CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-14493

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.

    Published: 25 Jul 2018
    5.5
    Medium

    CVE-2018-1002206

    Last Modified: 5 Jun 2026

    SharpCompress before 0.21.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 25 Jul 2018
    5.5
    Medium

    CVE-2018-1002203

    Last Modified: 21 Nov 2024

    unzipper npm library before 0.8.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 25 Jul 2018
    5.5
    Medium

    CVE-2018-1002207

    Last Modified: 21 Nov 2024

    mholt/archiver golang package before e4ef56d48eb029648b0e895bb0b6a393ef0829c3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 25 Jul 2018
    5.5
    Medium

    CVE-2018-1002209

    Last Modified: 21 Nov 2024

    QuaZIP before 0.7.6 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 25 Jul 2018
    5.5
    Medium

    CVE-2018-1002208

    Last Modified: 21 Nov 2024

    SharpZipLib before 1.0 RC1 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 25 Jul 2018
    5.5
    Medium

    CVE-2018-1002205

    Last Modified: 6 May 2025

    DotNetZip.Semvered before 1.11.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published: 25 Jul 2018
    8
    High

    CVE-2018-5240

    Last Modified: 21 Nov 2024

    The Inventory Plugin for Symantec Management Agent prior to 7.6 POST HF7, 8.0 POST HF6, or 8.1 RU7 may be susceptible to a privilege escalation vulnerability, which is a type of issue that allows a user to gain elevated access to resources that are normally protected at lower access levels.

    Published: 25 Jul 2018
    7.5
    High

    CVE-2017-10936

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in all versions prior to V4.01.01 of the ZTE ZXCDN-SNS product allows remote attackers to execute arbitrary SQL commands via the aoData parameter, resulting in the disclosure of database information.

    Published: 25 Jul 2018
    7.2
    High

    CVE-2017-10935

    Last Modified: 21 Nov 2024

    All versions prior to ZSRV2 V3.00.40 of the ZTE ZXR10 1800-2S products allow remote authenticated users to bypass the original password authentication protection to change other user's password.

    Published: 25 Jul 2018
    9.8
    Critical

    CVE-2017-10934

    Last Modified: 21 Nov 2024

    All versions prior to V5.09.02.02T4 of the ZTE ZXIPTV-EPG product use the Java RMI service in which the servers use the Apache Commons Collections (ACC) library that may result in Java deserialization vulnerabilities. An unauthenticated remote attacker can exploit the vulnerabilities by sending a crafted RMI request to execute arbitrary code on the target host.

    Published: 25 Jul 2018
    7.5
    High

    CVE-2017-10937

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in all versions prior to V2.01.05.09 of the ZTE ZXIPTV-UCM product allows remote attackers to execute arbitrary SQL commands via the opertype parameter, resulting in the disclosure of database information.

    Published: 25 Jul 2018
    5.3
    Medium

    CVE-2018-14432

    Last Modified: 21 Nov 2024

    In the Federation component of OpenStack Keystone before 11.0.4, 12.0.0, and 13.0.0, an authenticated "GET /v3/OS-FEDERATION/projects" request may bypass intended access restrictions on listing projects. An authenticated user may discover projects they have no authority to access, leaking all projects in the deployment and their attributes. Only Keystone with the /v3/OS-FEDERATION endpoint enabled via policy.json is affected.

    Published: 25 Jul 2018
    7.5
    High

    CVE-2018-5530

    Last Modified: 21 Nov 2024

    F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, or 11.6.0-11.6.3.1 virtual servers with HTTP/2 profiles enabled are vulnerable to "HPACK Bomb".

    Published: 25 Jul 2018
    7.5
    High

    CVE-2018-5536

    Last Modified: 21 Nov 2024

    A remote attacker via undisclosed measures, may be able to exploit an F5 BIG-IP APM 13.0.0-13.1.0.7 or 12.1.0-12.1.3.5 virtual server configured with an APM per-request policy object and cause a memory leak in the APM module.

