CVE Feed

    Dashboard / CVE

    9.9
    Critical

    CVE-2018-3110

    Last Modified: 21 Nov 2024

    A vulnerability was discovered in the Java VM component of Oracle Database Server. Supported versions that are affected are 11.2.0.4, 12.1.0.2, 12.2.0.1 and 18. Easily exploitable vulnerability allows low privileged attacker having Create Session privilege with network access via Oracle Net to compromise Java VM. While the vulnerability is in Java VM, attacks may significantly impact additional products. Successful attacks of this vulnerability can result in takeover of Java VM. CVSS 3.0 Base Score 9.9 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H).

    Published: 10 Aug 2018
    9.8
    Critical

    CVE-2018-3779

    Last Modified: 21 Nov 2024

    active-support ruby gem 5.2.0 could allow a remote attacker to execute arbitrary code on the system, caused by containing a malicious backdoor. An attacker could exploit this vulnerability to execute arbitrary code on the system.

    Published: 10 Aug 2018
    7.8
    High

    CVE-2018-11063

    Last Modified: 21 Nov 2024

    Dell WMS versions 1.1 and prior are impacted by multiple unquoted service path vulnerabilities. Affected software installs multiple services incorrectly by specifying the paths to the service executables without quotes. This could potentially allow a low-privileged local user to execute arbitrary executables with elevated privileges.

    Published: 10 Aug 2018
    8.1
    High

    CVE-2018-11048

    Last Modified: 21 Nov 2024

    Dell EMC Data Protection Advisor, versions 6.2, 6,3, 6.4, 6.5 and Dell EMC Integrated Data Protection Appliance (IDPA) versions 2.0, 2.1 contain a XML External Entity (XXE) Injection vulnerability in the REST API. An authenticated remote malicious user could potentially exploit this vulnerability to read certain system files in the server or cause denial of service by supplying specially crafted Document Type Definitions (DTDs) in an XML request.

    Published: 10 Aug 2018
    7.5
    High

    CVE-2018-14782

    Last Modified: 21 Nov 2024

    NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device allows access to configuration files and profiles without authenticating the user.

    Published: 10 Aug 2018
    8.8
    High

    CVE-2018-14783

    Last Modified: 21 Nov 2024

    NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. A cross-site request forgery condition can occur, allowing an attacker to change passwords of the device remotely.

    Published: 10 Aug 2018
    6.1
    Medium

    CVE-2018-14784

    Last Modified: 21 Nov 2024

    NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The device is vulnerable to several cross-site scripting attacks, allowing a remote attacker to run arbitrary code on the device.

    Published: 10 Aug 2018
    7.5
    High

    CVE-2018-14785

    Last Modified: 21 Nov 2024

    NetComm Wireless G LTE Light Industrial M2M Router (NWL-25) with firmware 2.0.29.11 and prior. The directory of the device is listed openly without authentication.

    Published: 10 Aug 2018
    9.8
    Critical

    CVE-2018-10630

    Last Modified: 21 Nov 2024

    For Crestron TSW-X60 version prior to 2.001.0037.001 and MC3 version prior to 1.502.0047.001, The devices are shipped with authentication disabled, and there is no indication to users that they need to take steps to enable it. When compromised, the access to the CTP console is left open.

    Published: 10 Aug 2018
    8.8
    High

    CVE-2018-13341

    Last Modified: 21 Nov 2024

    Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.

    Published: 10 Aug 2018
    5.2
    Medium

    CVE-2018-10622

    Last Modified: 22 Jun 2026

    Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials for network authentication.

    Published: 10 Aug 2018
    4.4
    Medium

    CVE-2018-10626

    Last Modified: 19 May 2026

    Medtronic MyCareLink Patient Monitor’s update service does not sufficiently verify the authenticity of the data uploaded. An attacker who obtains per-product credentials from the monitor and paired implantable cardiac device information can potentially upload invalid data to the Medtronic CareLink network.

    Published: 10 Aug 2018
    5.4
    Medium

    CVE-2018-15190

    Last Modified: 21 Nov 2024

    PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.

    Published: 10 Aug 2018
    6.5
    Medium

    CVE-2018-15191

    Last Modified: 21 Nov 2024

    PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.

    Published: 10 Aug 2018
    4.3
    Medium

    CVE-2018-10932

    Last Modified: 21 Nov 2024

    lldptool version 1.0.1 and older can print a raw, unsanitized attacker controlled buffer when mngAddr information is displayed. This may allow an attacker to inject shell control characters into the buffer and impact the behavior of the terminal.

    Published: 10 Aug 2018
    6.1
    Medium

    CVE-2018-14503

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.

    Published: 10 Aug 2018
    4.8
    Medium

    CVE-2018-14837

    Last Modified: 21 Nov 2024

    Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.

    Published: 10 Aug 2018
    7.5
    High

    CVE-2018-11492

    Last Modified: 21 Nov 2024

    ASUS HG100 devices allow denial of service via an IPv4 packet flood.

