CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-13134

    Last Modified: 21 Nov 2024

    TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.

    Published: 4 Jul 2018
    4.3
    Medium

    CVE-2018-12374

    Last Modified: 21 Nov 2024

    Plaintext of decrypted emails can leak through by user submitting an embedded form by pressing enter key within a text input field. This vulnerability affects Thunderbird < 52.9.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13128

    Last Modified: 21 Nov 2024

    Etherty Token (ETY) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13130

    Last Modified: 21 Nov 2024

    Bitotal (TFUND) is a smart contract running on Ethereum. The mintTokens function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13132

    Last Modified: 21 Nov 2024

    Spadeico is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13144

    Last Modified: 21 Nov 2024

    The transfer and transferFrom functions of a smart contract implementation for Pandora (PDX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-14436

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-4 has a memory leak in ReadMIFFImage in coders/miff.c.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-11335

    Last Modified: 21 Nov 2024

    GVToken Genesis Vision (GVT) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-10885

    Last Modified: 21 Nov 2024

    In atomic-openshift before version 3.10.9 a malicious network-policy configuration can cause Openshift Routing to crash when using ovs-networkpolicy plugin. An attacker can use this flaw to cause a Denial of Service (DoS) attack on an Openshift 3.9, or 3.7 Cluster.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13126

    Last Modified: 21 Nov 2024

    MoxyOnePresale is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13127

    Last Modified: 21 Nov 2024

    SP8DE PreSale Token (DSPX) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13129

    Last Modified: 21 Nov 2024

    SP8DE Token (SPX) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-13153

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.8-4, there is a memory leak in the XMagickCommand function in MagickCore/animate.c.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-14434

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-4 has a memory leak for a colormap in WriteMPCImage in coders/mpc.c.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-11429

    Last Modified: 21 Nov 2024

    ATLANT (ATL) is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-12372

    Last Modified: 21 Nov 2024

    Decrypted S/MIME parts, when included in HTML crafted for an attack, can leak plaintext when included in a a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

    Published: 4 Jul 2018
    7.5
    High

    CVE-2018-13131

    Last Modified: 21 Nov 2024

    SpadePreSale is a smart contract running on Ethereum. The mint function has an integer overflow that allows minted tokens to be arbitrarily retrieved by the contract owner.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-14435

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-4 has a memory leak in DecodeImage in coders/pcd.c.

    Published: 4 Jul 2018
    6.5
    Medium

    CVE-2018-14437

    Last Modified: 21 Nov 2024

    ImageMagick 7.0.8-4 has a memory leak in parse8BIM in coders/meta.c.

    Published: 4 Jul 2018
    5.5
    Medium

    CVE-2018-13121

    Last Modified: 21 Nov 2024

    RealOne Player 2.0 Build 6.0.11.872 allows remote attackers to cause a denial of service (array out-of-bounds access and application crash) via a crafted .aiff file.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-13123

    Last Modified: 21 Nov 2024

    onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to read arbitrary files via the i and f parameters, as demonstrated by ?i=etc/&f=passwd&p=raw_view for the /etc/passwd file.

    Published: 3 Jul 2018
    6.5
    Medium

    CVE-2018-13122

    Last Modified: 21 Nov 2024

    onefilecms.php in OneFileCMS through 2017-10-08 might allow attackers to delete arbitrary files via the Delete File(s) screen, as demonstrated by a ?i=var/www/html/&f=123.php&p=edit&p=deletefile URI.

    Published: 3 Jul 2018
    6.1
    Medium

    CVE-2018-3747

    Last Modified: 21 Nov 2024

    The public node module versions <= 1.0.3 allows to embed HTML in file names, which (in certain conditions) might lead to execute malicious JavaScript.

    Published: 3 Jul 2018
    6.1
    Medium

    CVE-2018-3748

    Last Modified: 21 Nov 2024

    There is a Stored XSS vulnerability in the glance node module versions <= 3.0.5. File name, which contains malicious HTML (eg. embedded iframe element or javascript: pseudo-protocol handler in <a> element) allows to execute JavaScript code against any user who opens a directory listing containing such crafted file name.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-3749

    Last Modified: 21 Nov 2024

    The utilities function in all versions < 1.0.1 of the deap node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

    Published: 3 Jul 2018
    8.8
    High

    CVE-2018-3754

    Last Modified: 21 Nov 2024

    Node.js third-party module query-mysql versions 0.0.0, 0.0.1, and 0.0.2 are vulnerable to an SQL injection vulnerability due to lack of user input sanitization. This may allow an attacker to run arbitrary SQL queries when fetching data from database.

