CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-16285

    Last Modified: 21 Nov 2024

    The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.

    Published: 6 Sept 2018
    5.5
    Medium

    CVE-2018-16647

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.13.0, the pdf_get_xref_entry function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation fault in fz_write_data in fitz/output.c) via a crafted pdf file.

    Published: 6 Sept 2018
    9.8
    Critical

    CVE-2018-6320

    Last Modified: 21 Nov 2024

    A vulnerability has been discovered in login.cgi in Pulse Secure Pulse Connect Secure (PCS) 8.1RX before 8.1R12 and 8.3RX before 8.3R2 and Pulse Policy Secure (PPS) 5.2RX before 5.2R9 and 5.4RX before 5.4R2 wherein an http(s) Host header received from the browser is trusted without validation.

    Published: 6 Sept 2018
    6.1
    Medium

    CVE-2018-12234

    Last Modified: 2 Mar 2026

    A Reflected Cross Site Scripting (XSS) Vulnerability was discovered in Adrenalin 5.4.0 HRMS Software. The user supplied input containing JavaScript is echoed back in JavaScript code in an HTML response via the flexiportal/GeneralInfo.aspx strAction parameter.

    Published: 6 Sept 2018
    6.8
    Medium

    CVE-2018-16261

    Last Modified: 21 Nov 2024

    In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.

    Published: 6 Sept 2018
    6.5
    Medium

    CVE-2018-16310

    Last Modified: 21 Nov 2024

    Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-15852 and CVE-2018-15907. NOTE: Technicolor denies that the described behavior is a vulnerability and states that Wi-Fi traffic is slowed or stopped only while the devices are exposed to a MAC flooding attack. This has been confirmed through testing against official up-to-date versions

    Published: 6 Sept 2018
    9.8
    Critical

    CVE-2018-16590

    Last Modified: 21 Nov 2024

    FURUNO FELCOM 250 and 500 devices use only client-side JavaScript in login.js for authentication.

    Published: 6 Sept 2018
    5.5
    Medium

    CVE-2018-16648

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.13.0, the fz_append_byte function in fitz/buffer.c allows remote attackers to cause a denial of service (segmentation fault) via a crafted pdf file. This is caused by a pdf/pdf-device.c pdf_dev_alpha array-index underflow.

    Published: 6 Sept 2018
    8.8
    High

    CVE-2018-1000669

    Last Modified: 21 Nov 2024

    KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Request Forgery (CSRF) vulnerability in /cgi-bin/koha/members/paycollect.pl Parameters affected: borrowernumber, amount, amountoutstanding, paid that can result in Attackers can mark payments as paid for certain users on behalf of Administrators. This attack appear to be exploitable via The victim must be socially engineered into clicking a link, usually via email. This vulnerability appears to have been fixed in 17.11.

    Published: 6 Sept 2018
    6.1
    Medium

    CVE-2018-1000670

    Last Modified: 21 Nov 2024

    KOHA Library System version 16.11.x (up until 16.11.13) and 17.05.x (up until 17.05.05) contains a Cross Site Scripting (XSS) vulnerability in Multiple fields on multiple pages including /cgi-bin/koha/acqui/supplier.pl?op=enter , /cgi-bin/koha/circ/circulation.pl?borrowernumber=[number] , /cgi-bin/koha/serials/subscription-add.pl that can result in Privilege escalation by taking control of higher privileged users browser sessions. This attack appear to be exploitable via Victims must be socially engineered to visit a vulnerable webpage containing malicious payload. This vulnerability appears to have been fixed in 17.11.

    Published: 6 Sept 2018
    6.1
    Medium

    CVE-2018-5005

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a Cross-site Scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 6 Sept 2018
    7.5
    High

    CVE-2017-14026

    Last Modified: 21 Nov 2024

    In Ice Qube Thermal Management Center versions prior to version 4.13, the web application does not properly authenticate users which may allow an attacker to gain access to sensitive information.

    Published: 6 Sept 2018
    9.8
    Critical

    CVE-2017-16714

    Last Modified: 21 Nov 2024

    In Ice Qube Thermal Management Center versions prior to version 4.13, passwords are stored in plaintext in a file that is accessible without authentication.

