CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-8495

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when Windows Shell improperly handles URIs, aka "Windows Shell Remote Code Execution Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers.

    Published: 10 Oct 2018
    8.8
    High

    CVE-2018-8502

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Excel software when the software fails to properly handle objects in Protected View, aka "Microsoft Excel Remote Code Execution Vulnerability." This affects Office 365 ProPlus, Microsoft Office, Microsoft Excel.

    Published: 10 Oct 2018
    8.8
    High

    CVE-2018-8504

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft Word software when the software fails to properly handle objects in Protected View, aka "Microsoft Word Remote Code Execution Vulnerability." This affects Microsoft SharePoint Server, Office 365 ProPlus, Microsoft Office, Microsoft Word.

    Published: 10 Oct 2018
    7.5
    High

    CVE-2018-8511

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8503, CVE-2018-8505, CVE-2018-8510, CVE-2018-8513.

    Published: 10 Oct 2018
    7.5
    High

    CVE-2018-18206

    Last Modified: 21 Nov 2024

    In the client in Bytom before 1.0.6, checkTopicRegister in p2p/discover/net.go does not prevent negative idx values, leading to a crash.

    Published: 10 Oct 2018
    9.8
    Critical

    CVE-2018-18202

    Last Modified: 21 Nov 2024

    The QLogic 4Gb Fibre Channel 5.5.2.6.0 and 4/8Gb SAN 7.10.1.20.0 modules for IBM BladeCenter have an undocumented support account with a support password, an undocumented diags account with a diags password, and an undocumented prom account with a prom password.

    Published: 10 Oct 2018
    6.5
    Medium

    CVE-2018-1000406

    Last Modified: 21 Nov 2024

    A path traversal vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/FileParameterValue.java that allows attackers with Job/Configure permission to define a file parameter with a file name outside the intended directory, resulting in an arbitrary file write on the Jenkins master when scheduling a build.

    Published: 10 Oct 2018
    6.1
    Medium

    CVE-2018-1000407

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/model/Api.java that allows attackers to specify URLs to Jenkins that result in rendering arbitrary attacker-controlled HTML by Jenkins.

    Published: 10 Oct 2018
    7.8
    High

    CVE-2018-1000410

    Last Modified: 21 Nov 2024

    An information exposure vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier, and the Stapler framework used by these releases, in core/src/main/java/org/kohsuke/stapler/RequestImpl.java, core/src/main/java/hudson/model/Descriptor.java that allows attackers with Overall/Administer permission or access to the local file system to obtain credentials entered by users if the form submission could not be successfully processed.

    Published: 10 Oct 2018
    5.4
    Medium

    CVE-2018-14664

    Last Modified: 21 Nov 2024

    A flaw was found in foreman from versions 1.18. A stored cross-site scripting vulnerability exists due to an improperly escaped HTML code in the breadcrumbs bar. This allows a user with permissions to edit which attribute is used in the breadcrumbs bar to store code that will be executed on the client side.

    Published: 10 Oct 2018
    7.5
    High

    CVE-2018-18225

    Last Modified: 21 Nov 2024

    In Wireshark 2.6.0 to 2.6.3, the CoAP dissector could crash. This was addressed in epan/dissectors/packet-coap.c by ensuring that the piv length is correctly computed.

    Published: 10 Oct 2018
    7.5
    High

    CVE-2018-18226

    Last Modified: 21 Nov 2024

    In Wireshark 2.6.0 to 2.6.3, the Steam IHS Discovery dissector could consume system memory. This was addressed in epan/dissectors/packet-steam-ihs-discovery.c by changing the memory-management approach.

    Published: 10 Oct 2018
    7.5
    High

    CVE-2018-18227

    Last Modified: 21 Nov 2024

    In Wireshark 2.6.0 to 2.6.3 and 2.4.0 to 2.4.9, the MS-WSP protocol dissector could crash. This was addressed in epan/dissectors/packet-mswsp.c by properly handling NULL return values.

    Published: 10 Oct 2018
    5.5
    Medium

    CVE-2019-7150

    Last Modified: 21 Nov 2024

    An issue was discovered in elfutils 0.175. A segmentation fault can occur in the function elf64_xlatetom in libelf/elf32_xlatetom.c, due to dwfl_segment_report_module not checking whether the dyn data read from a core file is truncated. A crafted input can cause a program crash, leading to denial-of-service, as demonstrated by eu-stack.

