CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-12826

    Last Modified: 21 Nov 2024

    Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 14 Aug 2018
    6.1
    Medium

    CVE-2016-4975

    Last Modified: 21 Nov 2024

    Possible CRLF injection allowing HTTP response splitting attacks for sites which use mod_userdir. This issue was mitigated by changes made in 2.4.25 and 2.2.32 which prohibit CR or LF injection into the "Location" or other outbound header key or value. Fixed in Apache HTTP Server 2.4.25 (Affected 2.4.1-2.4.23). Fixed in Apache HTTP Server 2.2.32 (Affected 2.2.0-2.2.31).

    Published: 14 Aug 2018
    5.4
    Medium

    CVE-2018-10934

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability was found in the JBoss Management Console versions before 7.1.6.CR1, 7.1.6.GA. Users with roles that can create objects in the application can exploit this to attack other privileged users.

    Published: 14 Aug 2018
    5.9
    Medium

    CVE-2018-5389

    Last Modified: 21 Nov 2024

    The Internet Key Exchange v1 main mode is vulnerable to offline dictionary or brute force attacks. Reusing a key pair across different versions and modes of IKE could lead to cross-protocol authentication bypasses. It is well known, that the aggressive mode of IKEv1 PSK is vulnerable to offline dictionary or brute force attacks. For the main mode, however, only an online attack against PSK authentication was thought to be feasible. This vulnerability could allow an attacker to recover a weak Pre-Shared Key or enable the impersonation of a victim host or network.

    Published: 14 Aug 2018
    5.3
    Medium

    CVE-2018-14781

    Last Modified: 22 May 2025

    Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin (bolus) delivery.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-10636

    Last Modified: 21 Nov 2024

    CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has multiple stack-based buffer overflow vulnerabilities that could cause the software to crash due to lacking user input validation before copying data from project files onto the stack. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.

    Published: 13 Aug 2018
    4.8
    Medium

    CVE-2018-10634

    Last Modified: 22 May 2025

    Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers.

    Published: 13 Aug 2018
    8.1
    High

    CVE-2018-10598

    Last Modified: 21 Nov 2024

    CNCSoft Version 1.00.83 and prior with ScreenEditor Version 1.00.54 has two out-of-bounds read vulnerabilities could cause the software to crash due to lacking user input validation for processing project files. Which may allow an attacker to gain remote code execution with administrator privileges if exploited.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-15123

    Last Modified: 21 Nov 2024

    Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under control device and smart home.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-15124

    Last Modified: 21 Nov 2024

    Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device.

    Published: 13 Aug 2018
    7.5
    High

    CVE-2018-15125

    Last Modified: 21 Nov 2024

    Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface.

    Published: 13 Aug 2018
    6.5
    Medium

    CVE-2018-6970

    Last Modified: 21 Nov 2024

    VMware Horizon 6 (6.x.x before 6.2.7), Horizon 7 (7.x.x before 7.5.1), and Horizon Client (4.x.x and prior before 4.8.1) contain an out-of-bounds read vulnerability in the Message Framework library. Successfully exploiting this issue may allow a less-privileged user to leak information from a privileged process running on a system where Horizon Connection Server, Horizon Agent or Horizon Client are installed. Note: This issue doesn't apply to Horizon 6, 7 Agents installed on Linux systems or Horizon Clients installed on non-Windows systems.

    Published: 13 Aug 2018
    5.4
    Medium

    CVE-2018-3780

    Last Modified: 21 Nov 2024

    A missing sanitization of search results for an autocomplete field in NextCloud Server <13.0.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

    Published: 13 Aug 2018
    5.4
    Medium

    CVE-2018-3781

    Last Modified: 21 Nov 2024

    A missing sanitization of search results for an autocomplete field in NextCloud Talk <3.2.5 could lead to a stored XSS requiring user-interaction. The missing sanitization only affected user names, hence malicious search results could only be crafted by authenticated users.

    Published: 13 Aug 2018
    Unknown

    CVE-2018-3782

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1002203. Reason: This candidate is a reservation duplicate of CVE-2018-1002203. Notes: All CVE users should reference CVE-2018-1002203 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-15145

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in portal/add_edit_event_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) eid, (2) userid, or (3) pid parameter.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-15139

    Last Modified: 21 Nov 2024

    Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.

    Published: 13 Aug 2018
    6.5
    Medium

    CVE-2018-15141

    Last Modified: 21 Nov 2024

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-15142

    Last Modified: 21 Nov 2024

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in the traversed directory.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-15143

    Last Modified: 21 Nov 2024

    Multiple SQL injection vulnerabilities in portal/find_appt_popup_user.php in versions of OpenEMR before 5.0.1.4 allow a remote attacker to execute arbitrary SQL commands via the (1) catid or (2) providerid parameter.