    Published: 6 Sept 2018
    5.4
    Medium

    CVE-2018-16622

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in /api/content/addOne in DoraCMS v2.0.3 allow remote attackers to inject arbitrary web script or HTML via the (1) discription or (2) comments field, related to users/userAddContent.

    Published: 6 Sept 2018
    6.1
    Medium

    CVE-2018-1000671

    Last Modified: 21 Nov 2024

    sympa version 6.2.16 and later contains a CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability in The "referer" parameter of the wwsympa.fcgi login action. that can result in Open redirection and reflected XSS via data URIs. This attack appear to be exploitable via Victim's browser must follow a URL supplied by the attacker. This vulnerability appears to have been fixed in none available.

    Published: 6 Sept 2018
    8.8
    High

    CVE-2018-1000658

    Last Modified: 21 Nov 2024

    LimeSurvey version prior to 3.14.4 contains a file upload vulnerability in upload functionality that can result in an attacker gaining code execution via webshell. This attack appear to be exploitable via an authenticated user uploading a zip archive which can contains malicious php files that can be called under certain circumstances. This vulnerability appears to have been fixed in after commit 91d143230eb357260a19c8424b3005deb49a47f7 / version 3.14.4.

    Published: 6 Sept 2018
    8.8
    High

    CVE-2018-1000659

    Last Modified: 21 Nov 2024

    LimeSurvey version 3.14.4 and earlier contains a directory traversal in file upload that allows upload of webshell vulnerability in file upload functionality that can result in remote code execution as authenticated user. This attack appear to be exploitable via An authenticated user can upload a specially crafted zip file to get remote code execution. This vulnerability appears to have been fixed in after commit 72a02ebaaf95a80e26127ee7ee2b123cccce05a7 / version 3.14.4.

    Published: 6 Sept 2018
    6.5
    Medium

    CVE-2018-1000663

    Last Modified: 21 Nov 2024

    jsish version 2.4.70 2.047 contains a Buffer Overflow vulnerability in function _jsi_evalcode from jsiEval.c that can result in Crash due to segmentation fault. This attack appear to be exploitable via The victim must execute crafted javascript code.

    Published: 6 Sept 2018
    9.8
    Critical

    CVE-2018-1000666

    Last Modified: 21 Nov 2024

    GIG Technology NV JumpScale Portal 7 version before commit 15443122ed2b1cbfd7bdefc048bf106f075becdb contains a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in method: notifySpaceModification; that can result in Improper validation of parameters results in command execution. This attack appear to be exploitable via Network connectivity, required minimal auth privileges (everyone can register an account). This vulnerability appears to have been fixed in After commit 15443122ed2b1cbfd7bdefc048bf106f075becdb.

    Published: 6 Sept 2018
    9.8
    Critical

    CVE-2018-1000800

    Last Modified: 21 Nov 2024

    zephyr-rtos version 1.12.0 contains a NULL base pointer reference vulnerability in sys_ring_buf_put(), sys_ring_buf_get() that can result in CPU Page Fault (error code 0x00000010). This attack appear to be exploitable via a malicious application call the vulnerable kernel APIs (system sys_ring_buf_get() and sys_ring_buf_put).

    Published: 6 Sept 2018
    7.5
    High

    CVE-2018-1000660

    Last Modified: 21 Nov 2024

    TOCK version prior to commit 42f7f36e74088036068d62253e1d8fb26605feed. For example dfde28196cd12071fcf6669f7654be7df482b85d contains a Insecure Permissions vulnerability in Function get_package_name in the file kernel/src/tbfheader.rs, variable "pub package_name: &'static str," in the file process.rs that can result in A tock capsule (untrusted driver) could access arbitrary memory by using only safe code. This vulnerability appears to have been fixed in commit 42f7f36e74088036068d62253e1d8fb26605feed.

    Published: 6 Sept 2018
    6.5
    Medium

    CVE-2018-1000661

    Last Modified: 21 Nov 2024

    jsish version 2.4.67 contains a CWE-476: NULL Pointer Dereference vulnerability in Jsi_LogMsg (jsiUtils.c:196) that can result in Crash due to segmentation fault. This attack appear to be exploitable via the victim executing specially crafted javascript code. This vulnerability appears to have been fixed in 2.4.69.

