CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-11488

    Last Modified: 21 Nov 2024

    A stack exhaustion vulnerability in the search function of dtSearch 7.90.8538.1 and prior allows remote attackers to cause a denial of service condition by sending a specially crafted HTTP request.

    Published: 29 May 2018
    6.1
    Medium

    CVE-2018-11532

    Last Modified: 21 Nov 2024

    An issue was discovered in the ChangUonDyU Advanced Statistics plugin 1.0.2 for MyBB. changstats.php has XSS, as demonstrated by a subject field.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11535

    Last Modified: 21 Nov 2024

    An issue was discovered in SITEMAKIN SLAC (Site Login and Access Control) v1.0. The parameter "my_item_search" in users.php is exploitable using SQL injection.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11536

    Last Modified: 21 Nov 2024

    md4c before 0.2.5 has a heap-based buffer overflow because md_split_simple_pairing_mark mishandles splits.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11523

    Last Modified: 21 Nov 2024

    upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-11527

    Last Modified: 21 Nov 2024

    An issue was discovered in CScms v4.1. A Cross-site request forgery (CSRF) vulnerability in plugins/sys/admin/Sys.php allows remote attackers to change the administrator's username and password via /admin.php/sys/editpass_save.

    Published: 29 May 2018
    9.8
    Critical

    CVE-2018-11528

    Last Modified: 5 May 2025

    WUZHI CMS 4.1.0 has SQL Injection via an api/sms_check.php?param= URI.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-11624

    Last Modified: 21 Nov 2024

    In ImageMagick 7.0.7-36 Q16, the ReadMATImage function in coders/mat.c allows attackers to cause a use after free via a crafted file.

    Published: 29 May 2018
    5.3
    Medium

    CVE-2018-12615

    Last Modified: 21 Nov 2024

    An issue was discovered in switchGroup() in agent/ExecHelper/ExecHelperMain.cpp in Phusion Passenger before 5.3.2. The set of groups (gidset) is not set correctly, leaving it up to randomness (i.e., uninitialized memory) which supplementary groups are actually being set while lowering privileges.

    Published: 29 May 2018
    6.1
    Medium

    CVE-2018-14040

    Last Modified: 21 Nov 2024

    In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

    Published: 29 May 2018
    6.1
    Medium

    CVE-2018-14041

    Last Modified: 21 Nov 2024

    In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

    Published: 29 May 2018
    6.1
    Medium

    CVE-2018-14042

    Last Modified: 21 Nov 2024

    In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6123

    Last Modified: 21 Nov 2024

    A use after free in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6124

    Last Modified: 21 Nov 2024

    Type confusion in ReadableStreams in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit object corruption via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6125

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in USB in Google Chrome on Windows prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information via a crafted HTML page.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6126

    Last Modified: 21 Nov 2024

    A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6129

    Last Modified: 21 Nov 2024

    Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6130

    Last Modified: 21 Nov 2024

    Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6131

    Last Modified: 21 Nov 2024

    Object lifecycle issue in WebAssembly in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Published: 29 May 2018
    4.3
    Medium

    CVE-2018-6132

    Last Modified: 21 Nov 2024

    Uninitialized data in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted video file.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6133

    Last Modified: 21 Nov 2024

    Incorrect handling of confusable characters in URL Formatter in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via IDN homographs via a crafted domain name.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6134

    Last Modified: 21 Nov 2024

    Information leak in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass no-referrer policy via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6136

    Last Modified: 21 Nov 2024

    Missing type check in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6137

    Last Modified: 21 Nov 2024

    CSS Paint API in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6142

    Last Modified: 21 Nov 2024

    Array bounds check failure in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted PDF file.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6143

    Last Modified: 21 Nov 2024

    Insufficient validation in V8 in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 29 May 2018
    5.5
    Medium

    CVE-2018-6147

    Last Modified: 21 Nov 2024

    Lack of secure text entry mode in Browser UI in Google Chrome on Mac prior to 67.0.3396.62 allowed a local attacker to obtain potentially sensitive information from process memory via a local process.

    Published: 29 May 2018
    7.5
    High

    CVE-2018-12022

    Last Modified: 21 Nov 2024

    An issue was discovered in FasterXML jackson-databind prior to 2.7.9.4, 2.8.11.2, and 2.9.6. When Default Typing is enabled (either globally or for a specific property), the service has the Jodd-db jar (for database access for the Jodd framework) in the classpath, and an attacker can provide an LDAP service to access, it is possible to make the service execute a malicious payload.

    Published: 29 May 2018
    9.6
    Critical

    CVE-2018-6127

    Last Modified: 21 Nov 2024

    Early free of object in use in IndexDB in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page.

