CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-12534

    Last Modified: 21 Nov 2024

    A SQL injection issue was discovered in the Quick Chat plugin before 4.00 for WordPress.

    Published: 18 Jun 2018
    7.4
    High

    CVE-2018-1153

    Last Modified: 21 Nov 2024

    Burp Suite Community Edition 1.7.32 and 1.7.33 fail to validate the server certificate in a couple of HTTPS requests which allows a man in the middle to modify or view traffic.

    Published: 18 Jun 2018
    5.3
    Medium

    CVE-2018-12522

    Last Modified: 21 Nov 2024

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.

    Published: 18 Jun 2018
    5.3
    Medium

    CVE-2018-12523

    Last Modified: 21 Nov 2024

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.

    Published: 18 Jun 2018
    5.3
    Medium

    CVE-2018-12524

    Last Modified: 21 Nov 2024

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.

    Published: 18 Jun 2018
    5.3
    Medium

    CVE-2018-12525

    Last Modified: 21 Nov 2024

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.

    Published: 18 Jun 2018
    6.5
    Medium

    CVE-2018-14404

    Last Modified: 3 Dec 2025

    A NULL pointer dereference vulnerability exists in the xpath.c:xmlXPathCompOpEval() function of libxml2 through 2.9.8 when parsing an invalid XPath expression in the XPATH_OP_AND or XPATH_OP_OR case. Applications processing untrusted XSL format inputs with the use of the libxml2 library may be vulnerable to a denial of service attack due to a crash of the application.

    Published: 18 Jun 2018
    8.8
    High

    CVE-2018-12538

    Last Modified: 21 Nov 2024

    In Eclipse Jetty versions 9.4.0 through 9.4.8, when using the optional Jetty provided FileSessionDataStore for persistent storage of HttpSession details, it is possible for a malicious user to access/hijack other HttpSessions and even delete unmatched HttpSessions present in the FileSystem's storage for the FileSessionDataStore.

    Published: 18 Jun 2018
    3.8
    Low

    CVE-2018-10871

    Last Modified: 21 Nov 2024

    389-ds-base before versions 1.3.8.5, 1.4.0.12 is vulnerable to a Cleartext Storage of Sensitive Information. By default, when the Replica and/or retroChangeLog plugins are enabled, 389-ds-base stores passwords in plaintext format in their respective changelog files. An attacker with sufficiently high privileges, such as root or Directory Manager, can query these files in order to retrieve plaintext passwords.

    Published: 18 Jun 2018
    9.8
    Critical

    CVE-2018-12071

    Last Modified: 9 Jun 2025

    A Session Fixation issue exists in CodeIgniter before 3.1.9 because session.use_strict_mode in the Session Library was mishandled.

    Published: 17 Jun 2018
    9.8
    Critical

    CVE-2018-12072

    Last Modified: 21 Nov 2024

    An issue was discovered in Cloud Media Popcorn A-200 03-05-130708-21-POP-411-000 firmware. It is configured to provide TELNET remote access (without a password) that pops a shell as root. If an attacker can connect to port 23 on the device, he can completely compromise it.

    Published: 17 Jun 2018
    5.3
    Medium

    CVE-2018-12073

    Last Modified: 21 Nov 2024

    An issue was discovered on Eminent EM4544 9.10 devices. The device does not require the user's current password to set a new one within the web interface. Therefore, it is possible to exploit this issue (e.g., in combination with a successful XSS, or at an unattended workstation) to change the admin password to an attacker-chosen value without knowing the current password.

    Published: 17 Jun 2018
    Unknown

    CVE-2016-1000013

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2016-10531. Reason: This candidate is a reservation duplicate of CVE-2016-10531. Notes: All CVE users should reference CVE-2016-10531 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 17 Jun 2018
    6.1
    Medium

    CVE-2018-12104

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Airbnb Knowledge Repo 0.7.4 allows remote attackers to inject arbitrary web scripts or HTML via the post comments functionality, as demonstrated by the post/posts/new_report.kp URI.

    Published: 17 Jun 2018
    9.8
    Critical

    CVE-2018-10997

    Last Modified: 21 Nov 2024

    Etere EtereWeb before 28.1.20 has a pre-authentication blind SQL injection in the POST parameters txUserName and txPassword.

    Published: 17 Jun 2018
    5.9
    Medium

    CVE-2018-10377

    Last Modified: 21 Nov 2024

    PortSwigger Burp Suite before 1.7.34 has Improper Certificate Validation of the Collaborator server certificate, which might allow man-in-the-middle attackers to obtain interaction data.

    Published: 17 Jun 2018
    6.1
    Medium

    CVE-2018-11647

    Last Modified: 21 Nov 2024

    index.js in oauth2orize-fprm before 0.2.1 has XSS via a crafted URL.

    Published: 17 Jun 2018
    7.4
    High

    CVE-2018-12331

    Last Modified: 21 Nov 2024

    Authentication Bypass by Spoofing vulnerability in ECOS System Management Appliance (aka SMA) 5.2.68 allows a man-in-the-middle attacker to compromise authentication keys and configurations via IP spoofing during "Easy Enrollment."

    Published: 17 Jun 2018
    4.2
    Medium

    CVE-2018-12332

    Last Modified: 21 Nov 2024

    Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset.

    Published: 17 Jun 2018
    8.1
    High

    CVE-2018-12333

    Last Modified: 21 Nov 2024

    Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code.

    Published: 17 Jun 2018
    7.5
    High

    CVE-2018-12334

    Last Modified: 21 Nov 2024

    Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a virtualization attack.

    Published: 17 Jun 2018
    7.3
    High

    CVE-2018-12335

    Last Modified: 21 Nov 2024

    Incorrect access control in ECOS System Management Appliance (aka SMA) 5.2.68 allows a user to compromise authentication keys, and access and manipulate security relevant configurations, via unrestricted database access during Easy Enrollment.

