CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-13014

    Last Modified: 21 Nov 2024

    Storing password in recoverable format in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.2 allows the local attacker to restore the SysWatch password from the settings database and modify program settings.

    Published: 29 Jun 2018
    7.8
    High

    CVE-2018-8901

    Last Modified: 21 Nov 2024

    An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have enabled LDAP authentication in their configuration.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-13011

    Last Modified: 21 Nov 2024

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Validate.

    Published: 29 Jun 2018
    7.8
    High

    CVE-2018-13013

    Last Modified: 21 Nov 2024

    Improper check of unusual conditions when launching msiexec.exe in safensec.com (SysWatch service) in SAFE'N'SEC SoftControl/SafenSoft SysWatch, SoftControl/SafenSoft TPSecure, and SoftControl/SafenSoft Enterprise Suite before 4.4.9 allows the local attacker to bypass a code-signing protection mechanism and install/execute an unauthorized program by modifying the system configuration and installing a forged MSI file. (The intended behavior is that the component SysWatch does not allow installation of MSI files unless they are signed by a limited list of certificates.)

    Published: 29 Jun 2018
    6.5
    Medium

    CVE-2018-8902

    Last Modified: 21 Nov 2024

    An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This discovered key can be used for all instances of the product.

    Published: 29 Jun 2018
    6.1
    Medium

    CVE-2018-13001

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Sandoba CP:Shop v2016.1. The vulnerability is located in the `admin.php` file of the `./cpshop/` module. Remote attackers are able to inject their own script codes to the client-side requested vulnerable web-application parameters. The attack vector of the vulnerability is non-persistent and the request method to inject/execute is GET with the path, search, rename, or dir parameter.

    Published: 29 Jun 2018
    4.8
    Medium

    CVE-2018-13002

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Inhaltsprojekte in Weblication CMS Core & Grid v12.6.24. The vulnerability is located in the `wFilemanager.php` and `index.php` files of the `/grid5/scripts/` modules. The injection point is located in the Project `Title` and the execution point occurs in the `Inhaltsprojekte` output listing section. Remote attackers with privileged user accounts are able to inject their own malicious script code with a persistent attack vector to compromise user session credentials or to manipulate the affected web-application module output context. The request method to inject is POST.

    Published: 29 Jun 2018
    6.1
    Medium

    CVE-2018-13003

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'type' to the /suggest URI.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-13005

    Last Modified: 21 Nov 2024

    An issue was discovered in MP4Box in GPAC 0.7.1. The function urn_Read in isomedia/box_code_base.c has a heap-based buffer over-read.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-13009

    Last Modified: 21 Nov 2024

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (conditional on a buffer_size_longs check).

    Published: 29 Jun 2018
    8.8
    High

    CVE-2018-13010

    Last Modified: 21 Nov 2024

    WSTMall v1.9.1_170316 has CSRF via the index.php?m=Admin&c=Users&a=edit URI to add a user account.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-13007

    Last Modified: 21 Nov 2024

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for GPMF_KEY_END and nest_level (not conditional on a buffer_size_longs check).

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-13006

    Last Modified: 21 Nov 2024

    An issue was discovered in MP4Box in GPAC 0.7.1. There is a heap-based buffer over-read in the isomedia/box_dump.c function hdlr_dump.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-13008

    Last Modified: 21 Nov 2024

    An issue was discovered in gpmf-parser 1.1.2. There is a heap-based buffer over-read in GPMF_parser.c in the function GPMF_Next, related to certain checks for a positive nest_level.

    Published: 29 Jun 2018
    4.8
    Medium

    CVE-2018-13000

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Advanced Electron Forum (AEF) v1.0.9. A persistent XSS vulnerability is located in the `FTP Link` element of the `Private Message` module. The editor of the private message module allows inserting links without sanitizing the content. This allows remote attackers to inject malicious script code payloads as a private message (aka pmbody). The injection point is the editor ftp link element and the execution point occurs in the message body context on arrival. The request method to inject is POST with restricted user privileges.

    Published: 29 Jun 2018
    8.8
    High

    CVE-2018-12995

    Last Modified: 21 Nov 2024

    onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen.

    Published: 29 Jun 2018
    6.1
    Medium

    CVE-2018-12996

    Last Modified: 21 Nov 2024

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager before 13 (Build 13800) allows remote attackers to inject arbitrary web script or HTML via the parameter 'method' to GraphicalView.do.