    Published: 13 Aug 2018
    6.5
    Medium

    CVE-2018-15140

    Last Modified: 21 Nov 2024

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-15144

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in interface/de_identification_forms/find_drug_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the search_term parameter.

    Published: 13 Aug 2018
    Unknown

    CVE-2018-10842

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-10912. Reason: This candidate is a duplicate of CVE-2018-10912. Notes: All CVE users should reference CVE-2018-10912 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Aug 2018
    5.4
    Medium

    CVE-2018-14849

    Last Modified: 21 Nov 2024

    Tiki before 18.2, 15.7 and 12.14 has XSS via link attributes, related to lib/core/WikiParser/OutputLink.php and lib/parser/parserlib.php.

    Published: 13 Aug 2018
    7.8
    High

    CVE-2018-14878

    Last Modified: 21 Nov 2024

    JetBrains dotPeek before 2018.2 and ReSharper Ultimate before 2018.1.4 allow attackers to execute code by decompiling a compiled .NET object (such as a DLL or EXE file) with a specific file, because of Deserialization of Untrusted Data.

    Published: 13 Aug 2018
    6.1
    Medium

    CVE-2018-10569

    Last Modified: 21 Nov 2024

    An issue was discovered in Edimax EW-7438RPn Mini v2 before version 1.26. There is XSS in an SSID field.

    Published: 13 Aug 2018
    6.1
    Medium

    CVE-2018-12587

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability was found in valeuraddons German Spelling Dictionary v1.3 (an Opera Browser add-on). Instead of providing text for a spelling check, remote attackers may inject arbitrary web script or HTML via the ajax query parameter in the URL Address Bar.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-13415

    Last Modified: 21 Nov 2024

    In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Plex, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-13417

    Last Modified: 21 Nov 2024

    In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Vuze, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

    Published: 13 Aug 2018
    5.4
    Medium

    CVE-2018-14850

    Last Modified: 21 Nov 2024

    Stored XSS vulnerabilities in Tiki before 18.2, 15.7 and 12.14 allow an authenticated user injecting JavaScript to gain administrator privileges if an administrator opens a wiki page and moves the mouse pointer over a modified link or thumb image.

    Published: 13 Aug 2018
    3.7
    Low

    CVE-2016-2922

    Last Modified: 21 Nov 2024

    IBM Rational ClearQuest 8.0 through 8.0.1.9 and 9.0 through 9.0.1.3 (CQ OSLC linkages, EmailRelay) fails to check the SSL certificate against the requested hostname. It is subject to a man-in-the-middle attack with an impersonating server observing all the data transmitted to the real server. IBM X-Force ID: 113353.

    Published: 13 Aug 2018
    6.5
    Medium

    CVE-2017-1286

    Last Modified: 21 Nov 2024

    Sensitive information about the configuration of the IBM UrbanCode Deploy 6.1 through 6.9.6.0 server and database can be obtained by a user who has been given elevated permissions in the UI, even after those elevated permissions have been revoked. IBM X-Force ID: 125147.

    Published: 13 Aug 2018
    5.3
    Medium

    CVE-2017-1749

    Last Modified: 21 Nov 2024

    IBM UrbanCode Deploy 6.1 through 6.9.6.0 could allow a remote attacker to traverse directories on the system. An unauthenticated attacker could alter UCD deployments. IBM X-Force ID: 135522.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-6414

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability in the web server of some Hikvision IP Cameras allows an attacker to send a specially crafted message to affected devices. Due to the insufficient input validation, successful exploit can corrupt memory and lead to arbitrary code execution or crash the process.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-5924

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.

    Published: 13 Aug 2018
    7.8
    High

    CVE-2018-5925

    Last Modified: 21 Nov 2024

    A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.

    Published: 13 Aug 2018
    6.1
    Medium

    CVE-2018-13392

    Last Modified: 21 Nov 2024

    Several resources in Atlassian Fisheye and Crucible before version 4.6.0 allow remote attackers to inject arbitrary HTML or JavaScript via a cross site scripting (XSS) vulnerability in linked issue keys.

    Published: 13 Aug 2018
    9.8
    Critical

    CVE-2018-0714

    Last Modified: 21 Nov 2024

    Command injection vulnerability in Helpdesk versions 1.1.21 and earlier in QNAP QTS 4.2.6 build 20180531, QTS 4.3.3 build 20180528, QTS 4.3.4 build 20180528 and their earlier versions could allow remote attackers to run arbitrary commands in the compromised application.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-10884

    Last Modified: 21 Nov 2024

    Ansible Tower before versions 3.1.8 and 3.2.6 is vulnerable to cross-site request forgery (CSRF) in awx/api/authentication.py. An attacker could exploit this by tricking already authenticated users into visiting a malicious site and hijacking the authtoken cookie.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-15518

    Last Modified: 21 Nov 2024

    QXmlStream in Qt 5.x before 5.11.3 has a double-free or corruption during parsing of a specially crafted illegal XML document.

