CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2018-15684

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT. PHP error logs are stored in an open directory (/include/logs) using predictable file names, which can lead to full path disclosure and leakage of sensitive data.

    Published: 5 Sept 2018
    5.4
    Medium

    CVE-2018-15917

    Last Modified: 21 Nov 2024

    Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

    Published: 5 Sept 2018
    5.4
    Medium

    CVE-2018-15918

    Last Modified: 21 Nov 2024

    An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-16144

    Last Modified: 21 Nov 2024

    The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password parameter.

    Published: 5 Sept 2018
    7.2
    High

    CVE-2018-16146

    Last Modified: 21 Nov 2024

    The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurable events. The value parameter is not properly sanitized, leading to arbitrary command injection with the privileges of the nagios user account.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-16147

    Last Modified: 21 Nov 2024

    The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-16148

    Last Modified: 21 Nov 2024

    The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.

    Published: 5 Sept 2018
    3.3
    Low

    CVE-2018-16252

    Last Modified: 21 Nov 2024

    FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.

    Published: 5 Sept 2018
    7.5
    High

    CVE-2018-16307

    Last Modified: 21 Nov 2024

    An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL and return those contents in its own response. If a domain name (containing a random string) is used in the HTTP Host header, the application performs an HTTP request to the specified domain. The response from that request is then included in the application's own response.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-16361

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-16381

    Last Modified: 21 Nov 2024

    e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.

    Published: 5 Sept 2018
    5.3
    Medium

    CVE-2018-16549

    Last Modified: 21 Nov 2024

    HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.

    Published: 5 Sept 2018
    8.1
    High

    CVE-2018-16145

    Last Modified: 21 Nov 2024

    The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow attackers to elevate their privileges to root after a system restart, hence obtaining full control of the appliance.

    Published: 5 Sept 2018
    8.8
    High

    CVE-2018-14769

    Last Modified: 21 Nov 2024

    VIVOTEK FD8177 devices before XXXXXX-VVTK-xx06a allow CSRF.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-15679

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT 2.5.4. The "keywords" parameter in the search function available at /index.php?page=forums&action=search is vulnerable to reflected cross-site scripting.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-15681

    Last Modified: 21 Nov 2024

    An issue was discovered in BTITeam XBTIT 2.5.4. When a user logs in, their password hash is rehashed using a predictable salt and stored in the "pass" cookie, which is not flagged as HTTPOnly. Due to the weak and predictable salt that is in place, an attacker who successfully steals this cookie can efficiently brute-force it to retrieve the user's cleartext password.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2015-9266

    Last Modified: 21 Nov 2024

    The web management interface of Ubiquiti airMAX, airFiber, airGateway and EdgeSwitch XP (formerly TOUGHSwitch) allows an unauthenticated attacker to upload and write arbitrary files using directory traversal techniques. An attacker can exploit this vulnerability to gain root privileges. This vulnerability is fixed in the following product versions (fixes released in July 2015, all prior versions are affected): airMAX AC 7.1.3; airMAX M (and airRouter) 5.6.2 XM/XW/TI, 5.5.11 XM/TI, and 5.5.10u2 XW; airGateway 1.1.5; airFiber AF24/AF24HD 2.2.1, AF5x 3.0.2.1, and AF5 2.2.1; airOS 4 XS2/XS5 4.0.4; and EdgeSwitch XP (formerly TOUGHSwitch) 1.3.2.

    Published: 5 Sept 2018
    7.2
    High

    CVE-2018-16436

    Last Modified: 21 Nov 2024

    Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.

    Published: 5 Sept 2018
    4.9
    Medium

    CVE-2018-16437

    Last Modified: 21 Nov 2024

    Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.

    Published: 5 Sept 2018
    5.9
    Medium

    CVE-2018-16546

    Last Modified: 21 Nov 2024

    Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation, as demonstrated by Amcrest_IPC-HX1X3X-LEXUS_Eng_N_AMCREST_V2.420.AC01.3.R.20180206.

    Published: 5 Sept 2018
    7.8
    High

    CVE-2018-16545

    Last Modified: 21 Nov 2024

    Kaizen Asset Manager (Enterprise Edition) and Training Manager (Enterprise Edition) allow a remote attacker to achieve arbitrary code execution via file impersonation. For example, a malicious dynamic-link library (dll) assumed the identity of a temporary (tmp) file (isxdl.dll) and an executable file assumed the identity of a temporary file (996E.temp).

