CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2018-14890

    Last Modified: 21 Nov 2024

    Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console.

    Published: 21 Sept 2018
    7.6
    High

    CVE-2018-12169

    Last Modified: 21 Nov 2024

    Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware authentication.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-17320

    Last Modified: 21 Nov 2024

    An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-17317

    Last Modified: 21 Nov 2024

    FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_set, io_in_ip, io_in_mask, io_in_gw, io_out_iface, io_out_set, io_out_mask, io_out_gw, iface, or domain parameter to /www/script/config_iface.php, or the newSSID, hostapd_secure, hostapd_wpa_passphrase, or supplicant_ssid parameter to /www/page_config.php.

    Published: 21 Sept 2018
    8.3
    High

    CVE-2018-15613

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could result in malicious content being returned to the user. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.

    Published: 21 Sept 2018
    8.3
    High

    CVE-2018-15612

    Last Modified: 21 Nov 2024

    A CSRF vulnerability in the Runtime Config component of Avaya Aura Orchestration Designer could allow an attacker to add, change, or remove administrative settings. Affected versions of Avaya Aura Orchestration Designer include all versions up to 7.2.1.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2013-4451

    Last Modified: 21 Nov 2024

    gitolite commit fa06a34 through 3.5.3 might allow attackers to have unspecified impact via vectors involving world-writable permissions when creating (1) ~/.gitolite.rc, (2) ~/.gitolite, or (3) ~/repositories/gitolite-admin.git on fresh installs.

    Published: 21 Sept 2018
    5.3
    Medium

    CVE-2018-16821

    Last Modified: 21 Nov 2024

    SeaCMS 6.64 allows arbitrary directory listing via upload/admin/admin_template.php?path=../templets/../../ requests.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-16822

    Last Modified: 21 Nov 2024

    SeaCMS 6.64 allows SQL Injection via the upload/admin/admin_video.php order parameter.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-16833

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central 10.0.271 has XSS via the "Features & Articles" search field to the /advsearch.do?SUBREQUEST=XMLHTTP URI.

    Published: 21 Sept 2018
    7.5
    High

    CVE-2018-17050

    Last Modified: 21 Nov 2024

    The mintToken function of a smart contract implementation for PolyAi (AI), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-17173

    Last Modified: 21 Nov 2024

    LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-17174

    Last Modified: 21 Nov 2024

    A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in a certain context) in a product using this library via malformed data.

    Published: 21 Sept 2018
    5.5
    Medium

    CVE-2013-7203

    Last Modified: 21 Nov 2024

    gitolite before commit fa06a34 might allow local users to read arbitrary files in repositories via vectors related to the user umask when running gitolite setup.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-17003

    Last Modified: 21 Nov 2024

    In LimeSurvey 3.14.7, HTML Injection and Stored XSS have been discovered in the appendix via the surveyls_title parameter to /index.php?r=admin/survey/sa/insert.

    Published: 21 Sept 2018
    7.5
    High

    CVE-2018-14730

    Last Modified: 21 Nov 2024

    An issue was discovered in Browserify-HMR. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:3123/ connection from any origin.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-16965

    Last Modified: 21 Nov 2024

    In Zoho ManageEngine SupportCenter Plus before 8.1 Build 8109, there is HTML Injection and Stored XSS via the /ServiceContractDef.do contractName parameter.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-17001

    Last Modified: 21 Nov 2024

    On the RICOH SP 4510SF printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-17141

    Last Modified: 21 Nov 2024

    HylaFAX 6.0.6 and HylaFAX+ 5.6.0 allow remote attackers to execute arbitrary code via a dial-in session that provides a FAX page with the JPEG bit enabled, which is mishandled in FaxModem::writeECMData() in the faxd/CopyQuality.c++ file.

    Published: 21 Sept 2018
    7.5
    High

    CVE-2018-12511

    Last Modified: 21 Nov 2024

    In the mintToken function of a smart contract implementation for Substratum (SUB), an Ethereum ERC20 token, the administrator can control mintedAmount, leverage an integer overflow, and modify a user account's balance arbitrarily.

    Published: 21 Sept 2018
    5.9
    Medium

    CVE-2018-13111

    Last Modified: 21 Nov 2024

    There exists a partial Denial of Service vulnerability in Wanscam HW0021 IP Cameras. An attacker could craft a malicious POST request to crash the ONVIF service on such a device.

