CVE Feed

    Dashboard / CVE

    7.5
    High

    CVE-2018-11322

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! Core before 3.8.8. Depending on the server configuration, PHAR files might be handled as executable PHP scripts by the webserver.

    Published: 22 May 2018
    8.8
    High

    CVE-2018-11323

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! Core before 3.8.8. Inadequate checks allowed users to modify the access levels of user groups with higher permissions.

    Published: 22 May 2018
    5.9
    Medium

    CVE-2018-11324

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! Core before 3.8.8. A long running background process, such as remote checks for core or extension updates, could create a race condition where a session that was expected to be destroyed would be recreated.

    Published: 22 May 2018
    9.8
    Critical

    CVE-2018-11325

    Last Modified: 21 Nov 2024

    An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.

    Published: 22 May 2018
    5.4
    Medium

    CVE-2018-1583

    Last Modified: 21 Nov 2024

    IBM StoredIQ 7.6 could allow an authenticated attacker to bypass certain security restrictions. By sending a specially-crafted request, an authenticated attacker could exploit this vulnerability to access and manipulate documents on StoredIQ managed data sources. IBM X-Force ID: 143331.

    Published: 22 May 2018
    7.8
    High

    CVE-2018-6962

    Last Modified: 21 Nov 2024

    VMware Fusion (10.x before 10.1.2) contains a signature bypass vulnerability which may lead to a local privilege escalation.

    Published: 22 May 2018
    6.1
    Medium

    CVE-2018-11366

    Last Modified: 21 Nov 2024

    init.php in the Loginizer plugin 1.3.8 through 1.3.9 for WordPress has Unauthenticated Stored Cross-Site Scripting (XSS) because logging is mishandled. This is fixed in 1.4.0.

    Published: 22 May 2018
    7.5
    High

    CVE-2018-11367

    Last Modified: 21 Nov 2024

    An issue was discovered in CppCMS before 1.2.1. There is a denial of service in the JSON parser module.

    Published: 22 May 2018
    5.5
    Medium

    CVE-2018-6963

    Last Modified: 21 Nov 2024

    VMware Workstation (14.x before 14.1.2) and Fusion (10.x before 10.1.2) contain multiple denial-of-service vulnerabilities that occur due to NULL pointer dereference issues in the RPC handler. Successful exploitation of these issues may allow an attacker with limited privileges on the guest machine trigger a denial-of-Service of their guest machine.

    Published: 22 May 2018
    7.5
    High

    CVE-2018-11329

    Last Modified: 21 Nov 2024

    The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take over the contract's ownership, aka ceoAnyone. After that, all the digital assets (including Ether balance and tokens) might be manipulated by the attackers, as exploited in the wild in May 2018.

    Published: 22 May 2018
    7.5
    High

    CVE-2018-11363

    Last Modified: 21 Nov 2024

    jpeg_size in pdfgen.c in PDFGen before 2018-04-09 has a heap-based buffer over-read.

    Published: 22 May 2018
    7.5
    High

    CVE-2018-11364

    Last Modified: 21 Nov 2024

    sav_parse_machine_integer_info_record in spss/readstat_sav_read.c in libreadstat.a in ReadStat 0.1.1 has a memory leak related to an iconv_open call.

    Published: 22 May 2018
    7.5
    High

    CVE-2018-11365

    Last Modified: 21 Nov 2024

    sas/readstat_sas7bcat_read.c in libreadstat.a in ReadStat 0.1.1 has an infinite loop.

    Published: 22 May 2018
    6.1
    Medium

    CVE-2018-11339

    Last Modified: 21 Nov 2024

    An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.

    Published: 22 May 2018
    7.2
    High

    CVE-2018-11340

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data to a specified filename. This can be used to place attacker controlled code on the file system that is then executed.

    Published: 22 May 2018
    7.2
    High

    CVE-2018-11341

    Last Modified: 21 Nov 2024

    Directory traversal in importuser.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to navigate the file system via the filename parameter.

    Published: 22 May 2018
    4.3
    Medium

    CVE-2018-11342

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in fileExplorer.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a path to a file on the system to create folders via the dest_folder parameter.

    Published: 22 May 2018
    5.4
    Medium

    CVE-2018-11343

    Last Modified: 21 Nov 2024

    A persistent cross site scripting vulnerability in playlistmanger.cgi in the ASUSTOR SoundsGood application allows attackers to store cross site scripting payloads via the 'playlist' POST parameter.