    Published: 29 Jun 2018
    7.5
    High

    CVE-2018-12997

    Last Modified: 21 Nov 2024

    Incorrect Access Control in FailOverHelperServlet in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows attackers to read certain files on the web server without login by sending a specially crafted request to the server with the operation=copyfile&fileName= substring.

    Published: 29 Jun 2018
    6.1
    Medium

    CVE-2018-12998

    Last Modified: 21 Nov 2024

    A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Netflow Analyzer before build 123137, Network Configuration Manager before build 123128, OpManager before build 123148, OpUtils before build 123161, and Firewall Analyzer before build 123147 allows remote attackers to inject arbitrary web script or HTML via the parameter 'operation' to /servlet/com.adventnet.me.opmanager.servlet.FailOverHelperServlet.

    Published: 29 Jun 2018
    4.8
    Medium

    CVE-2018-12992

    Last Modified: 21 Nov 2024

    An issue was discovered CMS MaeloStore V.1.5.0. There is stored XSS in the Telephone field of the admin interface.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-12993

    Last Modified: 21 Nov 2024

    onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to conduct brute-force attacks via the onefilecms_username and onefilecms_password fields.

    Published: 29 Jun 2018
    8.8
    High

    CVE-2018-12994

    Last Modified: 21 Nov 2024

    onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen.

    Published: 29 Jun 2018
    7.5
    High

    CVE-2018-12999

    Last Modified: 21 Nov 2024

    Incorrect Access Control in AgentTrayIconServlet in Zoho ManageEngine Desktop Central 10.0.255 allows attackers to delete certain files on the web server without login by sending a specially crafted request to the server with a computerName=../ substring to the /agenttrayicon URI.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-12972

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenTSDB 2.3.0. Many parameters to the /q URI can execute commands, including o, key, style, and yrange and y2range and their JSON input.

    Published: 29 Jun 2018
    6.1
    Medium

    CVE-2018-12973

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenTSDB 2.3.0. There is XSS in parameter 'json' to the /q URI.

    Published: 29 Jun 2018
    5.5
    Medium

    CVE-2018-12982

    Last Modified: 21 Nov 2024

    Invalid memory read in the PoDoFo::PdfVariant::DelayedLoad() function in PdfVariant.h in PoDoFo 0.9.6-rc1 allows remote attackers to have denial-of-service impact via a crafted file.

    Published: 29 Jun 2018
    7.8
    High

    CVE-2018-12983

    Last Modified: 21 Nov 2024

    A stack-based buffer over-read in the PdfEncryptMD5Base::ComputeEncryptionKey() function in PdfEncrypt.cpp in PoDoFo 0.9.6-rc1 could be leveraged by remote attackers to cause a denial-of-service via a crafted pdf file.

    Published: 29 Jun 2018
    9.8
    Critical

    CVE-2018-12984

    Last Modified: 21 Nov 2024

    Hycus CMS 1.0.4 allows Authentication Bypass via "'=' 'OR'" credentials.

    Published: 29 Jun 2018
    6.5
    Medium

    CVE-2018-12971

    Last Modified: 21 Nov 2024

    EasyCMS 1.3 has CSRF via the index.php?s=/admin/user/delAll URI to delete users.

    Published: 29 Jun 2018
    7.5
    High

    CVE-2018-12988

    Last Modified: 21 Nov 2024

    GreenCMS 2.3.0603 has an arbitrary file download vulnerability via an index.php?m=admin&c=media&a=downfile URI.

    Published: 29 Jun 2018
    7.8
    High

    CVE-2018-10874

    Last Modified: 21 Nov 2024

    In ansible it was found that inventory variables are loaded from current working directory when running ad-hoc command which are under attacker's control, allowing to run arbitrary code as a result.

    Published: 29 Jun 2018
    7.5
    High

    CVE-2018-18074

    Last Modified: 21 Nov 2024

    The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

    Published: 29 Jun 2018
    7.8
    High

    CVE-2018-10875

    Last Modified: 21 Nov 2024

    A flaw was found in ansible. ansible.cfg is read from the current working directory which can be altered to make it point to a plugin or a module path under the control of an attacker, thus allowing the attacker to execute arbitrary code.

    Published: 29 Jun 2018
    8.1
    High

    CVE-2018-8039

    Last Modified: 21 Nov 2024

    It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.