    Published: 5 Sept 2018
    5.5
    Medium

    CVE-2018-16541

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect free logic in pagedevice replacement to crash the interpreter.

    Published: 5 Sept 2018
    7.8
    High

    CVE-2018-16543

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, gssetresolution and gsgetresolution allow attackers to have an unspecified impact.

    Published: 5 Sept 2018
    7.8
    High

    CVE-2018-16540

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files to the builtin PDF14 converter could use a use-after-free in copydevice handling to crash the interpreter or possibly have unspecified other impact.

    Published: 5 Sept 2018
    5.5
    Medium

    CVE-2018-16539

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use incorrect access checking in temp file handling to disclose contents of files on the system otherwise not readable.

    Published: 5 Sept 2018
    5.5
    Medium

    CVE-2018-16542

    Last Modified: 21 Nov 2024

    In Artifex Ghostscript before 9.24, attackers able to supply crafted PostScript files could use insufficient interpreter stack-size checking during error handling to crash the interpreter.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-16521

    Last Modified: 21 Nov 2024

    An XML External Entity (XXE) vulnerability exists in HTML Form Entry 3.7.0, as distributed in OpenMRS Reference Application 2.8.0.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-16518

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability with remote code execution in Prim'X Zed! FREE through 1.0 build 186 and Zed! Limited Edition through 6.1 build 2208 allows creation of arbitrary files on a user's workstation using crafted ZED! containers because the watermark loading function can place an executable file into a Startup folder.

    Published: 5 Sept 2018
    6.1
    Medium

    CVE-2018-16516

    Last Modified: 21 Nov 2024

    helpers.py in Flask-Admin 1.5.2 has Reflected XSS via a crafted URL.

    Published: 5 Sept 2018
    5.9
    Medium

    CVE-2018-9194

    Last Modified: 21 Nov 2024

    A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under VIP SSL feature when CPx being used.

    Published: 5 Sept 2018
    4.3
    Medium

    CVE-2018-1353

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in Fortinet FortiManager 6.0.1 and below versions allows a standard user with adom assignment read the interface settings of vdoms unrelated to the assigned adom.

    Published: 5 Sept 2018
    5.9
    Medium

    CVE-2018-9192

    Last Modified: 21 Nov 2024

    A plaintext recovery of encrypted messages or a Man-in-the-middle (MiTM) attack on RSA PKCS #1 v1.5 encryption may be possible without knowledge of the server's private key. Fortinet FortiOS 5.4.6 to 5.4.9, 6.0.0 and 6.0.1 are vulnerable by such attack under SSL Deep Inspection feature when CPx being used.

    Published: 5 Sept 2018
    Unknown

    CVE-2018-1000662

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was inadvertently assigned by a different CNA at a time when the discoverer was communicating with the specific "Vendors and Projects" CNA for the product in question

    Published: 5 Sept 2018
    Unknown

    CVE-2018-1000672

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-16391, CVE-2018-16392, CVE-2018-16393, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16421, CVE-2018-16422, CVE-2018-16423, CVE-2018-16424, CVE-2018-16425, CVE-2018-16426, CVE-2018-16427. Reason: This candidate is a duplicate of CVE-2018-16391, CVE-2018-16392, CVE-2018-16393, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16421, CVE-2018-16422, CVE-2018-16423, CVE-2018-16424, CVE-2018-16425, CVE-2018-16426, and CVE-2018-16427. Notes: All CVE users should reference CVE-2018-16391, CVE-2018-16392, CVE-2018-16393, CVE-2018-16418, CVE-2018-16419, CVE-2018-16420, CVE-2018-16421, CVE-2018-16422, CVE-2018-16423, CVE-2018-16424, CVE-2018-16425, CVE-2018-16426, and/or CVE-2018-16427 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 5 Sept 2018
    7.8
    High

    CVE-2018-16510

    Last Modified: 21 Nov 2024

    An issue was discovered in Artifex Ghostscript before 9.24. Incorrect exec stack handling in the "CS" and "SC" PDF primitives could be used by remote attackers able to supply crafted PDFs to crash the interpreter or possibly have unspecified other impact.