    Published: 17 Jun 2018
    9.8
    Critical

    CVE-2018-12336

    Last Modified: 21 Nov 2024

    Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access.

    Published: 17 Jun 2018
    9.8
    Critical

    CVE-2018-12338

    Last Modified: 21 Nov 2024

    Undocumented Factory Backdoor in ECOS System Management Appliance (aka SMA) 5.2.68 allows the vendor to extract confidential information and manipulate security relevant configurations via remote root SSH access.

    Published: 17 Jun 2018
    9.8
    Critical

    CVE-2018-10969

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

    Published: 17 Jun 2018
    5.9
    Medium

    CVE-2018-12329

    Last Modified: 21 Nov 2024

    Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning.

    Published: 17 Jun 2018
    8.1
    High

    CVE-2018-12330

    Last Modified: 21 Nov 2024

    Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compromised firmware.

    Published: 17 Jun 2018
    4.6
    Medium

    CVE-2018-12337

    Last Modified: 21 Nov 2024

    Reliance on Security Through Obscurity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to partially extract confidential configurations via user-space emulation.

    Published: 17 Jun 2018
    Unknown

    CVE-2018-12262

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 17 Jun 2018
    7.5
    High

    CVE-2018-12454

    Last Modified: 21 Nov 2024

    The _addguess function of a simplelottery smart contract implementation for 1000 Guess, an Ethereum gambling game, generates a random value with publicly readable variables such as the current block information and a private variable (which can be read with a getStorageAt call). Therefore, it allows attackers to always win and get rewards.

    Published: 17 Jun 2018
    9.8
    Critical

    CVE-2018-12503

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has a heap-based buffer over-read in LoadEXRImageFromMemory in tinyexr.h.

    Published: 16 Jun 2018
    7.5
    High

    CVE-2018-12504

    Last Modified: 21 Nov 2024

    tinyexr 0.9.5 has an assertion failure in ComputeChannelLayout in tinyexr.h.

    Published: 16 Jun 2018
    6.1
    Medium

    CVE-2018-12501

    Last Modified: 21 Nov 2024

    Nagios Fusion before 4.1.4 has XSS, aka TPS#13332-13335.

    Published: 16 Jun 2018
    7.1
    High

    CVE-2018-12684

    Last Modified: 21 Nov 2024

    Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.

    Published: 16 Jun 2018
    6.5
    Medium

    CVE-2018-5751

    Last Modified: 21 Nov 2024

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the "groups" and "users" APIs.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2018-5753

    Last Modified: 21 Nov 2024

    The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2) Sender address.

    Published: 15 Jun 2018
    5.4
    Medium

    CVE-2018-5754

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.

    Published: 15 Jun 2018
    5.5
    Medium

    CVE-2018-5755

    Last Modified: 21 Nov 2024

    Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full pathname in a formula in a spreadsheet.

    Published: 15 Jun 2018
    4.3
    Medium

    CVE-2018-5756

    Last Modified: 21 Nov 2024

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.

    Published: 15 Jun 2018
    8.8
    High

    CVE-2018-6496

    Last Modified: 21 Nov 2024

    Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Browser version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15, 4.15.1 which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).

    Published: 15 Jun 2018
    8.1
    High

    CVE-2018-9859

    Last Modified: 21 Nov 2024

    The path of Whale update service was unquoted in NAVER Whale before 1.0.40.7. This vulnerability can be used for persistent privilege escalation if it's available to create an executable file with System privilege by other vulnerable applications.

    Published: 15 Jun 2018
    9.8
    Critical

    CVE-2018-11221

    Last Modified: 21 Nov 2024

    Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.

    Published: 15 Jun 2018
    7.5
    High

    CVE-2018-11222

    Last Modified: 21 Nov 2024

    Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.

    Published: 15 Jun 2018
    5.4
    Medium

    CVE-2018-11223

    Last Modified: 21 Nov 2024

    XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agente&refr=" call.

    Published: 15 Jun 2018
    6.5
    Medium

    CVE-2017-17062

    Last Modified: 21 Nov 2024

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev35, 7.8.x before 7.8.2-rev38, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev19 allows remote authenticated users to save arbitrary user attributes by leveraging improper privilege management.

    Published: 15 Jun 2018
    8.8
    High

    CVE-2018-5752

    Last Modified: 21 Nov 2024

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.

    Published: 15 Jun 2018
    8.8
    High

    CVE-2018-6497

    Last Modified: 21 Nov 2024

    Remote Cross-site Request forgery (CSRF) potential has been identified in UCMBD Server version DDM Content Pack V 10.20, 10.21, 10.22, 10.22 CUP7, 10.30, 10.31, 10.32, 10.33, 10.33 CUP2, 11.0 and CMS Server version 2018.05 BACKGROUND which could allow for remote unsafe deserialization and cross-site request forgery (CSRF).

    Published: 15 Jun 2018
    5.5
    Medium

    CVE-2018-5860

    Last Modified: 21 Nov 2024

    In the MDSS driver in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel, a data structure may be used without being initialized correctly.

    Published: 15 Jun 2018
    5.5
    Medium

    CVE-2017-18169

    Last Modified: 21 Nov 2024

    User process can perform the kernel DOS in ashmem when doing cache maintenance operation in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

    Published: 15 Jun 2018
    7.8
    High

    CVE-2018-5863

    Last Modified: 21 Nov 2024

    If userspace provides a too-large WPA RSN IE length in wlan_hdd_cfg80211_set_ie(), a buffer overflow occurs in all Android releases(Android for MSM, Firefox OS for MSM, QRD Android) from CAF using the Linux kernel.

    Published: 15 Jun 2018