    Published: 25 Jul 2018
    3.7
    Low

    CVE-2018-5538

    Last Modified: 21 Nov 2024

    On F5 BIG-IP DNS 13.1.0-13.1.0.7, 12.1.3-12.1.3.5, DNS Express / DNS Zones accept NOTIFY messages on the management interface from source IP addresses not listed in the 'Allow NOTIFY From' configuration parameter when the db variable "dnsexpress.notifyport" is set to any value other than the default of "0".

    Published: 25 Jul 2018
    7.5
    High

    CVE-2018-5541

    Last Modified: 21 Nov 2024

    When F5 BIG-IP ASM 13.0.0-13.1.0.1, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.5.1-11.5.6 is processing HTTP requests, an unusually large number of parameters can cause excessive CPU usage in the BIG-IP ASM bd process.

    Published: 25 Jul 2018
    7.5
    High

    CVE-2018-5539

    Last Modified: 21 Nov 2024

    Under certain conditions, on F5 BIG-IP ASM 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, 11.5.1-11.5.6, or 11.2.1, when processing CSRF protections, the BIG-IP ASM bd process may restart and produce a core file.

    Published: 25 Jul 2018
    8.1
    High

    CVE-2018-5542

    Last Modified: 21 Nov 2024

    F5 BIG-IP 13.0.0-13.0.1, 12.1.0-12.1.3.6, or 11.2.1-11.6.3.2 HTTPS health monitors do not validate the identity of the monitored server.

    Published: 25 Jul 2018
    7.4
    High

    CVE-2018-5531

    Last Modified: 21 Nov 2024

    Through undisclosed methods, on F5 BIG-IP 13.0.0-13.1.0.7, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6, adjacent network attackers can cause a denial of service for VCMP guest and host systems. Attack must be sourced from adjacent network (layer 2).

    Published: 25 Jul 2018
    5.3
    Medium

    CVE-2018-5537

    Last Modified: 21 Nov 2024

    A remote attacker may be able to disrupt services on F5 BIG-IP 13.0.0-13.1.0.5, 12.1.0-12.1.3.5, 11.6.0-11.6.3.1, or 11.2.1-11.5.6 if the TMM virtual server is configured with a HTML or a Rewrite profile. TMM may restart while processing some specially prepared HTML content from the back end.

    Published: 25 Jul 2018
    9.8
    Critical

    CVE-2018-11491

    Last Modified: 21 Nov 2024

    ASUS HG100 devices with firmware before 1.05.12 allow unauthenticated access, leading to remote command execution.

    Published: 25 Jul 2018
    7.8
    High

    CVE-2018-6971

    Last Modified: 21 Nov 2024

    VMware Horizon View Agents (7.x.x before 7.5.1) contain a local information disclosure vulnerability due to insecure logging of credentials in the vmmsi.log file when an account other than the currently logged on user is specified during installation (including silent installations). Successful exploitation of this issue may allow low privileged users access to the credentials specified during the Horizon View Agent installation.

    Published: 25 Jul 2018
    6.5
    Medium

    CVE-2018-6972

    Last Modified: 21 Nov 2024

    VMware ESXi (6.7 before ESXi670-201806401-BG, 6.5 before ESXi650-201806401-BG, 6.0 before ESXi600-201806401-BG and 5.5 before ESXi550-201806401-BG), Workstation (14.x before 14.1.2), and Fusion (10.x before 10.1.2) contain a denial-of-service vulnerability due to NULL pointer dereference issue in RPC handler. Successful exploitation of this issue may allow attackers with normal user privileges to crash their VMs.

    Published: 25 Jul 2018
    7.5
    High

    CVE-2018-14596

    Last Modified: 21 Nov 2024

    wancms 1.0 through 5.0 allows remote attackers to cause a denial of service (resource consumption) via a checkcode (aka verification code) URI in which the values of font_size, width, and height are large numbers.