    Published: 22 May 2018
    6.5
    Medium

    CVE-2018-11344

    Last Modified: 21 Nov 2024

    A path traversal vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to arbitrarily specify a file on the system to download via the file1 parameter.

    Published: 22 May 2018
    8.8
    High

    CVE-2018-11345

    Last Modified: 21 Nov 2024

    An unrestricted file upload vulnerability in upload.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows attackers to upload supplied data via the POST parameter filename. This can be used to place attacker controlled code on the file system that can then be executed. Further, the filename parameter is vulnerable to path traversal and allows the attacker to place the file anywhere on the system.

    Published: 22 May 2018
    4.3
    Medium

    CVE-2018-11346

    Last Modified: 21 Nov 2024

    An insecure direct object reference vulnerability in download.cgi in ASUSTOR AS6202T ADM 3.1.0.RFQ3 allows the ability to reference the "download_sys_settings" action and then specify files arbitrarily throughout the system via the act parameter.

    Published: 22 May 2018
    6.1
    Medium

    CVE-2018-11627

    Last Modified: 21 Nov 2024

    Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.

    Published: 22 May 2018
    6.5
    Medium

    CVE-2018-5388

    Last Modified: 21 Nov 2024

    In stroke_socket.c in strongSwan before 5.6.3, a missing packet length check could allow a buffer underflow, which may lead to resource exhaustion and denial of service while reading from the socket.

    Published: 22 May 2018
    5.9
    Medium

    CVE-2018-11412

    Last Modified: 21 Nov 2024

    In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.

    Published: 22 May 2018
    5.5
    Medium

    CVE-2018-3639

    Last Modified: 29 May 2026

    Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB), Variant 4.

    Published: 21 May 2018
    4.8
    Medium

    CVE-2018-11330

    Last Modified: 21 Nov 2024

    An issue was discovered in Pluck before 4.7.6. There is authenticated stored XSS because the character set for filenames is not properly restricted.

    Published: 21 May 2018
    9.8
    Critical

    CVE-2018-11331

    Last Modified: 21 Nov 2024

    An issue was discovered in Pluck before 4.7.6. Remote PHP code execution is possible because the set of disallowed filetypes for uploads in missing some applicable ones such as .phtml and .htaccess.

    Published: 21 May 2018
    5.6
    Medium

    CVE-2018-3640

    Last Modified: 21 Nov 2024

    Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.

    Published: 21 May 2018
    7.8
    High

    CVE-2018-7687

    Last Modified: 21 Nov 2024

    The Micro Focus Client for OES before version 2 SP4 IR8a has a vulnerability that could allow a local attacker to elevate privileges via a buffer overflow in ncfsd.sys.

    Published: 21 May 2018
    7.5
    High

    CVE-2018-8012

    Last Modified: 21 Nov 2024

    No authentication/authorization is enforced when a server attempts to join a quorum in Apache ZooKeeper before 3.4.10, and 3.5.0-alpha through 3.5.3-beta. As a result an arbitrary end point could join the cluster and begin propagating counterfeit changes to the leader.

    Published: 21 May 2018
    5.5
    Medium

    CVE-2018-7268

    Last Modified: 21 Nov 2024

    MagniComp SysInfo before 10-H81, as shipped with BMC BladeLogic Automation and other products, contains an information exposure vulnerability in which a local unprivileged user is able to read any root (uid 0) owned file on the system, regardless of the file permissions. Confidential information such as password hashes (/etc/shadow) or other secrets (such as log files or private keys) can be leaked to the attacker. The vulnerability has a confidentiality impact, but has no direct impact on system integrity or availability.

    Published: 21 May 2018
    6.5
    Medium

    CVE-2018-11096

    Last Modified: 21 Nov 2024

    Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information remotely.

    Published: 21 May 2018
    6.5
    Medium

    CVE-2018-11092

    Last Modified: 21 Nov 2024

    An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.

    Published: 21 May 2018
    9.8
    Critical

    CVE-2018-11320

    Last Modified: 21 Nov 2024

    In Octopus Deploy 2018.4.4 through 2018.5.1, Octopus variables that are sourced from the target do not have sensitive values obfuscated in the deployment logs.