    Published: 21 Sept 2018
    7.5
    High

    CVE-2018-14731

    Last Modified: 21 Nov 2024

    An issue was discovered in HMRServer.js in Parcel parcel-bundler. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1 connection (with a random TCP port number) from any origin. The random port number can be found by connecting to http://127.0.0.1 and reading the "new WebSocket" line in the source code.

    Published: 21 Sept 2018
    7.5
    High

    CVE-2018-14732

    Last Modified: 21 Nov 2024

    An issue was discovered in lib/Server.js in webpack-dev-server before 3.1.6. Attackers are able to steal developer's code because the origin of requests is not checked by the WebSocket server, which is used for HMR (Hot Module Replacement). Anyone can receive the HMR message sent by the WebSocket server via a ws://127.0.0.1:8080/ connection from any origin.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-17002

    Last Modified: 21 Nov 2024

    On the RICOH MP 2001 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-14688

    Last Modified: 21 Nov 2024

    An issue was discovered in Subsonic 6.1.1. The radio settings are affected by three stored cross-site scripting vulnerabilities in the name[x], streamUrl[x], homepageUrl[x] parameters (where x is an integer) to internetRadioSettings.view that could be used to steal session information of a victim.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-14689

    Last Modified: 21 Nov 2024

    An issue was discovered in Subsonic 6.1.1. The transcoding settings are affected by five stored cross-site scripting vulnerabilities in the name[x], sourceformats[x], targetFormat[x], step1[x], and step2[x] parameters (where x is an integer) to transcodingSettings.view that could be used to steal session information of a victim.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-14691

    Last Modified: 21 Nov 2024

    An issue was discovered in Subsonic 6.1.1. The music tags feature is affected by three stored cross-site scripting vulnerabilities in the c0-param2, c0-param3, and c0-param4 parameters to dwr/call/plaincall/tagService.setTags.dwr that could be used to steal session information of a victim.

    Published: 21 Sept 2018
    8.6
    High

    CVE-2018-16793

    Last Modified: 21 Nov 2024

    Rollup 18 for Microsoft Exchange Server 2010 SP3 and previous versions has an SSRF vulnerability via the username parameter in /owa/auth/logon.aspx in the OWA (Outlook Web Access) login page.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-9282

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Subsonic Media Server 6.1.1. The podcast subscription form is affected by a stored XSS vulnerability in the add parameter to podcastReceiverAdmin.view; no administrator access is required. By injecting a JavaScript payload, this flaw could be used to manipulate a user's session, or elevate privileges by targeting an administrative user.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-14690

    Last Modified: 21 Nov 2024

    An issue was discovered in Subsonic 6.1.1. The general settings are affected by two stored cross-site scripting vulnerabilities in the title and subtitle parameters to generalSettings.view that could be used to steal session information of a victim.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-16281

    Last Modified: 21 Nov 2024

    The DEISER "Profields - Project Custom Fields" app before 6.0.2 for Jira has Incorrect Access Control.

    Published: 21 Sept 2018
    4
    Medium

    CVE-2018-11352

    Last Modified: 21 Nov 2024

    The Wallabag application 2.2.3 to 2.3.2 is affected by one cross-site scripting (XSS) vulnerability that is stored within the configuration page. This vulnerability enables the execution of a JavaScript payload each time an administrator visits the configuration page. The vulnerability can be exploited with authentication and used to target administrators and steal their sessions.

    Published: 21 Sept 2018
    7.2
    High

    CVE-2018-16784

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 SP2 allows XML injection, and resultant remote code execution, via a "<file type='file' name='../" substring.

    Published: 21 Sept 2018
    8.2
    High

    CVE-2018-3906

    Last Modified: 21 Nov 2024

    An exploitable stack-based buffer overflow vulnerability exists in the retrieval of a database field in video-core's HTTP server of Samsung SmartThings Hub. The video-core process insecurely extracts the shard.videoHostURL field from its SQLite database, leading to a buffer overflow on the stack. An attacker can send an HTTP request to trigger this vulnerability.