    Published: 25 Jul 2018
    7.8
    High

    CVE-2018-14678

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.11, as used in Xen through 4.11.x. The xen_failsafe_callback entry point in arch/x86/entry/entry_64.S does not properly maintain RBX, which allows local users to cause a denial of service (uninitialized memory usage and system crash). Within Xen, 64-bit x86 PV Linux guest OS users can trigger a guest OS crash or possibly gain privileges.

    Published: 25 Jul 2018
    8.1
    High

    CVE-2018-14348

    Last Modified: 21 Nov 2024

    libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.

    Published: 25 Jul 2018
    8.8
    High

    CVE-2018-11060

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.4.0.1, contain an authorization bypass vulnerability in the REST API. A remote authenticated malicious Archer user could potentially exploit this vulnerability to elevate their privileges.

    Published: 24 Jul 2018
    6.5
    Medium

    CVE-2018-11044

    Last Modified: 21 Nov 2024

    Pivotal Apps Manager included in Pivotal Application Service, versions 2.2.x prior to 2.2.1 and 2.1.x prior to 2.1.8 and 2.0.x prior to 2.0.17 and 1.12.x prior to 1.12.26, does not escape all user-provided content when sending invitation emails. A malicious authenticated user can inject content into an invite to another user, exploiting the trust implied by the source of the email.

    Published: 24 Jul 2018
    7.5
    High

    CVE-2018-11047

    Last Modified: 21 Nov 2024

    Cloud Foundry UAA, versions 4.19 prior to 4.19.2 and 4.12 prior to 4.12.4 and 4.10 prior to 4.10.2 and 4.7 prior to 4.7.6 and 4.5 prior to 4.5.7, incorrectly authorizes requests to admin endpoints by accepting a valid refresh token in lieu of an access token. Refresh tokens by design have a longer expiration time than access tokens, allowing the possessor of a refresh token to authenticate longer than expected. This affects the administrative endpoints of the UAA. i.e. /Users, /Groups, etc. However, if the user has been deleted or had groups removed, or the client was deleted, the refresh token will no longer be valid.

    Published: 24 Jul 2018
    8.2
    High

    CVE-2018-11059

    Last Modified: 21 Nov 2024

    RSA Archer, versions prior to 6.4.0.1, contain a stored cross-site scripting vulnerability. A remote authenticated malicious Archer user could potentially exploit this vulnerability to store malicious HTML or JavaScript code in a trusted application data store. When application users access the corrupted data store through their browsers, the malicious code gets executed by the web browser in the context of the vulnerable web application.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2018-10628

    Last Modified: 21 Nov 2024

    AVEVA InTouch 2014 R2 SP1 and prior, InTouch 2017, InTouch 2017 Update 1, and InTouch 2017 Update 2 allow an unauthenticated user to send a specially crafted packet that could overflow the buffer on a locale not using a dot floating point separator. Exploitation could allow remote code execution under the privileges of the InTouch View process.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2018-8859

    Last Modified: 2 Jun 2026

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can bypass the required authentication specified in the security configuration file by including extra characters in the directory name when specifying the directory to be accessed. This vulnerability does not affect the i.LON 600 product.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2018-8855

    Last Modified: 2 Jun 2026

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices allow unencrypted Web connections by default, and devices can receive configuration and firmware updates by unsecure FTP.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2018-8851

    Last Modified: 2 Jun 2026

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. The devices store passwords in plaintext, which may allow an attacker with access to the configuration file to log into the SmartServer web user interface.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2018-10627

    Last Modified: 2 Jun 2026

    Echelon SmartServer 1 all versions, SmartServer 2 all versions prior to release 4.11.007, i.LON 100 all versions, and i.LON 600 all versions. An attacker can use the SOAP API to retrieve and change sensitive configuration items such as the usernames and passwords for the Web and FTP servers. This vulnerability does not affect the i.LON 600 product.

