CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-17086

    Last Modified: 21 Nov 2024

    An issue was discovered in OTCMS 3.61. XSS exists in admin/share_switch.php via these parameters: fieldName fieldName2 tabName.

    Published: 16 Sept 2018
    7.8
    High

    CVE-2018-17088

    Last Modified: 21 Nov 2024

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because there is an integer overflow during a check for whether a location exceeds the EXIF data length. This is analogous to the CVE-2016-3822 integer overflow in exif.c. This gpsinfo.c vulnerability is unrelated to the CVE-2018-16554 gpsinfo.c vulnerability.

    Published: 16 Sept 2018
    9.8
    Critical

    CVE-2018-17072

    Last Modified: 21 Nov 2024

    JSON++ through 2016-06-15 has a buffer over-read in yyparse() in json.y.

    Published: 16 Sept 2018
    7.5
    High

    CVE-2018-17073

    Last Modified: 21 Nov 2024

    wernsey/bitmap before 2018-08-18 allows a NULL pointer dereference via a 4-bit image.

    Published: 16 Sept 2018
    6.1
    Medium

    CVE-2018-17074

    Last Modified: 21 Nov 2024

    The Feed Statistics plugin before 4.0 for WordPress has an Open Redirect via the feed-stats-url parameter.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17076

    Last Modified: 21 Nov 2024

    GPP through 2.25 will try to use more memory space than is available on the stack, leading to a segmentation fault or possibly unspecified other impact via a crafted file.

    Published: 16 Sept 2018
    7.8
    High

    CVE-2018-16554

    Last Modified: 21 Nov 2024

    The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of inconsistency between float and double in a sprintf format string during TAG_GPS_ALT handling.

    Published: 16 Sept 2018
    7.5
    High

    CVE-2018-17075

    Last Modified: 21 Nov 2024

    The html package (aka x/net/html) before 2018-07-13 in Go mishandles "in frameset" insertion mode, leading to a "panic: runtime error" for html.Parse of <template><object>, <template><applet>, or <template><marquee>. This is related to HTMLTreeBuilder.cpp in WebKit.

    Published: 16 Sept 2018
    6.1
    Medium

    CVE-2018-17077

    Last Modified: 21 Nov 2024

    An issue was discovered in yiqicms through 2016-11-20. There is stored XSS in comment.php because a length limit can be bypassed.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17095

    Last Modified: 13 Aug 2025

    An issue has been discovered in mpruett Audio File Library (aka audiofile) 0.3.6, 0.3.5, 0.3.4, 0.3.3, 0.3.2, 0.3.1, 0.3.0. A heap-based buffer overflow in Expand3To4Module::run has occurred when running sfconvert.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17100

    Last Modified: 21 Nov 2024

    An issue was discovered in LibTIFF 4.0.9. There is a int32 overflow in multiply_ms in tools/ppm2tiff.c, which can cause a denial of service (crash) or possibly have unspecified other impact via a crafted image file.

    Published: 16 Sept 2018
    8.8
    High

    CVE-2018-17101

    Last Modified: 21 Nov 2024

    An issue was discovered in LibTIFF 4.0.9. There are two out-of-bounds writes in cpTags in tools/tiff2bw.c and tools/pal2rgb.c, which can cause a denial of service (application crash) or possibly have unspecified other impact via a crafted image file.

    Published: 16 Sept 2018
    9.8
    Critical

    CVE-2018-17065

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. Within the handler function of the /goform/DDNS route, a very long password could lead to a stack-based buffer overflow and overwrite the return address.

    Published: 15 Sept 2018
    9.8
    Critical

    CVE-2018-17066

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/form2systime.cgi route. This could lead to command injection via shell metacharacters in the datetime parameter.

    Published: 15 Sept 2018
    9.8
    Critical

    CVE-2018-17067

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. A very long password to /goform/formLogin could lead to a stack-based buffer overflow and overwrite the return address.

