CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-18084

    Last Modified: 21 Nov 2024

    An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-18083

    Last Modified: 21 Nov 2024

    An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-18075

    Last Modified: 21 Nov 2024

    WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.

    Published: 9 Oct 2018
    5.4
    Medium

    CVE-2018-18029

    Last Modified: 21 Nov 2024

    Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.

    Published: 9 Oct 2018
    9.8
    Critical

    CVE-2018-14081

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext.

    Published: 9 Oct 2018
    6.8
    Medium

    CVE-2018-15543

    Last Modified: 21 Nov 2024

    An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The FingerprintManager class for Biometric validation allows authentication bypass through the callback method from onAuthenticationFailed to onAuthenticationSucceeded with null, because the fingerprint API in conjunction with the Android keyGenerator class is not implemented. In other words, an attacker could authenticate with an arbitrary fingerprint. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-14080

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file.

    Published: 9 Oct 2018
    6.4
    Medium

    CVE-2018-15542

    Last Modified: 21 Nov 2024

    An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return value to true. In other words, an attacker could authenticate with an arbitrary passcode. NOTE: the vendor indicates that this is not an attack of interest within the context of their threat model, which excludes Android devices on which rooting has occurred

    Published: 9 Oct 2018
    4.6
    Medium

    CVE-2018-7928

    Last Modified: 21 Nov 2024

    There is a security vulnerability which could lead to Factory Reset Protection (FRP) bypass in the MyCloud APP with the versions before 8.1.2.303 installed on some Huawei smart phones. When re-configuring the mobile phone using the FRP function, an attacker can replace the old account with a new one through special steps by exploit this vulnerability. As a result, the FRP function is bypassed.

    Published: 9 Oct 2018
    3.5
    Low

    CVE-2018-12477

    Last Modified: 21 Nov 2024

    A Improper Neutralization of CRLF Sequences vulnerability in Open Build Service allows remote attackers to cause deletion of directories by tricking obs-service-refresh_patches to delete them. Affected releases are openSUSE Open Build Service: versions prior to d6244245dda5367767efc989446fe4b5e4609cce.

    Published: 9 Oct 2018
    4.8
    Medium

    CVE-2018-12478

    Last Modified: 21 Nov 2024

    A Improper Input Validation vulnerability in Open Build Service allows remote attackers to extract files from the system where the service runs. Affected releases are openSUSE Open Build Service: status of is unknown.

    Published: 9 Oct 2018
    6.5
    Medium

    CVE-2018-12479

    Last Modified: 21 Nov 2024

    A Improper Input Validation vulnerability in Open Build Service allows remote attackers to cause DoS by specifying crafted request IDs. Affected releases are openSUSE Open Build Service: versions prior to 01b015ca2a320afc4fae823465d1e72da8bd60df.

    Published: 9 Oct 2018
    5.4
    Medium

    CVE-2018-2466

    Last Modified: 21 Nov 2024

    In Impact and Lineage Analysis in SAP Data Services, version 4.2, the management console does not sufficiently validate user-controlled inputs, which results in Cross-Site Scripting (XSS) vulnerability.

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-2468

    Last Modified: 21 Nov 2024

    Under certain conditions the backup server in SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise be restricted.

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-2469

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Adaptive Server Enterprise (ASE), versions 15.7 and 16.0, allows an attacker to access information which would otherwise be restricted.

    Published: 9 Oct 2018
    6.1
    Medium

    CVE-2018-2470

    Last Modified: 21 Nov 2024

    In SAP NetWeaver Application Server for ABAP, from 7.0 to 7.02, 7.30, 7.31, 7.40 and from 7.50 to 7.53, applications do not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 9 Oct 2018
    5.3
    Medium

    CVE-2018-2467

    Last Modified: 21 Nov 2024

    In the Software Development Kit in SAP BusinessObjects BI Platform Servers, versions 4.1 and 4.2, using the specially crafted URL in a Web Browser such as Chrome the system returns an error with the path of the used application server.

    Published: 9 Oct 2018
    6.1
    Medium

    CVE-2018-2472

    Last Modified: 21 Nov 2024

    SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 (Web Intelligence DHTML client) does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability.

    Published: 9 Oct 2018
    6.5
    Medium

    CVE-2018-2474

    Last Modified: 21 Nov 2024

    SAP Fiori 1.0 for SAP ERP HCM (Approve Leave Request, version 2) application allows an attacker to trick an authenticated user to send unintended request to the web server. This vulnerability is due to insufficient CSRF protection.

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-2471

    Last Modified: 21 Nov 2024

    Under certain conditions SAP BusinessObjects Business Intelligence Platform 4.10 and 4.20 allows an attacker to access information which would otherwise be restricted.

    Published: 9 Oct 2018
    8.5
    High

    CVE-2018-2475

    Last Modified: 21 Nov 2024

    Following the Gardener architecture, the Kubernetes apiserver of a Gardener managed shoot cluster resides in the corresponding seed cluster. Due to missing network isolation a shoot's apiserver can access services/endpoints in the private network of its corresponding seed cluster. Combined with other minor Kubernetes security issues, the missing network isolation theoretically can lead to compromise other shoot or seed clusters in the "Gardener" context. The issue is rated high due to the high impact of a potential exploitation in "Gardener" context. This was fixed in Gardener release 0.12.4.

    Published: 9 Oct 2018
    5.4
    Medium

    CVE-2018-12474

    Last Modified: 21 Nov 2024

    Improper input validation in obs-service-tar_scm of Open Build Service allows remote attackers to cause access and extract information outside the current build or cause the creation of file in attacker controlled locations. Affected releases are openSUSE Open Build Service: versions prior to 51a17c553b6ae2598820b7a90fd0c11502a49106.

    Published: 9 Oct 2018
    7.5
    High

    CVE-2018-18071

    Last Modified: 21 Nov 2024

    An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be used to operate the Remote Parking Pilot, unlock the vehicle, or obtain sensitive information such as latitude, longitude, and direction of travel.

    Published: 9 Oct 2018
    5.9
    Medium

    CVE-2018-18070

    Last Modified: 21 Nov 2024

    An issue was discovered in Daimler Mercedes-Benz COMAND 17/13.0 50.12 on Mercedes-Benz C-Class 2018 vehicles. Defining or receiving a specific navigation route might cause the system to freeze and reboot after a few transmissions. When the system next starts, it tries to re-calculate the route, which will cause a boot loop. (Under certain circumstances, it is possible to quickly overwrite the malicious route to regain the stability of the system.)

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18092

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18099

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18100

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18102

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18103

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18104

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18121

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18122

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18123

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18124

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18125

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18126

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18127

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18128

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18129

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18130

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18131

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18132

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18133

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18134

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18135

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18136

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18137

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18140

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18141

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018
    Unknown

    CVE-2018-18142

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was in a CNA pool that was not assigned to any issues. Notes: none.

    Published: 9 Oct 2018