    Published: 3 Jul 2018
    5.5
    Medium

    CVE-2018-9242

    Last Modified: 21 Nov 2024

    The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier may allow an attacker to delete files in the system via specific request parameters.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2018-9335

    Last Modified: 21 Nov 2024

    The PAN-OS session browser in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.9 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2018-9337

    Last Modified: 21 Nov 2024

    The PAN-OS web interface administration page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.17 and earlier, PAN-OS 8.0.10 and earlier, and PAN-OS 8.1.1 and earlier may allow an attacker to inject arbitrary JavaScript or HTML.

    Published: 3 Jul 2018
    4.7
    Medium

    CVE-2017-0913

    Last Modified: 21 Nov 2024

    Ubiquiti UCRM versions 2.3.0 to 2.7.7 allow an authenticated user to read arbitrary files in the local file system. Note that by default, the local file system is isolated in a docker container. Successful exploitation requires valid credentials to an account with "Edit" access to "System Customization".

    Published: 3 Jul 2018
    8.1
    High

    CVE-2017-0921

    Last Modified: 21 Nov 2024

    GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an unverified password change issue in the PasswordsController component resulting in potential account takeover if a victim's session is compromised.

    Published: 3 Jul 2018
    7.5
    High

    CVE-2017-0929

    Last Modified: 21 Nov 2024

    DNN (aka DotNetNuke) before 9.2.0 suffers from a Server-Side Request Forgery (SSRF) vulnerability in the DnnImageHandler class. Attackers may be able to access information about internal network resources.

    Published: 3 Jul 2018
    5.5
    Medium

    CVE-2018-9334

    Last Modified: 21 Nov 2024

    The PAN-OS management web interface page in PAN-OS 6.1.20 and earlier, PAN-OS 7.1.16 and earlier, PAN-OS 8.0.8 and earlier, and PAN-OS 8.1.0 may allow an attacker to access the GlobalProtect password hashes of local users via manipulation of the HTML markup.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-3752

    Last Modified: 21 Nov 2024

    The utilities function in all versions <= 1.0.0 of the merge-options node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-0912

    Last Modified: 21 Nov 2024

    Ubiquiti UCRM versions 2.5.0 to 2.7.7 are vulnerable to Stored Cross-site Scripting. Due to the lack sanitization, it is possible to inject arbitrary HTML code by manipulating the uploaded filename. Successful exploitation requires valid credentials to an account with "Edit" access to "Scheduling".

    Published: 3 Jul 2018
    7.5
    High

    CVE-2017-0919

    Last Modified: 21 Nov 2024

    GitLab Community and Enterprise Editions before 10.1.6, 10.2.6, and 10.3.4 are vulnerable to an authorization bypass issue in the GitLab import component resulting in an attacker being able to perform operations under a group in which they were previously unauthorized.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-3751

    Last Modified: 21 Nov 2024

    The utilities function in all versions <= 0.3.0 of the merge-recursive node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-3753

    Last Modified: 21 Nov 2024

    The utilities function in all versions <= 1.0.0 of the merge-objects node module can be tricked into modifying the prototype of Object when the attacker can control part of the structure passed to this function. This can let an attacker add or modify existing properties that will exist on all objects.

    Published: 3 Jul 2018
    6.1
    Medium

    CVE-2018-7636

    Last Modified: 21 Nov 2024

    The URL filtering "continue page" hosted by PAN-OS 8.0.10 and earlier may allow an attacker to inject arbitrary JavaScript or HTML via specially crafted URLs.

    Published: 3 Jul 2018
    9.8
    Critical

    CVE-2018-13116

    Last Modified: 21 Nov 2024

    /user/del.php in zzcms 8.3 allows SQL injection via the tablename parameter after leveraging use of the zzcms_ask table.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1568

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 131778.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1250

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force 124630.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1316

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125728.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1293

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125154.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1312

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125723.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1317

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125729.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1651

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 133261.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1690

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 134065.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1280

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 124758.

    Published: 3 Jul 2018
    5.4
    Medium

    CVE-2017-1294

    Last Modified: 21 Nov 2024

    IBM Rational Quality Manager and IBM Rational Collaborative Lifecycle Management 5.0 through 5.0.2 and 6.0 through 6.0.5 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 125155.

    Published: 3 Jul 2018