    Published: 15 Sept 2018
    9.8
    Critical

    CVE-2018-17068

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction in the handler function of the /goform/Diagnosis route. This could lead to command injection via shell metacharacters in the sendNum parameter.

    Published: 15 Sept 2018
    6.5
    Medium

    CVE-2018-17069

    Last Modified: 21 Nov 2024

    An issue was discovered in UNL-CMS 7.59. A CSRF attack can create new content via ?q=node%2Fadd%2Farticle&render=overlay&render=overlay.

    Published: 15 Sept 2018
    6.5
    Medium

    CVE-2018-17070

    Last Modified: 21 Nov 2024

    An issue was discovered in UNL-CMS 7.59. A CSRF attack can update the website settings via ?q=admin%2Fconfig%2Fsystem%2Fsite-information&render=overlay&render=overlay.

    Published: 15 Sept 2018
    9.8
    Critical

    CVE-2018-17064

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/sylogapply route. This could lead to command injection via the syslogIp parameter after /goform/clearlog is invoked.

    Published: 15 Sept 2018
    9.8
    Critical

    CVE-2018-17063

    Last Modified: 21 Nov 2024

    An issue was discovered on D-Link DIR-816 A2 1.10 B05 devices. An HTTP request parameter is used in command string construction within the handler function of the /goform/NTPSyncWithHost route. This could lead to command injection via shell metacharacters.

    Published: 15 Sept 2018
    6.1
    Medium

    CVE-2018-17061

    Last Modified: 21 Nov 2024

    BullGuard Safe Browsing before 18.1.355.9 allows XSS on Google, Bing, and Yahoo! pages via domains indexed in search results.

    Published: 15 Sept 2018
    6.5
    Medium

    CVE-2018-17233

    Last Modified: 21 Nov 2024

    A SIGFPE signal is raised in the function H5D__create_chunk_file_map_hyper() of H5Dchunk.c in the HDF HDF5 through 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. It could allow a remote denial of service attack.

    Published: 15 Sept 2018
    4.8
    Medium

    CVE-2018-10763

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page.

    Published: 14 Sept 2018
    7.8
    High

    CVE-2018-10814

    Last Modified: 21 Nov 2024

    Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.

    Published: 14 Sept 2018
    7.5
    High

    CVE-2018-12086

    Last Modified: 21 Nov 2024

    Buffer overflow in OPC UA applications allows remote attackers to trigger a stack overflow with carefully structured requests.

    Published: 14 Sept 2018
    5.3
    Medium

    CVE-2018-16242

    Last Modified: 21 Nov 2024

    oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable nonce used in the locking protocol.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-16286

    Last Modified: 21 Nov 2024

    LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-16287

    Last Modified: 21 Nov 2024

    LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.

    Published: 14 Sept 2018
    8.6
    High

    CVE-2018-16288

    Last Modified: 21 Nov 2024

    LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

    Published: 14 Sept 2018
    7.5
    High

    CVE-2018-16706

    Last Modified: 21 Nov 2024

    LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

    Published: 14 Sept 2018
    8.2
    High

    CVE-2018-12585

    Last Modified: 21 Nov 2024

    An XXE vulnerability in the OPC UA Java and .NET Legacy Stack can allow remote attackers to trigger a denial of service.

    Published: 14 Sept 2018
    4.3
    Medium

    CVE-2017-16639

    Last Modified: 21 Nov 2024

    Tor Browser on Windows before 8.0 allows remote attackers to bypass the intended anonymity feature and discover a client IP address, a different vulnerability than CVE-2017-16541. User interaction is required to trigger this vulnerability.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-17057

    Last Modified: 21 Nov 2024

    An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-11058

    Last Modified: 21 Nov 2024

    RSA BSAFE Micro Edition Suite, versions prior to 4.0.11 (in 4.0.x) and prior to 4.1.6 (in 4.1.x), and RSA BSAFE Crypto-C Micro Edition, version prior to 4.0.5.3 (in 4.0.x) contain a Buffer Over-Read vulnerability when parsing ASN.1 data. A remote attacker could use maliciously constructed ASN.1 data that would result in such issue.

