CVE Feed

    Dashboard / CVE

    4.6
    Medium

    CVE-2017-17158

    Last Modified: 21 Nov 2024

    Some Huawei smart phones with the versions before Berlin-L21HNC185B381; the versions before Prague-AL00AC00B223; the versions before Prague-AL00BC00B223; the versions before Prague-AL00CC00B223; the versions before Prague-L31C432B208; the versions before Prague-TL00AC01B223; the versions before Prague-TL00AC01B223 have an information exposure vulnerability. When the user's smart phone connects to the malicious device for charging, an unauthenticated attacker may activate some specific function by sending some specially crafted messages. Due to insufficient input validation of the messages, successful exploit may cause information exposure.

    Published: 24 May 2018
    8.8
    High

    CVE-2018-7903

    Last Modified: 21 Nov 2024

    Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.

    Published: 24 May 2018
    8.8
    High

    CVE-2018-7904

    Last Modified: 21 Nov 2024

    Huawei 1288H V5 and 288H V5 with software of V100R005C00 have a JSON injection vulnerability. An authenticated, remote attacker can launch a JSON injection to modify the password of administrator. Due to insufficient verification of the input, this could be exploited to obtain the management privilege of the system.

    Published: 24 May 2018
    7.5
    High

    CVE-2018-7942

    Last Modified: 21 Nov 2024

    The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have an authentication bypass vulnerability. An unauthenticated, remote attacker may send some specially crafted messages to the affected products. Due to improper authentication design, successful exploit may cause some information leak.

    Published: 24 May 2018
    5.5
    Medium

    CVE-2018-1000040

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0 and earlier, multiple use of uninitialized value bugs in the PDF parser could allow an attacker to cause a denial of service (crash) or influence program flow via a crafted file.

    Published: 24 May 2018
    6.5
    Medium

    CVE-2018-9920

    Last Modified: 21 Nov 2024

    Server side request forgery exists in the runtime application in K2 smartforms 4.6.11 via a modified hostname in an https://*/Identity/STS/Forms/Scripts URL.

    Published: 24 May 2018
    5.5
    Medium

    CVE-2018-1000036

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0 and earlier, multiple memory leaks in the PDF parser allow an attacker to cause a denial of service (memory leak) via a crafted file.

    Published: 24 May 2018
    5.5
    Medium

    CVE-2018-1000037

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0 and earlier, multiple reachable assertions in the PDF parser allow an attacker to cause a denial of service (assert crash) via a crafted file.

    Published: 24 May 2018
    6.5
    Medium

    CVE-2017-9421

    Last Modified: 21 Nov 2024

    Authentication Bypass vulnerability in Accellion kiteworks before 2017.01.00 allows remote attackers to execute certain API calls on behalf of a web user using a gathered token via a POST request to /oauth/token.

    Published: 24 May 2018
    7.8
    High

    CVE-2018-1000038

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0 and earlier, a stack buffer overflow in function pdf_lookup_cmap_full in pdf/pdf-cmap.c could allow an attacker to execute arbitrary code via a crafted file.

    Published: 24 May 2018
    6.3
    Medium

    CVE-2018-1000039

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0 and earlier, multiple heap use after free bugs in the PDF parser could allow an attacker to execute arbitrary code, read memory, or cause a denial of service via a crafted file.

    Published: 24 May 2018
    7.5
    High

    CVE-2018-11411

    Last Modified: 21 Nov 2024

    The transferFrom function of a smart contract implementation for DimonCoin (FUD), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all victims' balances into their account) because certain computations involving _value are incorrect.

    Published: 24 May 2018
    5.4
    Medium

    CVE-2018-11403

    Last Modified: 21 Nov 2024

    DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.

    Published: 24 May 2018
    6.1
    Medium

    CVE-2018-11404

    Last Modified: 21 Nov 2024

    DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

    Published: 24 May 2018
    8.8
    High

    CVE-2018-11405

    Last Modified: 21 Nov 2024

    Kliqqi 2.0.2 has CSRF in admin/admin_users.php.

    Published: 24 May 2018
    4.6
    Medium

    CVE-2018-11400

    Last Modified: 21 Nov 2024

    In SimpliSafe Original, the Base Station fails to detect tamper attempts: it does not send a notification if a physically proximate attacker removes the battery and external power.