    Published: 10 Aug 2018
    7.2
    High

    CVE-2018-14028

    Last Modified: 21 Nov 2024

    In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but the PHP file remains in a predictable wp-content/uploads location, allowing for an attacker to then execute the file. This represents a security risk in limited scenarios where an attacker (who does have the required capabilities for plugin uploads) cannot simply place arbitrary PHP code into a valid plugin ZIP file and upload that plugin, because a machine's wp-content/plugins directory permissions were set up to block all new plugins.

    Published: 10 Aug 2018
    8.8
    High

    CVE-2018-15186

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Chartered Accountant : Auditor Website 2.0.1 has CSRF via client/auditor/updprofile.php.

    Published: 10 Aug 2018
    6.5
    Medium

    CVE-2018-15188

    Last Modified: 21 Nov 2024

    PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile.

    Published: 10 Aug 2018
    6.1
    Medium

    CVE-2018-13390

    Last Modified: 21 Nov 2024

    Unauthenticated access to cloudtoken daemon on Linux via network from version 0.1.1 before version 0.1.24 allows attackers on the same subnet to gain temporary AWS credentials for the users' roles.

    Published: 10 Aug 2018
    6.5
    Medium

    CVE-2018-15185

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PHP and JavaScript code in the "Current Position" field.

    Published: 10 Aug 2018
    8
    High

    CVE-2018-15187

    Last Modified: 21 Nov 2024

    PHP Scripts Mall advanced-real-estate-script 4.0.9 has CSRF via edit-profile.php.

    Published: 10 Aug 2018
    5.4
    Medium

    CVE-2018-15189

    Last Modified: 21 Nov 2024

    PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.

    Published: 10 Aug 2018
    7.5
    High

    CVE-2018-10769

    Last Modified: 21 Nov 2024

    The transferProxy and approveProxy functions of a smart contract implementation for SmartMesh (SMT), an Ethereum ERC20 token, allow attackers to accomplish an unauthorized transfer of digital assets because replay attacks can occur with the same-named functions (with the same signatures) in other tokens: First (FST), GG Token (GG), M2C Mesh Network (MTC), M2C Mesh Network (mesh), and UG Token (UGT).

    Published: 10 Aug 2018
    3.3
    Low

    CVE-2018-6556

    Last Modified: 21 Nov 2024

    lxc-user-nic when asked to delete a network interface will unconditionally open a user provided path. This code path may be used by an unprivileged user to check for the existence of a path which they wouldn't otherwise be able to reach. It may also be used to trigger side effects by causing a (read-only) open of special kernel files (ptmx, proc, sys). Affected releases are LXC: 2.0 versions above and including 2.0.9; 3.0 versions above and including 3.0.0, prior to 3.0.2.

    Published: 10 Aug 2018
    6.1
    Medium

    CVE-2018-20676

    Last Modified: 21 Nov 2024

    In Bootstrap before 3.4.0, XSS is possible in the tooltip data-viewport attribute.

    Published: 10 Aug 2018
    6.1
    Medium

    CVE-2018-20677

    Last Modified: 21 Nov 2024

    In Bootstrap before 3.4.0, XSS is possible in the affix configuration target property.

    Published: 10 Aug 2018
    7.5
    High

    CVE-2018-7686

    Last Modified: 21 Nov 2024

    Information leakage vulnerability in NetIQ eDirectory before 9.1.1 HF1 due to shared memory usage.

    Published: 9 Aug 2018
    6.1
    Medium

    CVE-2018-7692

    Last Modified: 21 Nov 2024

    Unvalidated redirect vulnerability in in NetIQ eDirectory before 9.1.1 HF1.

    Published: 9 Aug 2018
    7.8
    High

    CVE-2018-0429

    Last Modified: 26 Nov 2024

    Stack-based buffer overflow in the Cisco Thor decoder before commit 18de8f9f0762c3a542b1122589edb8af859d9813 allows local users to cause a denial of service (segmentation fault) and execute arbitrary code via a crafted non-conformant Thor bitstream.

    Published: 9 Aug 2018
    7.5
    High

    CVE-2018-14735

    Last Modified: 21 Nov 2024

    An Information Exposure issue was discovered in Hitachi Command Suite 8.5.3. A remote attacker may be able to exploit a flaw in the permission of messaging that may allow for information exposure via a crafted message.

    Published: 9 Aug 2018
    8.1
    High

    CVE-2018-15133

    Last Modified: 7 Nov 2025

    In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

    Published: 9 Aug 2018
    6.5
    Medium

    CVE-2018-15181

    Last Modified: 21 Nov 2024

    JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Security Key fields.

    Published: 9 Aug 2018
    5.4
    Medium

    CVE-2018-15182

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.

    Published: 9 Aug 2018
    6.1
    Medium

    CVE-2018-15183

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Myperfectresume / JobHero / Resume Clone Script 2.0.6 has Stored XSS via the Full Name and Title fields.

    Published: 9 Aug 2018
    5.4
    Medium

    CVE-2018-15184

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to CVE-2018-6795.

