highly sensitive information or jeopardize system integrity due to improper authentication mechanisms. IBM X-Force ID: 147907.

    Published: 11 Oct 2018