    Published: 24 May 2018
    6.6
    Medium

    CVE-2018-11402

    Last Modified: 21 Nov 2024

    SimpliSafe Original has Unencrypted Keypad Transmissions, which allows physically proximate attackers to discover the PIN.

    Published: 24 May 2018
    4.3
    Medium

    CVE-2018-11399

    Last Modified: 21 Nov 2024

    SimpliSafe Original has Unencrypted Sensor Transmissions, which allows physically proximate attackers to obtain potentially sensitive information about the specific times when alarm-system events occur.

    Published: 24 May 2018
    4.6
    Medium

    CVE-2018-11401

    Last Modified: 21 Nov 2024

    In SimpliSafe Original, RF Interference (e.g., an extremely strong 433.92 MHz signal) by a physically proximate attacker does not cause a notification.

    Published: 24 May 2018
    8.1
    High

    CVE-2018-1000500

    Last Modified: 9 Jun 2025

    Busybox contains a Missing SSL certificate validation vulnerability in The "busybox wget" applet that can result in arbitrary code execution. This attack appear to be exploitable via Simply download any file over HTTPS using "busybox wget https://compromised-domain.com/important-file".

    Published: 24 May 2018
    8.5
    High

    CVE-2018-10843

    Last Modified: 21 Nov 2024

    source-to-image component of Openshift Container Platform before versions atomic-openshift 3.7.53, atomic-openshift 3.9.31 is vulnerable to a privilege escalation which allows the assemble script to run as the root user in a non-privileged container. An attacker can use this flaw to open network connections, and possibly other actions, on the host which are normally only available to a root user.

    Published: 24 May 2018
    6.1
    Medium

    CVE-2018-10428

    Last Modified: 21 Nov 2024

    ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.

    Published: 23 May 2018
    5.4
    Medium

    CVE-2018-6495

    Last Modified: 21 Nov 2024

    Cross-Site Scripting (XSS) in Micro Focus Universal CMDB, version 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, 10.33, 11.0, CMS, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1 and Micro Focus UCMDB Browser, version 4.10, 4.11, 4.12, 4.13, 4.14, 4.15.1. This vulnerability could be remotely exploited to allow Cross-Site Scripting (XSS).

    Published: 23 May 2018
    9.8
    Critical

    CVE-2018-10648

    Last Modified: 21 Nov 2024

    There are Unauthenticated File Upload Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

    Published: 23 May 2018
    6.1
    Medium

    CVE-2018-10649

    Last Modified: 21 Nov 2024

    There is a Cross-Site Scripting Vulnerability in Citrix XenMobile Server 10.7 before RP3.

    Published: 23 May 2018
    7.8
    High

    CVE-2018-10650

    Last Modified: 21 Nov 2024

    There is an Insufficient Path Validation Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

    Published: 23 May 2018
    6.1
    Medium

    CVE-2018-10651

    Last Modified: 21 Nov 2024

    There are Open Redirect Vulnerabilities in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

    Published: 23 May 2018
    7.5
    High

    CVE-2018-10652

    Last Modified: 21 Nov 2024

    There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.

    Published: 23 May 2018
    9.8
    Critical

    CVE-2018-10653

    Last Modified: 21 Nov 2024

    There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

    Published: 23 May 2018
    8.1
    High

    CVE-2018-10654

    Last Modified: 21 Nov 2024

    There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

    Published: 23 May 2018
    6.5
    Medium

    CVE-2018-10353

    Last Modified: 21 Nov 2024

    A SQL injection information disclosure vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to disclose sensitive information on vulnerable installations due to a flaw in the formChangePass class. Authentication is required to exploit this vulnerability.

    Published: 23 May 2018
    8.8
    High

    CVE-2018-10354

    Last Modified: 21 Nov 2024

    A command injection remote command execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the LauncherServer. Authentication is required to exploit this vulnerability.

    Published: 23 May 2018
    7
    High

    CVE-2018-10355

    Last Modified: 21 Nov 2024

    An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system in order to exploit this vulnerability.

    Published: 23 May 2018
    8.8
    High

    CVE-2018-10356

    Last Modified: 21 Nov 2024

    A SQL injection remote code execution vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRequestDomains class. Authentication is required to exploit this vulnerability.

    Published: 23 May 2018
    8.8
    High

    CVE-2018-10357

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability in Trend Micro Endpoint Application Control 2.0 could allow a remote attacker to execute arbitrary code on vulnerable installations due to a flaw in the FileDrop servlet. Authentication is required to exploit this vulnerability.