    Published: 21 Sept 2018
    7.8
    High

    CVE-2018-3914

    Last Modified: 21 Nov 2024

    An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 2000 bytes. An attacker can send an arbitrarily long "sessionToken" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    8.2
    High

    CVE-2018-3915

    Last Modified: 21 Nov 2024

    An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-11241

    Last Modified: 21 Nov 2024

    An issue was discovered on SoftCase T-Router build 20112017 devices. A remote attacker can read and write to arbitrary files on the system as root, as demonstrated by code execution after writing to a crontab file. This is fixed in production builds as of Spring 2018.

    Published: 21 Sept 2018
    9.8
    Critical

    CVE-2018-11240

    Last Modified: 21 Nov 2024

    An issue was discovered on SoftCase T-Router build 20112017 devices. There are no restrictions on the 'exec command' feature of the T-Router protocol. If the command syntax is correct, there is code execution both on the other modem and on the main servers. This is fixed in production builds as of Spring 2018.

    Published: 21 Sept 2018
    8.8
    High

    CVE-2018-3894

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the /cameras/XXXX/clips handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy call overflows the destination buffer, which has a size of 52 bytes. An attacker can send an arbitrarily long "startTime" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    6.1
    Medium

    CVE-2018-16786

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 SP2 allows XSS via an onhashchange attribute in the msg parameter to /plus/feedback_ajax.php.

    Published: 21 Sept 2018
    6.7
    Medium

    CVE-2018-3913

    Last Modified: 21 Nov 2024

    An exploitable stack-based buffer overflow vulnerability exists in the retrieval of database fields in the video-core HTTP server of the Samsung SmartThings Hub STH-ETH-250 - Firmware version 0.20.17. The strcpy call overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily long "accessKey" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    9.9
    Critical

    CVE-2018-3874

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 32 bytes. An attacker can send an arbitrarily long "accessKey" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    9.9
    Critical

    CVE-2018-3877

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 160 bytes. An attacker can send an arbitrarily long "directory" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    9.9
    Critical

    CVE-2018-3873

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 128 bytes. An attacker can send an arbitrarily long "secretKey" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    8.8
    High

    CVE-2018-3876

    Last Modified: 21 Nov 2024

    An exploitable buffer overflow vulnerability exists in the credentials handler of video-core's HTTP server of Samsung SmartThings Hub STH-ETH-250-Firmware version 0.20.17. The strncpy overflows the destination buffer, which has a size of 64 bytes. An attacker can send an arbitrarily long "bucket" value in order to exploit this vulnerability.

    Published: 21 Sept 2018
    5.5
    Medium

    CVE-2018-1685

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 contains a vulnerability in db2cacpy that could allow a local user to read any file on the system. IBM X-Force ID: 145502.

    Published: 21 Sept 2018
    8.4
    High

    CVE-2018-1710

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 10.1, 10.5, and 11.1 tool db2licm is affected by buffer overflow vulnerability that can potentially result in arbitrary code execution. IBM X-Force ID: 146364.

    Published: 21 Sept 2018
    8.4
    High

    CVE-2018-1711

    Last Modified: 21 Nov 2024

    IBM DB2 for Linux, UNIX and Windows (includes DB2 Connect Server) 9.7, 10.1, 10.5, and 11.1 could allow a local user to to gain privileges due to allowing modification of columns of existing tasks. IBM X-Force ID: 146369.

    Published: 21 Sept 2018
    6.5
    Medium

    CVE-2018-17292

    Last Modified: 21 Nov 2024

    An issue was discovered in WAVM before 2018-09-16. The loadModule function in Include/Inline/CLI.h lacks checking of the file length before a file magic comparison, allowing attackers to cause a Denial of Service (application crash caused by out-of-bounds read) by crafting a file that has fewer than 4 bytes.

    Published: 21 Sept 2018
    8.8
    High

    CVE-2018-17293

    Last Modified: 21 Nov 2024

    An issue was discovered in WAVM before 2018-09-16. The run function in Programs/wavm/wavm.cpp does not check whether there is Emscripten memory to store the command-line arguments passed by the input WebAssembly file's main function, which allows attackers to cause a denial of service (application crash by NULL pointer dereference) or possibly have unspecified other impact by crafting certain WebAssembly files.

    Published: 21 Sept 2018