    Published: 6 Sept 2018
    5.9
    Medium

    CVE-2018-1000664

    Last Modified: 21 Nov 2024

    daneren2005 DSub for Subsonic (Android client) version 5.4.1 contains a CWE-295: Improper Certificate Validation vulnerability in HTTPS Client that can result in Any non-CA signed server certificate, including self signed and expired, are accepted by the client. This attack appear to be exploitable via The victim connects to a server that's MITM/Proxied by an attacker.

    Published: 6 Sept 2018
    6.5
    Medium

    CVE-2018-1000668

    Last Modified: 21 Nov 2024

    jsish version 2.4.70 2.047 contains a CWE-125: Out-of-bounds Read vulnerability in function jsi_ObjArrayLookup (jsiObj.c:274) that can result in Crash due to segmentation fault. This attack appear to be exploitable via The victim must execute crafted javascript code. This vulnerability appears to have been fixed in 2.4.71.

    Published: 6 Sept 2018
    6.5
    Medium

    CVE-2018-16606

    Last Modified: 21 Nov 2024

    In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).

    Published: 6 Sept 2018
    8.8
    High

    CVE-2018-1000773

    Last Modified: 21 Nov 2024

    WordPress version 4.9.8 and earlier contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution due to an incomplete fix for CVE-2017-1000600. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time.

    Published: 6 Sept 2018
    7.2
    High

    CVE-2018-16604

    Last Modified: 21 Nov 2024

    An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double quotes (e.g., "${phpinfo()}").

    Published: 6 Sept 2018
    8.8
    High

    CVE-2018-11263

    Last Modified: 21 Nov 2024

    In all Android releases (Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, radio_id is received from the FW and is used to access the buffer to copy the radio stats received for each radio from FW. If the radio_id received from the FW is greater than or equal to maximum, an OOB write will occur. On supported Google Pixel and Nexus devices, this has been addressed in security patch level 2018-08-05.

    Published: 6 Sept 2018
    7.3
    High

    CVE-2018-1695

    Last Modified: 21 Nov 2024

    IBM WebSphere Application Server 7.0, 8.0, and 8.5.5 installations using Form Login could allow a remote attacker to conduct spoofing attacks. IBM X-Force ID: 145769.

    Published: 6 Sept 2018
    6.1
    Medium

    CVE-2018-16459

    Last Modified: 21 Nov 2024

    An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.

    Published: 6 Sept 2018
    Unknown

    CVE-2018-1000673

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000773. Reason: This candidate is a reservation duplicate of CVE-2018-1000773. Notes: All CVE users should reference CVE-2018-1000773 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 6 Sept 2018
    8.8
    High

    CVE-2017-1000600

    Last Modified: 21 Nov 2024

    WordPress version <4.9 contains a CWE-20 Input Validation vulnerability in thumbnail processing that can result in remote code execution. This attack appears to be exploitable via thumbnail upload by an authenticated user and may require additional plugins in order to be exploited however this has not been confirmed at this time. This issue appears to have been partially, but not completely fixed in WordPress 4.9

    Published: 6 Sept 2018
    5.5
    Medium

    CVE-2018-1000886

    Last Modified: 21 Nov 2024

    nasm version 2.14.01rc5, 2.15 contains a Buffer Overflow vulnerability in asm/stdscan.c:130 that can result in Stack-overflow caused by triggering endless macro generation, crash the program. This attack appear to be exploitable via a crafted nasm input file.

    Published: 6 Sept 2018
    7.8
    High

    CVE-2018-16588

    Last Modified: 21 Nov 2024

    Privilege escalation can occur in the SUSE useradd.c code in useradd, as distributed in the SUSE shadow package through 4.2.1-27.9.1 for SUSE Linux Enterprise 12 (SLE-12) and through 4.5-5.39 for SUSE Linux Enterprise 15 (SLE-15). Non-existing intermediate directories are created with mode 0777 during user creation. Given that they are world-writable, local attackers might use this for privilege escalation and other unspecified attacks. NOTE: this would affect non-SUSE users who took useradd.c code from a 2014-04-02 upstream pull request; however, no non-SUSE distribution is known to be affected.

    Published: 6 Sept 2018
    5.5
    Medium

    CVE-2018-1000667

    Last Modified: 21 Nov 2024

    NASM nasm-2.13.03 nasm- 2.14rc15 version 2.14rc15 and earlier contains a memory corruption (crashed) of nasm when handling a crafted file due to function assemble_file(inname, depend_ptr) at asm/nasm.c:482. vulnerability in function assemble_file(inname, depend_ptr) at asm/nasm.c:482. that can result in aborting/crash nasm program. This attack appear to be exploitable via a specially crafted asm file..

