CVE Feed

    Dashboard / CVE

    8.8
    High

    CVE-2018-15197

    Last Modified: 21 Nov 2024

    An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges.

    Published: 8 Aug 2018
    8.8
    High

    CVE-2018-15198

    Last Modified: 21 Nov 2024

    An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/User/add.html that can add a user.

    Published: 8 Aug 2018
    5.4
    Medium

    CVE-2018-15199

    Last Modified: 21 Nov 2024

    AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.

    Published: 8 Aug 2018
    8.6
    High

    CVE-2018-15192

    Last Modified: 21 Nov 2024

    An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.

    Published: 8 Aug 2018
    8.8
    High

    CVE-2018-15193

    Last Modified: 21 Nov 2024

    A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.

    Published: 8 Aug 2018
    7.8
    High

    CVE-2018-15175

    Last Modified: 21 Nov 2024

    XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified other impact via a crafted RLE file.

    Published: 8 Aug 2018
    6.1
    Medium

    CVE-2018-15178

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.

    Published: 8 Aug 2018
    9.8
    Critical

    CVE-2018-15168

    Last Modified: 21 Nov 2024

    A SQL Injection vulnerability exists in the Zoho ManageEngine Applications Manager 13 before build 13820 via the resids parameter in a /editDisplaynames.do?method=editDisplaynames GET request.

    Published: 8 Aug 2018
    7.8
    High

    CVE-2018-15174

    Last Modified: 21 Nov 2024

    XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO file.

    Published: 8 Aug 2018
    7.8
    High

    CVE-2018-15176

    Last Modified: 21 Nov 2024

    XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact via a crafted RLE file.

    Published: 8 Aug 2018
    8.8
    High

    CVE-2018-15177

    Last Modified: 21 Nov 2024

    In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.

    Published: 8 Aug 2018
    8.8
    High

    CVE-2013-7464

    Last Modified: 21 Nov 2024

    In csrf-magic before 1.0.4, if $GLOBALS['csrf']['secret'] is not configured, the Anti-CSRF Token used is predictable and would permit an attacker to bypass the CSRF protections, because an automatically generated secret is not used.

    Published: 8 Aug 2018
    6.5
    Medium

    CVE-2018-10908

    Last Modified: 21 Nov 2024

    It was found that vdsm before version 4.20.37 invokes qemu-img on untrusted inputs without limiting resources. By uploading a specially crafted image, an attacker could cause the qemu-img process to consume unbounded amounts of memory of CPU time, causing a denial of service condition that could potentially impact other users of the host.

    Published: 8 Aug 2018
    6.1
    Medium

    CVE-2018-15169

    Last Modified: 21 Nov 2024

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.

    Published: 8 Aug 2018
    6.5
    Medium

    CVE-2018-14526

    Last Modified: 21 Nov 2024

    An issue was discovered in rsn_supp/wpa.c in wpa_supplicant 2.0 through 2.6. Under certain conditions, the integrity of EAPOL-Key messages is not checked, leading to a decryption oracle. An attacker within range of the Access Point and client can abuse the vulnerability to recover sensitive information.

    Published: 8 Aug 2018
    9.8
    Critical

    CVE-2018-15137

    Last Modified: 21 Nov 2024

    CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.

    Published: 8 Aug 2018
    5.8
    Medium

    CVE-2018-11456

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4). An attacker with network access to the device could send specially crafted network packets to determine whether or not a network port on another remote system is accessible or not. This allows the attacker to do basic network scanning using the victims machine. Successful exploitation requires a network connection to the affected device. The attacker does not need privileges, no user interaction is required. The impact is limited to determining whether or not a port on a target system is accessible by the affected device.

    Published: 7 Aug 2018
    5.9
    Medium

    CVE-2018-12885

    Last Modified: 21 Nov 2024

    The randMod() function of the smart contract implementation for MyCryptoChamp, an Ethereum game, generates a random value with publicly readable variables such as the current block information and a private variable, (which can be read with a getStorageAt call). Therefore, attackers can get powerful champs/items and get rewards.

    Published: 7 Aug 2018
    7.5
    High

    CVE-2018-15132

    Last Modified: 21 Nov 2024

    An issue was discovered in ext/standard/link_win32.c in PHP before 5.6.37, 7.0.x before 7.0.31, 7.1.x before 7.1.20, and 7.2.x before 7.2.8. The linkinfo function on Windows doesn't implement the open_basedir check. This could be abused to find files on paths outside of the allowed directories.