    Published: 14 Sept 2018
    5.9
    Medium

    CVE-2018-11087

    Last Modified: 27 Mar 2025

    Pivotal Spring AMQP, 1.x versions prior to 1.7.10 and 2.x versions prior to 2.0.6, expose a man-in-the-middle vulnerability due to lack of hostname validation. A malicious user that has the ability to intercept traffic would be able to view data in transit.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-0718

    Last Modified: 21 Nov 2024

    Command injection vulnerability in Music Station 5.1.2 and earlier versions in QNAP QTS 4.3.3 and 4.3.4 could allow remote attackers to run arbitrary commands in the compromised application.

    Published: 14 Sept 2018
    5.9
    Medium

    CVE-2018-1719

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 8.5 and 9.0 could provide weaker than expected security under certain conditions. This could result in a downgrade of TLS protocol. A remote attacker could exploit this vulnerability to perform man-in-the-middle attacks. IBM X-Force ID: 147292.

    Published: 14 Sept 2018
    4.9
    Medium

    CVE-2018-1791

    Last Modified: 21 Nov 2024

    IBM Connections 5.0, 5.5, and 6.0 is vulnerable to an External Service Interaction attack, caused by improper validation of a request property. By submitting suitable payloads, an attacker could exploit this vulnerability to induce the Connections server to attack other systems. IBM X-Force ID: 148946.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-17035

    Last Modified: 21 Nov 2024

    UCMS 1.4.6 has SQL injection during installation via the install/index.php mysql_dbname parameter.

    Published: 14 Sept 2018
    8.8
    High

    CVE-2018-17037

    Last Modified: 21 Nov 2024

    user/editpost.php in UCMS 1.4.6 mishandles levels, which allows escalation from the normal user level of 1 to the superuser level of 3.

    Published: 14 Sept 2018
    6.1
    Medium

    CVE-2018-17039

    Last Modified: 21 Nov 2024

    MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.

    Published: 14 Sept 2018
    5.5
    Medium

    CVE-2018-17042

    Last Modified: 21 Nov 2024

    An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop.

    Published: 14 Sept 2018
    4.8
    Medium

    CVE-2018-17044

    Last Modified: 21 Nov 2024

    In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.

    Published: 14 Sept 2018
    6.1
    Medium

    CVE-2018-17046

    Last Modified: 21 Nov 2024

    translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.

    Published: 14 Sept 2018
    6.1
    Medium

    CVE-2018-17051

    Last Modified: 21 Nov 2024

    K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.

    Published: 14 Sept 2018
    7.8
    High

    CVE-2018-17043

    Last Modified: 21 Nov 2024

    An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init in Storage.cpp, called from parse_doc in parse_doc.cpp.

    Published: 14 Sept 2018
    6.1
    Medium

    CVE-2018-17034

    Last Modified: 21 Nov 2024

    UCMS 1.4.6 has XSS via the install/index.php mysql_dbname parameter.

    Published: 14 Sept 2018
    9.8
    Critical

    CVE-2018-17036

    Last Modified: 21 Nov 2024

    An issue was discovered in UCMS 1.4.6 and 1.6. It allows PHP code injection during installation via the systemdomain parameter to install/index.php, as demonstrated by injecting a phpinfo() call into /inc/config.php.

    Published: 14 Sept 2018
    8.8
    High

    CVE-2018-17045

    Last Modified: 21 Nov 2024

    An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aksi_users.php?act=update.

    Published: 14 Sept 2018
    6.1
    Medium

    CVE-2018-17049

    Last Modified: 21 Nov 2024

    CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.

    Published: 14 Sept 2018