    Published: 5 Sept 2018
    6.5
    Medium

    CVE-2018-18499

    Last Modified: 21 Nov 2024

    A same-origin policy violation allowing the theft of cross-origin URL entries when using a meta http-equiv="refresh" on a page to cause a redirection to another site using performance.getEntries(). This is a same-origin policy violation and could allow for data theft. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

    Published: 5 Sept 2018
    7.8
    High

    CVE-2018-12379

    Last Modified: 25 Nov 2025

    When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running the Mozilla Updater manually on the local system with the malicious MAR file in order to occur. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

    Published: 5 Sept 2018
    5.5
    Medium

    CVE-2018-16517

    Last Modified: 21 Nov 2024

    asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.

    Published: 5 Sept 2018
    8.8
    High

    CVE-2018-12375

    Last Modified: 21 Nov 2024

    Memory safety bugs present in Firefox 61. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62.

    Published: 5 Sept 2018
    5.3
    Medium

    CVE-2018-12382

    Last Modified: 21 Nov 2024

    The displayed addressbar URL can be spoofed on Firefox for Android using a javascript: URI in concert with JavaScript to insert text before the loaded domain name, scrolling the loaded domain out of view to the right. This can lead to user confusion. *This vulnerability only affects Firefox for Android < 62.*

    Published: 5 Sept 2018
    6.5
    Medium

    CVE-2018-16548

    Last Modified: 10 Jul 2025

    An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.

    Published: 5 Sept 2018
    5.5
    Medium

    CVE-2018-21232

    Last Modified: 21 Nov 2024

    re2c before 2.0 has uncontrolled recursion that causes stack consumption in find_fixed_tags.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-12376

    Last Modified: 25 Nov 2025

    Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary code. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-12378

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when an IndexedDB index is deleted while still in use by JavaScript code that is providing payload values to be stored. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

    Published: 5 Sept 2018
    5.3
    Medium

    CVE-2018-12381

    Last Modified: 25 Nov 2025

    Manually dragging and dropping an Outlook email message into the browser will trigger a page navigation when the message's mail columns are incorrectly interpreted as a URL. *Note: this issue only affects Windows operating systems with Outlook installed. Other operating systems are not affected.*. This vulnerability affects Firefox ESR < 60.2 and Firefox < 62.

    Published: 5 Sept 2018
    7.5
    High

    CVE-2018-14618

    Last Modified: 15 Apr 2026

    curl before version 7.61.1 is vulnerable to a buffer overrun in the NTLM authentication code. The internal function Curl_ntlm_core_mk_nt_hash multiplies the length of the password by two (SUM) to figure out how large temporary storage area to allocate from the heap. The length value is then subsequently used to iterate over the password and generate output into the allocated storage buffer. On systems with a 32 bit size_t, the math to calculate SUM triggers an integer overflow when the password length exceeds 2GB (2^31 bytes). This integer overflow usually causes a very small buffer to actually get allocated instead of the intended very huge one, making the use of that buffer end up in a heap buffer overflow. (This bug is almost identical to CVE-2017-8816.)

    Published: 5 Sept 2018
    6.5
    Medium

    CVE-2018-17237

    Last Modified: 21 Nov 2024

    A SIGFPE signal is raised in the function H5D__chunk_set_info_real() of H5Dchunk.c in the HDF HDF5 1.10.3 library during an attempted parse of a crafted HDF file, because of incorrect protection against division by zero. This issue is different from CVE-2018-11207.

    Published: 5 Sept 2018
    9.8
    Critical

    CVE-2018-12377

    Last Modified: 25 Nov 2025

    A use-after-free vulnerability can occur when refresh driver timers are refreshed in some circumstances during shutdown when the timer is deleted while still in use. This results in a potentially exploitable crash. This vulnerability affects Firefox < 62, Firefox ESR < 60.2, and Thunderbird < 60.2.1.

    Published: 5 Sept 2018
    5.5
    Medium

    CVE-2018-12383

    Last Modified: 21 Nov 2024

    If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not deleted when the data was copied to a new format starting in Firefox 58. The new master password is added only on the new file. This could allow the exposure of stored password data outside of user expectations. This vulnerability affects Firefox < 62, Firefox ESR < 60.2.1, and Thunderbird < 60.2.1.

    Published: 5 Sept 2018
    7.5
    High

    CVE-2018-6923

    Last Modified: 21 Nov 2024

    In FreeBSD before 11.1-STABLE, 11.2-RELEASE-p2, 11.1-RELEASE-p13, ip fragment reassembly code is vulnerable to a denial of service due to excessive system resource consumption. This issue can allow a remote attacker who is able to send an arbitrary ip fragments to cause the machine to consume excessive resources.

    Published: 4 Sept 2018