    Published: 7 Aug 2018
    7.8
    High

    CVE-2018-11453

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to insert specially crafted files which may prevent TIA Portal startup (Denial-of-Service) or lead to local code execution. No special privileges are required, but the victim needs to attempt to start TIA Portal after the manipulation.

    Published: 7 Aug 2018
    8.6
    High

    CVE-2018-11454

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V10, V11, V12 (All versions), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V13 (All versions < V13 SP2 Update 2), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V14 (All versions < V14 SP1 Update 6), SIMATIC STEP 7 (TIA Portal) and WinCC (TIA Portal) V15 (All versions < V15 Update 2). Improper file permissions in the default installation of TIA Portal may allow an attacker with local file system access to manipulate resources which may be transferred to devices and executed there by a different user. No special privileges are required, but the victim needs to transfer the manipulated files to a device. Execution is caused on the target device rather than on the PG device.

    Published: 7 Aug 2018
    8.8
    High

    CVE-2018-11455

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Automation License Manager 5 (All versions < 5.3.4.4), Automation License Manager 6 (All versions < 6.0.1). A directory traversal vulnerability could allow a remote attacker to move arbitrary files, which can result in code execution, compromising confidentiality, integrity and availability of the system. Successful exploitation requires a network connection to the affected device. The attacker does not need privileges or special conditions of the system, but user interaction is required.

    Published: 7 Aug 2018
    5.4
    Medium

    CVE-2018-15130

    Last Modified: 21 Nov 2024

    ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.

    Published: 7 Aug 2018
    5.4
    Medium

    CVE-2018-1690

    Last Modified: 21 Nov 2024

    IBM Rhapsody Model Manager 6.0.6 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 145510.

    Published: 7 Aug 2018
    5.4
    Medium

    CVE-2018-15129

    Last Modified: 21 Nov 2024

    ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.

    Published: 7 Aug 2018
    7.5
    High

    CVE-2018-15501

    Last Modified: 21 Nov 2024

    In ng_pkt in transports/smart_pkt.c in libgit2 before 0.26.6 and 0.27.x before 0.27.4, a remote attacker can send a crafted smart-protocol "ng" packet that lacks a '\0' byte to trigger an out-of-bounds read that leads to DoS.

    Published: 7 Aug 2018
    8.8
    High

    CVE-2018-16335

    Last Modified: 21 Nov 2024

    newoffsets handling in ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf. This is a different vulnerability than CVE-2018-15209.

    Published: 7 Aug 2018
    5.5
    Medium

    CVE-2018-5953

    Last Modified: 21 Nov 2024

    The swiotlb_print_info function in lib/swiotlb.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "software IO TLB" printk call.

    Published: 7 Aug 2018
    5.5
    Medium

    CVE-2018-5995

    Last Modified: 21 Nov 2024

    The pcpu_embed_first_chunk function in mm/percpu.c in the Linux kernel through 4.14.14 allows local users to obtain sensitive address information by reading dmesg data from a "pages/cpu" printk call.

    Published: 7 Aug 2018
    8.8
    High

    CVE-2018-15209

    Last Modified: 21 Nov 2024

    ChopUpSingleUncompressedStrip in tif_dirread.c in LibTIFF 4.0.9 allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecified other impact via a crafted TIFF file, as demonstrated by tiff2pdf.

    Published: 7 Aug 2018
    5.4
    Medium

    CVE-2018-14869

    Last Modified: 21 Nov 2024

    PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.

    Published: 6 Aug 2018
    5.9
    Medium

    CVE-2017-16653

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The current implementation of CSRF protection in Symfony (Version >=2) does not use different tokens for HTTP and HTTPS; therefore the token is subject to MITM attacks on HTTP and can then be used in an HTTPS context to do CSRF attacks.

    Published: 6 Aug 2018
    6.5
    Medium

    CVE-2017-16790

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. When a form is submitted by the user, the request handler classes of the Form component merge POST data and uploaded files data into one array. This big array forms the data that are then bound to the form. At this stage there is no difference anymore between submitted POST data and uploaded files. A user can send a crafted HTTP request where the value of a "FileType" is sent as normal POST data that could be interpreted as a local file path on the server-side (for example, "file:///etc/passwd"). If the application did not perform any additional checks about the value submitted to the "FileType", the contents of the given file on the server could have been exposed to the attacker.

    Published: 6 Aug 2018
    8.1
    High

    CVE-2017-16252

    Last Modified: 21 Nov 2024

    Specially crafted commands sent through the PubNub service in Insteon Hub 2245-222 with firmware version 1012 can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an authenticated HTTP request to trigger this vulnerability.At 0x9d014cc0 the value for the cmd key is copied using strcpy to the buffer at $sp+0x11c. This buffer is 20 bytes large, sending anything longer will cause a buffer overflow.