    Published: 13 Aug 2018
    5.5
    Medium

    CVE-2018-15746

    Last Modified: 21 Nov 2024

    qemu-seccomp.c in QEMU might allow local OS guest users to cause a denial of service (guest crash) by leveraging mishandling of the seccomp policy for threads other than the main thread.

    Published: 13 Aug 2018
    6.5
    Medium

    CVE-2018-16336

    Last Modified: 21 Nov 2024

    Exiv2::Internal::PngChunk::parseTXTChunk in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, a different vulnerability than CVE-2018-10999.

    Published: 13 Aug 2018
    4.2
    Medium

    CVE-2018-11770

    Last Modified: 21 Nov 2024

    From version 1.3.0 onward, Apache Spark's standalone master exposes a REST API for job submission, in addition to the submission mechanism used by spark-submit. In standalone, the config property 'spark.authenticate.secret' establishes a shared secret for authenticating requests to submit jobs via spark-submit. However, the REST API does not use this or any other authentication mechanism, and this is not adequately documented. In this case, a user would be able to run a driver program without authenticating, but not launch executors, using the REST API. This REST API is also used by Mesos, when set up to run in cluster mode (i.e., when also running MesosClusterDispatcher), for job submission. Future versions of Spark will improve documentation on these points, and prohibit setting 'spark.authenticate.secret' when running the REST APIs, to make this clear. Future versions will also disable the REST API by default in the standalone master by changing the default value of 'spark.master.rest.enabled' to 'false'.

    Published: 13 Aug 2018
    7.8
    High

    CVE-2018-14424

    Last Modified: 21 Nov 2024

    The daemon in GDM through 3.29.1 does not properly unexport display objects from its D-Bus interface when they are destroyed, which allows a local attacker to trigger a use-after-free via a specially crafted sequence of D-Bus method calls, resulting in a denial of service or potential code execution.

    Published: 13 Aug 2018
    5.5
    Medium

    CVE-2018-16435

    Last Modified: 21 Nov 2024

    Little CMS (aka Little Color Management System) 2.9 has an integer overflow in the AllocateDataSet function in cmscgats.c, leading to a heap-based buffer overflow in the SetData function via a crafted file in the second argument to cmsIT8LoadFromFile.

    Published: 13 Aug 2018
    8.8
    High

    CVE-2018-3775

    Last Modified: 21 Nov 2024

    Improper Authentication in Nextcloud Server prior to version 12.0.3 would allow an attacker that obtained user credentials to bypass the 2 Factor Authentication.

    Published: 12 Aug 2018
    5.3
    Medium

    CVE-2018-3776

    Last Modified: 21 Nov 2024

    Improper input validator in Nextcloud Server prior to 12.0.3 and 11.0.5 could lead to an attacker's actions not being logged in the audit log.

    Published: 12 Aug 2018
    5.5
    Medium

    CVE-2018-1000654

    Last Modified: 21 Nov 2024

    GNU Libtasn1-4.13 libtasn1-4.13 version libtasn1-4.13, libtasn1-4.12 contains a DoS, specifically CPU usage will reach 100% when running asn1Paser against the POC due to an issue in _asn1_expand_object_id(p_tree), after a long time, the program will be killed. This attack appears to be exploitable via parsing a crafted file.

    Published: 12 Aug 2018
    7.5
    High

    CVE-2018-7166

    Last Modified: 21 Nov 2024

    In all versions of Node.js 10 prior to 10.9.0, an argument processing flaw can cause `Buffer.alloc()` to return uninitialized memory. This method is intended to be safe and only return initialized, or cleared, memory. The third argument specifying `encoding` can be passed as a number, this is misinterpreted by `Buffer's` internal "fill" method as the `start` to a fill operation. This flaw may be abused where `Buffer.alloc()` arguments are derived from user input to return uncleared memory blocks that may contain sensitive information.

    Published: 11 Aug 2018
    7.5
    High

    CVE-2018-12115

    Last Modified: 21 Nov 2024

    In all versions of Node.js prior to 6.14.4, 8.11.4 and 10.9.0 when used with UCS-2 encoding (recognized by Node.js under the names `'ucs2'`, `'ucs-2'`, `'utf16le'` and `'utf-16le'`), `Buffer#write()` can be abused to write outside of the bounds of a single `Buffer`. Writes that start from the second-to-last position of a buffer cause a miscalculation of the maximum length of the input bytes to be written.

    Published: 11 Aug 2018