    Published: 9 Aug 2018
    5.3
    Medium

    CVE-2018-6922

    Last Modified: 21 Nov 2024

    One of the data structures that holds TCP segments in all versions of FreeBSD prior to 11.2-RELEASE-p1, 11.1-RELEASE-p12, and 10.4-RELEASE-p10 uses an inefficient algorithm to reassemble the data. This causes the CPU time spent on segment processing to grow linearly with the number of segments in the reassembly queue. An attacker who has the ability to send TCP traffic to a victim system can degrade the victim system's network performance and/or consume excessive CPU by exploiting the inefficiency of TCP reassembly handling, with relatively small bandwidth cost.

    Published: 9 Aug 2018
    8.5
    High

    CVE-2018-10915

    Last Modified: 21 Nov 2024

    A vulnerability was found in libpq, the default PostgreSQL client library where libpq failed to properly reset its internal state between connections. If an affected version of libpq was used with "host" or "hostaddr" connection parameters from untrusted input, attackers could bypass client-side connection security features, obtain access to higher privileged connections or potentially cause other impact through SQL injection, by causing the PQescape() functions to malfunction. Postgresql versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 are affected.

    Published: 9 Aug 2018
    8.1
    High

    CVE-2018-10925

    Last Modified: 21 Nov 2024

    It was discovered that PostgreSQL versions before 10.5, 9.6.10, 9.5.14, 9.4.19, and 9.3.24 failed to properly check authorization on certain statements involved with "INSERT ... ON CONFLICT DO UPDATE". An attacker with "CREATE TABLE" privileges could exploit this to read arbitrary bytes server memory. If the attacker also had certain "INSERT" and limited "UPDATE" privileges to a particular table, they could exploit this to update other columns in the same table.

    Published: 9 Aug 2018
    9.8
    Critical

    CVE-2018-10931

    Last Modified: 21 Nov 2024

    It was found that cobbler 2.6.x exposed all functions from its CobblerXMLRPCInterface class over XMLRPC. A remote, unauthenticated attacker could use this flaw to gain high privileges within cobbler, upload files to arbitrary location in the context of the daemon.

    Published: 9 Aug 2018
    5.5
    Medium

    CVE-2018-7754

    Last Modified: 21 Nov 2024

    The aoedisk_debugfs_show function in drivers/block/aoe/aoeblk.c in the Linux kernel through 4.16.4rc4 allows local users to obtain sensitive address information by reading "ffree: " lines in a debugfs file.

    Published: 9 Aug 2018
    7.5
    High

    CVE-2018-5740

    Last Modified: 21 Nov 2024

    "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

    Published: 8 Aug 2018
    5.3
    Medium

    CVE-2018-3778

    Last Modified: 21 Nov 2024

    Improper authorization in aedes version <0.35.0 will publish a LWT in a channel when a client is not authorized.

    Published: 8 Aug 2018
    7.5
    High

    CVE-2018-11561

    Last Modified: 21 Nov 2024

    An integer overflow in the unprotected distributeToken function of a smart contract implementation for EETHER (EETHER), an Ethereum ERC20 token, will lead to an unauthorized increase of an attacker's digital assets.

    Published: 8 Aug 2018
    7.2
    High

    CVE-2018-11769

    Last Modified: 21 Nov 2024

    CouchDB administrative users before 2.2.0 can configure the database server via HTTP(S). Due to insufficient validation of administrator-supplied configuration settings via the HTTP API, it is possible for a CouchDB administrator user to escalate their privileges to that of the operating system's user under which CouchDB runs, by bypassing the blacklist of configuration settings that are not allowed to be modified via the HTTP API. This privilege escalation effectively allows a CouchDB admin user to gain arbitrary remote code execution, bypassing CVE-2017-12636 and CVE-2018-8007.

    Published: 8 Aug 2018
    7.5
    High

    CVE-2018-12408

    Last Modified: 21 Nov 2024

    The BusinessWorks engine component of TIBCO Software Inc.'s TIBCO ActiveMatrix BusinessWorks, TIBCO ActiveMatrix BusinessWorks for z/Linux, and TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric contains a vulnerability that may allow XML eXternal Entity (XXE) attacks via incoming network messages, and may disclose the contents of files accessible to a running BusinessWorks engine Affected releases are TIBCO Software Inc. TIBCO ActiveMatrix BusinessWorks: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks for z/Linux: versions up to and including 5.13.0, TIBCO ActiveMatrix BusinessWorks Distribution for TIBCO Silver Fabric: versions up to and including 5.13.0.

    Published: 8 Aug 2018
    6.3
    Medium

    CVE-2018-15202

    Last Modified: 21 Nov 2024

    An issue was discovered in Juunan06 eCommerce through 2018-08-05. There is a CSRF vulnerability in ee/eBoutique/app/template/includes/crudTreatment.php that can add new users and add products.

    Published: 8 Aug 2018
    6.5
    Medium

    CVE-2018-15203

    Last Modified: 21 Nov 2024

    An issue was discovered in Ignited CMS through 2017-02-19. ign/index.php/admin/pages/add_page allows a CSRF attack to add pages.

    Published: 8 Aug 2018