    Published: 29 May 2018
    8.1
    High

    CVE-2018-6138

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Extensions API in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to bypass navigation restrictions via a crafted Chrome Extension.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6139

    Last Modified: 21 Nov 2024

    Insufficient target checks on the chrome.debugger API in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6141

    Last Modified: 21 Nov 2024

    Insufficient validation of an image filter in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker who had compromised the renderer process to perform an out of bounds memory read via a crafted HTML page.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6144

    Last Modified: 21 Nov 2024

    Off-by-one error in PDFium in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted PDF file.

    Published: 29 May 2018
    5
    Medium

    CVE-2018-1075

    Last Modified: 21 Nov 2024

    ovirt-engine up to version 4.2.3 is vulnerable to an unfiltered password when choosing manual db provisioning. When engine-setup was run and one chooses to provision the database manually or connect to a remote database, the password input was logged in cleartext during the verification step. Sharing the provisioning log might inadvertently leak database passwords.

    Published: 29 May 2018
    6.1
    Medium

    CVE-2018-6128

    Last Modified: 21 Nov 2024

    Incorrect URL parsing in WebKit in Google Chrome on iOS prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 29 May 2018
    6.5
    Medium

    CVE-2018-6135

    Last Modified: 21 Nov 2024

    Lack of clearing the previous site before loading alerts from a new one in Blink in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform domain spoofing via a crafted HTML page.

    Published: 29 May 2018
    8.8
    High

    CVE-2018-6140

    Last Modified: 21 Nov 2024

    Allowing the chrome.debugger API to attach to Web UI pages in DevTools in Google Chrome prior to 67.0.3396.62 allowed an attacker who convinced a user to install a malicious extension to execute arbitrary code via a crafted Chrome Extension.

    Published: 29 May 2018
    6.1
    Medium

    CVE-2018-6145

    Last Modified: 21 Nov 2024

    Insufficient data validation in HTML parser in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to bypass same origin policy via a crafted HTML page.

    Published: 29 May 2018
    5.3
    Medium

    CVE-2018-10732

    Last Modified: 21 Nov 2024

    The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.

    Published: 28 May 2018
    8.8
    High

    CVE-2018-11516

    Last Modified: 21 Nov 2024

    The vlc_demux_chained_Delete function in input/demux_chained.c in VideoLAN VLC media player 3.0.1 allows remote attackers to cause a denial of service (heap corruption and application crash) or possibly have unspecified other impact via a crafted .swf file.

    Published: 28 May 2018
    5.3
    Medium

    CVE-2018-11517

    Last Modified: 21 Nov 2024

    mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.

    Published: 28 May 2018
    9.8
    Critical

    CVE-2018-11309

    Last Modified: 21 Nov 2024

    Blind SQL injection in coupon_code in the MemberMouse plugin 2.2.8 and prior for WordPress allows an unauthenticated attacker to dump the WordPress MySQL database via an applyCoupon action in an admin-ajax.php request.

    Published: 28 May 2018
    5.4
    Medium

    CVE-2018-11430

    Last Modified: 21 Nov 2024

    An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. The XSS is located in the mod notes textarea.

    Published: 28 May 2018
    8.8
    High

    CVE-2018-11514

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Naukri Clone Script through 3.0.3 allows Unrestricted Upload of a File with a Dangerous Type in edit_resume_det.php, as demonstrated by changing .docx to .php.

    Published: 28 May 2018
    9.8
    Critical

    CVE-2018-11515

    Last Modified: 21 Nov 2024

    The wpForo plugin through 2018-02-05 for WordPress has SQL Injection via a search with the /forum/ wpfo parameter.

    Published: 28 May 2018
    4.8
    Medium

    CVE-2018-11512

    Last Modified: 21 Nov 2024

    Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.

    Published: 28 May 2018
    6.5
    Medium

    CVE-2018-11507

    Last Modified: 21 Nov 2024

    An issue was discovered in Free Lossless Image Format (FLIF) 0.3. An attacker can trigger a long loop in image_load_pnm in image/image-pnm.cpp.

    Published: 28 May 2018
    7.8
    High

    CVE-2018-10878

    Last Modified: 21 Nov 2024

    A flaw was found in the Linux kernel's ext4 filesystem. A local user can cause an out-of-bounds write and a denial of service or unspecified other impact is possible by mounting and operating a crafted ext4 filesystem image.

    Published: 28 May 2018
    7.5
    High

    CVE-2018-10811

    Last Modified: 21 Nov 2024

    strongSwan 5.6.0 and older allows Remote Denial of Service because of Missing Initialization of a Variable.

    Published: 28 May 2018
    6.5
    Medium

    CVE-2018-12373

    Last Modified: 21 Nov 2024

    dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9.

    Published: 27 May 2018