    Published: 23 May 2018
    9.8
    Critical

    CVE-2018-8898

    Last Modified: 21 Nov 2024

    A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.

    Published: 23 May 2018
    8.8
    High

    CVE-2018-10352

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formConfiguration class. Authentication is required to exploit this vulnerability.

    Published: 23 May 2018
    8.8
    High

    CVE-2018-10351

    Last Modified: 21 Nov 2024

    A vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a remote attacker to execute arbitrary SQL statements on vulnerable installations due to a flaw in the formRegistration2 class. Authentication is required to exploit this vulnerability.

    Published: 23 May 2018
    8.1
    High

    CVE-2018-11231

    Last Modified: 21 Nov 2024

    In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.

    Published: 23 May 2018
    5.3
    Medium

    CVE-2018-1193

    Last Modified: 21 Nov 2024

    Cloud Foundry routing-release, versions prior to 0.175.0, lacks sanitization for user-provided X-Forwarded-Proto headers. A remote user can set the X-Forwarded-Proto header in a request to potentially bypass an application requirement to only respond over secure connections.

    Published: 23 May 2018
    8.8
    High

    CVE-2017-9317

    Last Modified: 21 Nov 2024

    Privilege escalation vulnerability found in some Dahua IP devices. Attacker in possession of low privilege account can gain access to credential information of high privilege account and further obtain device information or attack the device.

    Published: 23 May 2018
    7.5
    High

    CVE-2018-1310

    Last Modified: 21 Nov 2024

    Apache NiFi JMS Deserialization issue because of ActiveMQ client vulnerability. Malicious JMS content could cause denial of service. See ActiveMQ CVE-2015-5254 announcement for more information. The fix to upgrade the activemq-client library to 5.15.3 was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 23 May 2018
    9.8
    Critical

    CVE-2018-1309

    Last Modified: 21 Nov 2024

    Apache NiFi External XML Entity issue in SplitXML processor. Malicious XML content could cause information disclosure or remote code execution. The fix to disable external general entity parsing and disallow doctype declarations was applied on the Apache NiFi 1.6.0 release. Users running a prior 1.x release should upgrade to the appropriate release.

    Published: 23 May 2018
    8.8
    High

    CVE-2018-8176

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Microsoft PowerPoint software when the software fails to properly validate XML content, aka "Microsoft PowerPoint Remote Code Execution Vulnerability." This affects Microsoft Office.

    Published: 23 May 2018
    7.5
    High

    CVE-2018-11396

    Last Modified: 21 Nov 2024

    ephy-session.c in libephymain.so in GNOME Web (aka Epiphany) through 3.28.2.1 allows remote attackers to cause a denial of service (application crash) via JavaScript code that triggers access to a NULL URL, as demonstrated by a crafted window.open call.

    Published: 23 May 2018
    8.1
    High

    CVE-2018-7295

    Last Modified: 21 Nov 2024

    ffxivlauncher.exe in Square Enix Final Fantasy XIV 4.21 and 4.25 on Windows is affected by Improper Enforcement of Message Integrity During Transmission in a Communication Channel, allowing a man-in-the-middle attacker to steal user credentials because a session retrieves global.js via http before proceeding to use https. This is fixed in Patch 4.3.

    Published: 23 May 2018
    7.8
    High

    CVE-2018-11334

    Last Modified: 21 Nov 2024

    Windscribe 1.81 creates a named pipe with a NULL DACL that allows Everyone users to gain privileges or cause a denial of service via \\.\pipe\WindscribeService.

    Published: 23 May 2018
    7.8
    High

    CVE-2019-3881

    Last Modified: 21 Nov 2024

    Bundler prior to 2.1.0 uses a predictable path in /tmp/, created with insecure permissions as a storage location for gems, if locations under the user's home directory are not available. If Bundler is used in a scenario where the user does not have a writable home directory, an attacker could place malicious code in this directory that would be later loaded and executed.

    Published: 23 May 2018
    5.5
    Medium

    CVE-2018-12495

    Last Modified: 21 Nov 2024

    The quoteblock function in markdown.c in libmarkdown.a in DISCOUNT 2.2.3a allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted file.

    Published: 23 May 2018
    9.8
    Critical

    CVE-2018-11410

    Last Modified: 21 Nov 2024

    An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 23 May 2018