    Published: 10 Oct 2018
    6.5
    Medium

    CVE-2018-1000997

    Last Modified: 21 Nov 2024

    A path traversal vulnerability exists in the Stapler web framework used by Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/org/kohsuke/stapler/Facet.java, groovy/src/main/java/org/kohsuke/stapler/jelly/groovy/GroovyFacet.java, jelly/src/main/java/org/kohsuke/stapler/jelly/JellyFacet.java, jruby/src/main/java/org/kohsuke/stapler/jelly/jruby/JRubyFacet.java, jsp/src/main/java/org/kohsuke/stapler/jsp/JSPFacet.java that allows attackers to render routable objects using any view in Jenkins, exposing internal information about those objects not intended to be viewed, such as their toString() representation.

    Published: 10 Oct 2018
    5.3
    Medium

    CVE-2018-16737

    Last Modified: 21 Nov 2024

    tinc before 1.0.30 has a broken authentication protocol, without even a partial mitigation.

    Published: 10 Oct 2018
    8.6
    High

    CVE-2018-17961

    Last Modified: 21 Nov 2024

    Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

    Published: 10 Oct 2018
    6.5
    Medium

    CVE-2018-1000408

    Last Modified: 21 Nov 2024

    A denial of service vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that allows attackers without Overall/Read permission to access a specific URL on instances using the built-in Jenkins user database security realm that results in the creation of an ephemeral user record in memory.

    Published: 10 Oct 2018
    5.4
    Medium

    CVE-2018-1000409

    Last Modified: 21 Nov 2024

    A session fixation vulnerability exists in Jenkins 2.145 and earlier, LTS 2.138.1 and earlier in core/src/main/java/hudson/security/HudsonPrivateSecurityRealm.java that prevented Jenkins from invalidating the existing session and creating a new one when a user signed up for a new user account.

    Published: 10 Oct 2018
    3.7
    Low

    CVE-2018-16738

    Last Modified: 21 Nov 2024

    tinc 1.0.30 through 1.0.34 has a broken authentication protocol, although there is a partial mitigation. This is fixed in 1.1.

    Published: 10 Oct 2018
    5.9
    Medium

    CVE-2018-16758

    Last Modified: 21 Nov 2024

    Missing message authentication in the meta-protocol in Tinc VPN version 1.0.34 and earlier allows a man-in-the-middle attack to disable the encryption of VPN packets.

    Published: 10 Oct 2018
    5.5
    Medium

    CVE-2018-18310

    Last Modified: 21 Nov 2024

    An invalid memory address dereference was discovered in dwfl_segment_report_module.c in libdwfl in elfutils through v0.174. The vulnerability allows attackers to cause a denial of service (application crash) with a crafted ELF file, as demonstrated by consider_notes.

    Published: 10 Oct 2018
    8.8
    High

    CVE-2018-18201

    Last Modified: 21 Nov 2024

    qibosoft V7.0 allows CSRF via admin/index.php?lfj=member&action=addmember to add a user account.

    Published: 9 Oct 2018
    6.1
    Medium

    CVE-2018-18199

    Last Modified: 21 Nov 2024

    Mediamanager in REDAXO before 5.6.4 has XSS.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-7631

    Last Modified: 21 Nov 2024

    Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to execute code remotely via a specially crafted GET request without a leading "/" and without authentication.

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-7632

    Last Modified: 21 Nov 2024

    Buffer Overflow in httpd in EpiCentro E_7.3.2+ allows attackers to cause a denial of service attack remotely via a specially crafted GET request with a leading "/" in the URL.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-7633

    Last Modified: 21 Nov 2024

    Code injection in the /ui/login form Language parameter in Epicentro E_7.3.2+ allows attackers to execute JavaScript code by making a user issue a manipulated POST request.

    Published: 9 Oct 2018
    6.1
    Medium

    CVE-2018-18198

    Last Modified: 21 Nov 2024

    The $opener_input_field variable in addons/mediapool/pages/index.php in REDAXO 5.6.3 is not effectively filtered and is output directly to the page. The attacker can insert XSS payloads via an index.php?page=mediapool/media&opener_input_field=[XSS] request.

    Published: 9 Oct 2018
    6.1
    Medium

    CVE-2018-17866

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in includes/core/um-actions-login.php in the "Ultimate Member - User Profile & Membership" plugin before 2.0.28 for WordPress allow remote attackers to inject arbitrary web script or HTML via the "Primary button Text" or "Second button text" field.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-18200

    Last Modified: 21 Nov 2024

    There is a SQL injection in Benutzerverwaltung in REDAXO before 5.6.4.

