CVE Feed

    Dashboard / CVE

    7.2
    High

    CVE-2018-1000527

    Last Modified: 21 Nov 2024

    Froxlor version <= 0.9.39.5 contains a PHP Object Injection vulnerability in Domain name form that can result in Possible information disclosure and remote code execution. This attack appear to be exploitable via Passing malicious PHP objection in $_POST['ssl_ipandport']. This vulnerability appears to have been fixed in after commit c1e62e6.

    Published: 26 Jun 2018
    7.5
    High

    CVE-2018-1000531

    Last Modified: 21 Nov 2024

    inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-1000540

    Last Modified: 21 Nov 2024

    LoboEvolution version < 9b75694cedfa4825d4a2330abf2719d470c654cd contains a XML External Entity (XXE) vulnerability in XML Parsing when viewing the XML file in the browser that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted XML file.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-1000546

    Last Modified: 21 Nov 2024

    Triplea version <= 1.9.0.0.10291 contains a XML External Entity (XXE) vulnerability in Importing game data that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted game data file (XML).

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-1000548

    Last Modified: 21 Nov 2024

    Umlet version < 14.3 contains a XML External Entity (XXE) vulnerability in File parsing that can result in disclosure of confidential data, denial of service, server side request forgery. This attack appear to be exploitable via Specially crafted UXF file. This vulnerability appears to have been fixed in 14.3.

    Published: 26 Jun 2018
    6.5
    Medium

    CVE-2018-1000558

    Last Modified: 21 Nov 2024

    OCS Inventory NG ocsreports 2.4 and ocsreports 2.3.1 version 2.4 and 2.3.1 contains a SQL Injection vulnerability in web search that can result in An authenticated attacker is able to gain full access to data stored within database. This attack appear to be exploitable via By sending crafted requests it is possible to gain database access. This vulnerability appears to have been fixed in 2.4.1.

    Published: 26 Jun 2018
    4.8
    Medium

    CVE-2018-1000508

    Last Modified: 21 Nov 2024

    WP ULike version 2.8.1, 3.1 contains a Cross Site Scripting (XSS) vulnerability in Settings screen that can result in allows unauthorised users to do almost anything an admin can. This attack appear to be exploitable via Admin must visit logs page. This vulnerability appears to have been fixed in 3.2.

    Published: 26 Jun 2018
    4.3
    Medium

    CVE-2018-1000503

    Last Modified: 21 Nov 2024

    MyBB Group MyBB contains a Incorrect Access Control vulnerability in Private forums that can result in Users can view posts from private forums without having the password. This attack appear to be exploitable via Subscribe to a forum through IDOR. This vulnerability appears to have been fixed in 1.8.15.

    Published: 26 Jun 2018
    6.5
    Medium

    CVE-2018-1000507

    Last Modified: 21 Nov 2024

    WP User Groups version 2.0.0 contains a Cross ite Request Forgery (CSRF) vulnerability in Settings page that can result in allows anybody to modify user groups and types. This attack appear to be exploitable via Admin must click on link. This vulnerability appears to have been fixed in 2.1.1.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-1000528

    Last Modified: 21 Nov 2024

    GONICUS GOsa version before commit 56070d6289d47ba3f5918885954dcceb75606001 contains a Cross Site Scripting (XSS) vulnerability in change password form (html/password.php, #308) that can result in injection of arbitrary web script or HTML. This attack appear to be exploitable via the victim must open a specially crafted web page. This vulnerability appears to have been fixed in after commit 56070d6289d47ba3f5918885954dcceb75606001.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-1000534

    Last Modified: 21 Nov 2024

    Joplin version prior to 1.0.90 contains a XSS evolving into code execution due to enabled nodeIntegration for that particular BrowserWindow instance where XSS was identified from vulnerability in Note content field - information on the fix can be found here https://github.com/laurent22/joplin/commit/494e235e18659574f836f84fcf9f4d4fcdcfcf89 that can result in executing unauthorized code within the rights in which the application is running. This attack appear to be exploitable via Victim synchronizing notes from the cloud services or other note-keeping services which contain malicious code. This vulnerability appears to have been fixed in 1.0.90 and later.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-1000536

    Last Modified: 21 Nov 2024

    Medis version 0.6.1 and earlier contains a XSS vulnerability evolving into code execution due to enabled nodeIntegration for the renderer process vulnerability in Key name parameter on new key creation that can result in Unauthorized code execution in the victim's machine, within the rights of the running application. This attack appear to be exploitable via Victim is synchronizing data from the redis server which contains malicious key value.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-1000542

    Last Modified: 21 Nov 2024

    netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted MMD file.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-1000543

    Last Modified: 21 Nov 2024

    Akiee version 0.0.3 contains a XSS leading to code execution due to the use of node integration vulnerability in "Details" of a task is not validated that can result in XSS leading to abritrary code execution. This attack appear to be exploitable via The attacker tricks the victim into opening a crafted markdown.

    Published: 26 Jun 2018
    5.3
    Medium

    CVE-2018-1000547

    Last Modified: 21 Nov 2024

    coreBOS version 7.0 and earlier contains a Incorrect Access Control vulnerability in Module: Contacts that can result in The error allows you to access records that you have no permissions to. .