    Published: 24 Jul 2018
    7.5
    High

    CVE-2018-10632

    Last Modified: 21 Nov 2024

    In Moxa NPort 5210, 5230, and 5232 versions 2.9 build 17030709 and prior, the amount of resources requested by a malicious actor are not restricted, allowing for a denial-of-service condition.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14582

    Last Modified: 21 Nov 2024

    index.php?r=admini/admin/create in BageCMS V3.1.3 allows CSRF to add a background administrator account.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14585

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. AP4_BytesToUInt16BE in Core/Ap4Utils.h has a heap-based buffer over-read after a call from the AP4_Stz2Atom class.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14587

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. AP4_MemoryByteStream::WritePartial in Core/Ap4ByteStream.cpp has a buffer over-read.

    Published: 24 Jul 2018
    7.5
    High

    CVE-2018-14588

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. A NULL pointer dereference can occur in AP4_DataBuffer::SetData in Core/Ap4DataBuffer.cpp.

    Published: 24 Jul 2018
    7.5
    High

    CVE-2018-14590

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Processor::ProcessFragments in Core/Ap4Processor.cpp.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14583

    Last Modified: 21 Nov 2024

    xyhai.php?s=/Auth/addUser in XYHCMS 3.5 allows CSRF to add a background administrator account.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14584

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. AP4_AvccAtom::Create in Core/Ap4AvccAtom.cpp has a heap-based buffer over-read.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14586

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. A SEGV can occur in AP4_Mpeg2TsAudioSampleStream::WriteSample in Core/Ap4Mpeg2Ts.cpp, a different vulnerability than CVE-2018-14532.

    Published: 24 Jul 2018
    8.8
    High

    CVE-2018-14589

    Last Modified: 21 Nov 2024

    An issue has been discovered in Bento4 1.5.1-624. AP4_Mp4AudioDsiParser::ReadBits in Codecs/Ap4Mp4AudioInfo.cpp has a heap-based buffer over-read.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2018-5384

    Last Modified: 21 Nov 2024

    Navarino Infinity web interface up to version 2.2 exposes an unauthenticated script that is prone to blind sql injection. If successfully exploited the user can get info from the underlying postgresql database that could lead into to total compromise of the product. The said script is available with no authentication.

    Published: 24 Jul 2018
    7.5
    High

    CVE-2018-5387

    Last Modified: 21 Nov 2024

    Wizkunde SAMLBase may incorrectly utilize the results of XML DOM traversal and canonicalization APIs in such a way that an attacker may be able to manipulate the SAML data without invalidating the cryptographic signature, allowing the attack to potentially bypass authentication to SAML service providers.

    Published: 24 Jul 2018
    9.8
    Critical

    CVE-2017-3181

    Last Modified: 21 Nov 2024

    Multiple TIBCO Products are prone to multiple unspecified SQL-injection vulnerabilities because it fails to properly sanitize user-supplied input before using it in an SQL query. Exploiting these issues could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. The following products and versions are affected: TIBCO Spotfire Analyst 7.7.0 TIBCO Spotfire Connectors 7.6.0 TIBCO Spotfire Deployment Kit 7.7.0 TIBCO Spotfire Desktop 7.6.0 TIBCO Spotfire Desktop 7.7.0 TIBCO Spotfire Desktop Developer Edition 7.7.0 TIBCO Spotfire Desktop Language Packs 7.6.0 TIBCO Spotfire Desktop Language Packs 7.7.0 The following components are affected: TIBCO Spotfire Client TIBCO Spotfire Web Player Client

    Published: 24 Jul 2018
    8.8
    High

    CVE-2017-3187

    Last Modified: 21 Nov 2024

    The dotCMS administration panel, versions 3.7.1 and earlier, are vulnerable to cross-site request forgery. The dotCMS administrator panel contains a cross-site request forgery (CSRF) vulnerability. An attacker can perform actions with the same permissions as a victim user, provided the victim has an active session and is induced to trigger the malicious request. An unauthenticated remote attacker may perform actions with the dotCMS administrator panel with the same permissions of a victim user or execute arbitrary system commands with the permissions of the user running the dotCMS application.

    Published: 24 Jul 2018