    Published: 6 Aug 2018
    7.5
    High

    CVE-2017-16654

    Last Modified: 21 Nov 2024

    An issue was discovered in Symfony before 2.7.38, 2.8.31, 3.2.14, 3.3.13, 3.4-BETA5, and 4.0-BETA5. The Intl component includes various bundle readers that are used to read resource bundles from the local filesystem. The read() methods of these classes use a path and a locale to determine the language bundle to retrieve. The locale argument value is commonly retrieved from untrusted user input (like a URL parameter). An attacker can use this argument to navigate to arbitrary directories via the dot-dot-slash attack, aka Directory Traversal.

    Published: 6 Aug 2018
    8.8
    High

    CVE-2018-14857

    Last Modified: 21 Nov 2024

    Unrestricted file upload (with remote code execution) in require/mail/NotificationMail.php in Webconsole in OCS Inventory NG OCS Inventory Server through 2.5 allows a privileged user to gain access to the server via a template file containing PHP code, because file extensions other than .html are permitted.

    Published: 6 Aug 2018
    8.8
    High

    CVE-2018-7060

    Last Modified: 21 Nov 2024

    Aruba ClearPass 6.6.x prior to 6.6.9 and 6.7.x prior to 6.7.1 is vulnerable to CSRF attacks against authenticated users. An attacker could manipulate an authenticated user into performing actions on the web administrative interface.

    Published: 6 Aug 2018
    6.1
    Medium

    CVE-2018-7068

    Last Modified: 21 Nov 2024

    HPE has identified a remote HOST header attack vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

    Published: 6 Aug 2018
    5.3
    Medium

    CVE-2018-7070

    Last Modified: 21 Nov 2024

    HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.

    Published: 6 Aug 2018
    4.3
    Medium

    CVE-2018-7071

    Last Modified: 21 Nov 2024

    HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.

    Published: 6 Aug 2018
    9.8
    Critical

    CVE-2018-7072

    Last Modified: 21 Nov 2024

    A remote bypass of security restrictions vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

    Published: 6 Aug 2018
    5.5
    Medium

    CVE-2018-7073

    Last Modified: 21 Nov 2024

    A local arbitrary file modification vulnerability was identified in HPE Moonshot Provisioning Manager prior to v1.24.

    Published: 6 Aug 2018
    9.8
    Critical

    CVE-2018-7074

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT 7.3 E0506P07. The vulnerability was resolved in iMC PLAT 7.3 E0605P04 or subsequent version.

    Published: 6 Aug 2018
    6.1
    Medium

    CVE-2018-7075

    Last Modified: 21 Nov 2024

    A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version v7.3 (E0506). The vulnerability is fixed in Intelligent Management Center PLAT 7.3 E0605P04 or subsequent version.

    Published: 6 Aug 2018
    7.2
    High

    CVE-2018-7078

    Last Modified: 21 Nov 2024

    A remote code execution was identified in HPE Integrated Lights-Out 4 (iLO 4) earlier than version v2.60 and HPE Integrated Lights-Out 5 (iLO 5) earlier than version v1.30.

    Published: 6 Aug 2018
    7.5
    High

    CVE-2018-7092

    Last Modified: 21 Nov 2024

    A potential security vulnerability has been identified in HPE Intelligent Management Center Platform (IMC Plat) 7.3 E0506P09. The vulnerability could be remotely exploited to allow for remote directory traversal leading to arbitrary file deletion.

    Published: 6 Aug 2018
    8.8
    High

    CVE-2016-8526

    Last Modified: 21 Nov 2024

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to an XML external entities (XXE). XXEs are a way to permit XML parsers to access storage that exist on external systems. If an unprivileged user is permitted to control the contents of XML files, XXE can be used as an attack vector. Because the XML parser has access to the local filesystem and runs with the permissions of the web server, it can access any file that is readable by the web server and copy it to an external system of the attacker's choosing. This could include files that contain passwords, which could then lead to privilege escalation.

    Published: 6 Aug 2018
    8.8
    High

    CVE-2016-4398

    Last Modified: 21 Nov 2024

    A remote arbitrary code execution vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10 using Java Deserialization.

    Published: 6 Aug 2018
    6.1
    Medium

    CVE-2016-4406

    Last Modified: 21 Nov 2024

    A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.

    Published: 6 Aug 2018
    6.1
    Medium

    CVE-2016-8527

    Last Modified: 21 Nov 2024

    Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into AirWave in the same browser.

    Published: 6 Aug 2018