    Published: 6 Sept 2018
    5.5
    Medium

    CVE-2018-1000801

    Last Modified: 21 Nov 2024

    okular version 18.08 and earlier contains a Directory Traversal vulnerability in function "unpackDocumentArchive(...)" in "core/document.cpp" that can result in Arbitrary file creation on the user workstation. This attack appear to be exploitable via he victim must open a specially crafted Okular archive. This issue appears to have been corrected in version 18.08.1

    Published: 6 Sept 2018
    7.7
    High

    CVE-2018-14632

    Last Modified: 21 Nov 2024

    An out of bound write can occur when patching an Openshift object using the 'oc patch' functionality in OpenShift Container Platform before 3.7. An attacker can use this flaw to cause a denial of service attack on the Openshift master api service which provides cluster management.

    Published: 6 Sept 2018
    6.1
    Medium

    CVE-2018-1000665

    Last Modified: 21 Nov 2024

    Dojo Dojo Objective Harness (DOH) version prior to version 1.14 contains a Cross Site Scripting (XSS) vulnerability in unit.html and testsDOH/_base/loader/i18n-exhaustive/i18n-test/unit.html and testsDOH/_base/i18nExhaustive.js in the DOH that can result in Victim attacked through their browser - deliver malware, steal HTTP cookies, bypass CORS trust. This attack appear to be exploitable via Victims are typically lured to a web site under the attacker's control; the XSS vulnerability on the target domain is silently exploited without the victim's knowledge. This vulnerability appears to have been fixed in 1.14.

    Published: 6 Sept 2018
    7.8
    High

    CVE-2018-16585

    Last Modified: 21 Nov 2024

    An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the startup phase). This leads to memory corruption, allowing remote attackers able to supply crafted PostScript to crash the interpreter or possibly have unspecified other impact. Note: A reputable source believes that the CVE is potentially a duplicate of CVE-2018-15910 as explained in Red Hat bugzilla (https://bugzilla.redhat.com/show_bug.cgi?id=1626193)

    Published: 6 Sept 2018
    9.8
    Critical

    CVE-2018-16550

    Last Modified: 21 Nov 2024

    TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value of the default 4-digit PIN.

    Published: 5 Sept 2018
    5.4
    Medium

    CVE-2018-16551

    Last Modified: 21 Nov 2024

    LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.

    Published: 5 Sept 2018
    8.8
    High

    CVE-2018-16552

    Last Modified: 21 Nov 2024

    MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.

    Published: 5 Sept 2018
    8.8
    High

    CVE-2018-14770

    Last Modified: 21 Nov 2024

    VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 1 of 2) via the ONVIF interface, (/onvif/device_service).

    Published: 5 Sept 2018
    8.8
    High

    CVE-2018-14771

    Last Modified: 21 Nov 2024

    VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow remote attackers to execute arbitrary code (issue 2 of 2) via eventscript.cgi.

    Published: 5 Sept 2018
    5.3
    Medium

    CVE-2018-15676

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT. By using String.replace and eval, it is possible to bypass the includes/crk_protection.php anti-XSS mechanism that looks for a number of dangerous fingerprints.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-15677

    Last Modified: 21 Nov 2024

    The newsfeed (aka /index.php?page=viewnews) in BTITeam XBTIT 2.5.4 has stored XSS via the title of a news item. This is also exploitable via CSRF.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-15678

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT 2.5.4. The "act" parameter in the sign-up page available at /index.php?page=signup is vulnerable to reflected cross-site scripting.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-15680

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT 2.5.4. The hashed passwords stored in the xbtit_users table are stored as unsalted MD5 hashes, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack.

    Published: 5 Sept 2018
    8.8
    High

    CVE-2018-15682

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT. Due to a lack of cross-site request forgery protection, it is possible to automate the action of sending private messages to users by luring an authenticated user to a web page that automatically submits a form on their behalf.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-15683

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT. The "returnto" parameter of the login page is vulnerable to an open redirect due to a lack of validation. If a user is already logged in when accessing the page, they will be instantly redirected.

    Published: 5 Sept 2018