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-11796

    Last Modified: 21 Nov 2024

    In Apache Tika 1.19 (CVE-2018-11761), we added an entity expansion limit for XML parsing. However, Tika reuses SAXParsers and calls reset() after each parse, which, for Xerces2 parsers, as per the documentation, removes the user-specified SecurityManager and thus removes entity expansion limits after the first parse. Apache Tika versions from 0.1 to 1.19 are therefore still vulnerable to entity expansions which can lead to a denial of service attack. Users should upgrade to 1.19.1 or later.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-10614

    Last Modified: 21 Nov 2024

    An XXE vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project XML files.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-17855

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.8.13. If an attacker gets access to the mail account of an user who can approve admin verifications in the registration process, he can activate himself.

    Published: 9 Oct 2018
    7.2
    High

    CVE-2018-17856

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.8.13. com_joomlaupdate allows the execution of arbitrary code. The default ACL config enabled the ability of Administrator-level users to access com_joomlaupdate and trigger code execution.

    Published: 9 Oct 2018
    4.3
    Medium

    CVE-2018-17859

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.8.13. Inadequate checks in com_contact could allow mail submission in disabled forms.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-10610

    Last Modified: 21 Nov 2024

    An out-of-bounds vulnerability in LeviStudioU, Versions 1.8.29 and 1.8.44 can be exploited when the application processes specially crafted project files.

    Published: 9 Oct 2018
    4.3
    Medium

    CVE-2018-17857

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.8.13. Inadequate checks on the tags search fields can lead to an access level violation.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-17858

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! before 3.8.13. com_installer actions do not have sufficient CSRF hardening in the backend.

    Published: 9 Oct 2018
    6.5
    Medium

    CVE-2018-18192

    Last Modified: 21 Nov 2024

    An issue was discovered in libgig 4.1.0. There is a NULL pointer dereference in the function DLS::File::GetFirstSample() in DLS.cpp.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-18196

    Last Modified: 21 Nov 2024

    An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in RIFF::List::GetListTypeString in RIFF.cpp.

    Published: 9 Oct 2018
    6.5
    Medium

    CVE-2018-6977

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7, 6.5, 6.0), Workstation (15.x and 14.x) and Fusion (11.x and 10.x) contain a denial-of-service vulnerability due to an infinite loop in a 3D-rendering shader. Successfully exploiting this issue may allow an attacker with normal user privileges in the guest to make the VM unresponsive, and in some cases, possibly result other VMs on the host or the host itself becoming unresponsive.

    Published: 9 Oct 2018
    5.4
    Medium

    CVE-2018-18087

    Last Modified: 21 Nov 2024

    The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor. The vulnerability is triggered by visiting /portfolio/${project_title}.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-18086

    Last Modified: 21 Nov 2024

    EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.

    Published: 9 Oct 2018
    5.5
    Medium

    CVE-2018-18190

    Last Modified: 21 Nov 2024

    An issue was discovered in GoPro gpmf-parser before 1.2.1. There is a divide-by-zero error in GPMF_ScaledData in GPMF_parser.c.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-18193

    Last Modified: 21 Nov 2024

    An issue was discovered in libgig 4.1.0. There is operator new[] failure (due to a big pWavePoolTable heap request) in DLS::File::File in DLS.cpp.

    Published: 9 Oct 2018
    6.5
    Medium

    CVE-2018-18195

    Last Modified: 21 Nov 2024

    An issue was discovered in libgig 4.1.0. There is an FPE (divide-by-zero error) in DLS::Sample::Sample in DLS.cpp.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-18197

    Last Modified: 21 Nov 2024

    An issue was discovered in libgig 4.1.0. There is an operator new[] failure (due to a big pSampleLoops heap request) in DLS::Sampler::Sampler in DLS.cpp.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-18191

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in /admin.php?c=member&m=edit&uid=1 in dayrui FineCms 5.4 allows remote attackers to change the administrator's password.

    Published: 9 Oct 2018
    8.8
    High

    CVE-2018-18194

    Last Modified: 21 Nov 2024

    An issue was discovered in libgig 4.1.0. There is a heap-based buffer over-read in DLS::Region::GetSample() in DLS.cpp.

    Published: 9 Oct 2018
    6.1
    Medium

    CVE-2018-18082

    Last Modified: 21 Nov 2024

    XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI.

    Published: 9 Oct 2018