    Published: 26 Jun 2018
    5.3
    Medium

    CVE-2018-1000549

    Last Modified: 21 Nov 2024

    Wekan version 1.04.0 contains a Email / Username Enumeration vulnerability in Register' and 'Forgot your password?' pages that can result in A remote attacker could perform a brute force attack to obtain valid usernames and email addresses.. This attack appear to be exploitable via HTTP Request.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-1000556

    Last Modified: 21 Nov 2024

    WordPress version 4.8 + contains a Cross Site Scripting (XSS) vulnerability in plugins.php or core wordpress on delete function that can result in An attacker can perform client side attacks which could be from stealing a cookie to code injection. This attack appear to be exploitable via an attacker must craft an URL with payload and send to the user. Victim need to open the link to be affected by reflected XSS. .

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-1000559

    Last Modified: 21 Nov 2024

    qutebrowser version introduced in v0.11.0 (1179ee7a937fb31414d77d9970bac21095358449) contains a Cross Site Scripting (XSS) vulnerability in history command, qute://history page that can result in Via injected JavaScript code, a website can steal the user's browsing history. This attack appear to be exploitable via the victim must open a page with a specially crafted <title> attribute, and then open the qute://history site via the :history command. This vulnerability appears to have been fixed in fixed in v1.3.3 (4c9360237f186681b1e3f2a0f30c45161cf405c7, to be released today) and v1.4.0 (5a7869f2feaa346853d2a85413d6527c87ef0d9f, released later this week).

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0557

    Last Modified: 21 Nov 2024

    Stored cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'E-mail Details Screen' via unspecified vectors.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0558

    Last Modified: 21 Nov 2024

    Reflected cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML in 'System settings' via unspecified vectors.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0559

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Mailwise 5.0.0 to 5.4.1 allows remote attackers to inject arbitrary web script or HTML 'Address' via unspecified vectors.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0565

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Office 10.0.0 to 10.8.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2018
    4.3
    Medium

    CVE-2018-0566

    Last Modified: 21 Nov 2024

    Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass authentication to obtain the schedules without access privilege via unspecified vectors.

    Published: 26 Jun 2018
    6.3
    Medium

    CVE-2018-0567

    Last Modified: 21 Nov 2024

    Cybozu Office 10.0.0 to 10.8.0 allows authenticated attackers to bypass access restriction to access and write non-public data via unspecified vectors.

    Published: 26 Jun 2018
    5.4
    Medium

    CVE-2018-0570

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2018
    4.3
    Medium

    CVE-2018-0571

    Last Modified: 21 Nov 2024

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers with a site operator privilege to upload arbitrary files.

    Published: 26 Jun 2018
    8.1
    High

    CVE-2018-0572

    Last Modified: 21 Nov 2024

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote authenticated attackers to bypass access restriction to view or alter a restricted content via unspecified vectors.

    Published: 26 Jun 2018
    5.3
    Medium

    CVE-2018-0573

    Last Modified: 21 Nov 2024

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction for a content to view a file which is uploaded by a site user via unspecified vectors.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0574

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2018
    5.3
    Medium

    CVE-2018-0575

    Last Modified: 21 Nov 2024

    baserCMS (baserCMS 4.1.0.1 and earlier versions, baserCMS 3.0.15 and earlier versions) allows remote attackers to bypass access restriction in mail form to view a file which is uploaded by a site user via unspecified vectors.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0592

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0593

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Microsoft OneDrive allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0594

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0595

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Skype for Windows allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0596

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Visual Studio Community allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0597

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Visual Studio Code allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0599

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of Visual C++ Redistributable allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0600

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in the installer of PlayMemories Home for Windows ver.5.5.01 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0601

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in axpdfium v0.01 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.2
    High

    CVE-2018-0604

    Last Modified: 21 Nov 2024

    Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.

    Published: 26 Jun 2018
    9.8
    Critical

    CVE-2018-0608

    Last Modified: 21 Nov 2024

    Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.

    Published: 26 Jun 2018
    7.8
    High

    CVE-2018-0609

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 26 Jun 2018
    7.4
    High

    CVE-2018-0611

    Last Modified: 21 Nov 2024

    The ANA App for iOS version 4.0.22 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0612

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in 5000 trillion yen converter v1.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2018
    4.3
    Medium

    CVE-2018-0528

    Last Modified: 21 Nov 2024

    Cybozu Office 10.0.0 to 10.7.0 allows authenticated attackers to bypass authentication to view the schedules that are not permitted to access via unspecified vectors.

    Published: 26 Jun 2018
    4.3
    Medium

    CVE-2018-0529

    Last Modified: 21 Nov 2024

    Cybozu Office 10.0.0 to 10.7.0 allows remote attackers to cause a denial of service via unspecified vectors.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0602

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2018
    6.1
    Medium

    CVE-2018-0605

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 26 Jun 2018
    7.2
    High

    CVE-2018-0610

    Last Modified: 21 Nov 2024

    Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.

    Published: 26 Jun 2018
    4.3
    Medium

    CVE-2018-0526

    Last Modified: 21 Nov 2024

    Cybozu Office 10.0.0 to 10.7.0 allow remote attackers to display an image located in an external server via unspecified vectors.

    Published: 26 Jun 2018