    Published: 29 Jun 2018
    4.8
    Medium

    CVE-2018-1351

    Last Modified: 21 Nov 2024

    A Cross-site Scripting (XSS) vulnerability in Fortinet FortiManager 6.0.0, 5.6.6 and below versions allows attacker to execute HTML/javascript code via managed remote devices CLI commands by viewing the remote device CLI config installation log.

    Published: 28 Jun 2018
    7.8
    High

    CVE-2018-12589

    Last Modified: 21 Nov 2024

    Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory.

    Published: 28 Jun 2018
    9.8
    Critical

    CVE-2018-12932

    Last Modified: 21 Nov 2024

    PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact by triggering a large pAlphaBlend->cbBitsSrc value.

    Published: 28 Jun 2018
    9.8
    Critical

    CVE-2018-12933

    Last Modified: 21 Nov 2024

    PlayEnhMetaFileRecord in enhmetafile.c in Wine 3.7 allows attackers to cause a denial of service (out-of-bounds write) or possibly have unspecified other impact because the attacker controls the pCreatePen->ihPen array index.

    Published: 28 Jun 2018
    6.5
    Medium

    CVE-2017-16859

    Last Modified: 21 Nov 2024

    The review attachment resource in Atlassian Fisheye and Crucible before version 4.3.2, from version 4.4.0 before 4.4.3 and before version 4.5.0 allows remote attackers to read files contained within context path of the running application through a path traversal vulnerability in the command parameter.

    Published: 28 Jun 2018
    9.8
    Critical

    CVE-2018-11510

    Last Modified: 21 Nov 2024

    The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.

    Published: 28 Jun 2018
    7.5
    High

    CVE-2018-12920

    Last Modified: 21 Nov 2024

    Brickstream 2300 devices allow remote attackers to obtain potentially sensitive information via a direct request for the basic.html#ipsettings or basic.html#datadelivery URI.

    Published: 28 Jun 2018
    7.5
    High

    CVE-2018-12922

    Last Modified: 21 Nov 2024

    Emerson Liebert IntelliSlot Web Card devices allow remote attackers to reconfigure access control via the config/configUser.htm or config/configTelnet.htm URI.

    Published: 28 Jun 2018
    7.5
    High

    CVE-2018-12923

    Last Modified: 21 Nov 2024

    BWS Systems HA-Bridge devices allow remote attackers to obtain potentially sensitive information via a direct request for the #!/system URI.

    Published: 28 Jun 2018
    9.8
    Critical

    CVE-2018-12925

    Last Modified: 21 Nov 2024

    Baseon Lantronix MSS devices do not require a password for TELNET access.

    Published: 28 Jun 2018
    7.5
    High

    CVE-2018-12927

    Last Modified: 21 Nov 2024

    Northern Electric & Power (NEP) inverter devices allow remote attackers to obtain potentially sensitive information via a direct request for the nep/status/index/1 URI.

    Published: 28 Jun 2018
    7.5
    High

    CVE-2018-12921

    Last Modified: 21 Nov 2024

    Electro Industries GaugeTech Nexus devices allow remote attackers to obtain potentially sensitive information via a direct request for the meter_information.htm, diag_system.htm, or diag_dnp_lan_wan.htm URI.

    Published: 28 Jun 2018
    9.8
    Critical

    CVE-2018-12924

    Last Modified: 21 Nov 2024

    Sollae Serial-Ethernet-Module and Remote-I/O-Device-Server devices have a default password of sollae for the TELNET service.

    Published: 28 Jun 2018
    7.5
    High

    CVE-2018-12926

    Last Modified: 21 Nov 2024

    Pharos Controls devices allow remote attackers to obtain potentially sensitive information via a direct request for the default/index.lsp or default/log.lsp URI.

    Published: 28 Jun 2018
    8.6
    High

    CVE-2018-12938

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17833. Reason: This candidate is a duplicate of CVE-2017-17833. Notes: All CVE users should reference CVE-2017-17833 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 28 Jun 2018
    5.4
    Medium

    CVE-2018-10860

    Last Modified: 21 Nov 2024

    perl-archive-zip is vulnerable to a directory traversal in Archive::Zip. It was found that the Archive::Zip module did not properly sanitize paths while extracting zip files. An attacker able to provide a specially crafted archive for processing could use this flaw to write or overwrite arbitrary files in the context of the perl interpreter.

    Published: 28 Jun 2018