    Published: 21 May 2018
    5.3
    Medium

    CVE-2018-8142

    Last Modified: 21 Nov 2024

    A security feature bypass exists when Windows incorrectly validates kernel driver signatures, aka "Windows Security Feature Bypass Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-1035.

    Published: 21 May 2018
    7.8
    High

    CVE-2018-11506

    Last Modified: 21 Nov 2024

    The sr_do_ioctl function in drivers/scsi/sr_ioctl.c in the Linux kernel through 4.16.12 allows local users to cause a denial of service (stack-based buffer overflow) or possibly have unspecified other impact because sense buffers have different sizes at the CDROM layer and the SCSI layer, as demonstrated by a CDROMREADMODE2 ioctl call.

    Published: 21 May 2018
    9.8
    Critical

    CVE-2018-17963

    Last Modified: 21 Nov 2024

    qemu_deliver_packet_iov in net/net.c in Qemu accepts packet sizes greater than INT_MAX, which allows attackers to cause a denial of service or possibly have unspecified other impact.

    Published: 21 May 2018
    5.5
    Medium

    CVE-2018-8010

    Last Modified: 21 Nov 2024

    This vulnerability in Apache Solr 6.0.0 to 6.6.3, 7.0.0 to 7.3.0 relates to an XML external entity expansion (XXE) in Solr config files (solrconfig.xml, schema.xml, managed-schema). In addition, Xinclude functionality provided in these config files is also affected in a similar way. The vulnerability can be used as XXE using file/ftp/http protocols in order to read arbitrary local files from the Solr server or the internal network. Users are advised to upgrade to either Solr 6.6.4 or Solr 7.3.1 releases both of which address the vulnerability. Once upgrade is complete, no other steps are required. Those releases only allow external entities and Xincludes that refer to local files / zookeeper resources below the Solr instance directory (using Solr's ResourceLoader); usage of absolute URLs is denied. Keep in mind, that external entities and XInclude are explicitly supported to better structure config files in large installations. Before Solr 6 this was no problem, as config files were not accessible through the APIs.

    Published: 21 May 2018
    9.1
    Critical

    CVE-2018-11311

    Last Modified: 21 Nov 2024

    A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.

    Published: 20 May 2018
    7.5
    High

    CVE-2018-11319

    Last Modified: 21 Nov 2024

    Syntastic (aka vim-syntastic) through 3.9.0 does not properly handle searches for configuration files (it searches the current directory up to potentially the root). This improper handling might be exploited for arbitrary code execution via a malicious gcc plugin, if an attacker has write access to a directory that is a parent of the base directory of the project being checked. NOTE: exploitation is more difficult after 3.8.0 because filename prediction may be needed.

    Published: 20 May 2018
    6.5
    Medium

    CVE-2018-11242

    Last Modified: 21 Nov 2024

    An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.

    Published: 20 May 2018
    6.5
    Medium

    CVE-2018-11315

    Last Modified: 21 Nov 2024

    The Local HTTP API in Radio Thermostat CT50 and CT80 1.04.84 and below products allows unauthorized access via a DNS rebinding attack. This can result in remote device temperature control, as demonstrated by a tstat t_heat request that accesses a device purchased in the Spring of 2018, and sets a home's target temperature to 95 degrees Fahrenheit. This vulnerability might be described as an addendum to CVE-2013-4860.

    Published: 20 May 2018
    7.5
    High

    CVE-2018-11239

    Last Modified: 21 Nov 2024

    An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets by providing a _to argument in conjunction with a large _value argument, as exploited in the wild in May 2018, aka the "burnOverflow" issue.

    Published: 19 May 2018
    8.8
    High

    CVE-2018-4943

    Last Modified: 21 Nov 2024

    Adobe PhoneGap Push Plugin versions 1.8.0 and earlier have an exploitable Same-Origin Method Execution vulnerability. Successful exploitation could lead to JavaScript code execution in the context of the PhoneGap app.

    Published: 19 May 2018
    7.8
    High

    CVE-2018-4873

    Last Modified: 21 Nov 2024

    Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Unquoted Search Path vulnerability. Successful exploitation could lead to local privilege escalation.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2018-4917

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    6.1
    Medium

    CVE-2018-4921

    Last Modified: 21 Nov 2024

    Adobe Connect versions 9.7 and earlier have an exploitable unrestricted SWF file upload vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 May 2018
    7.5
    High

    CVE-2018-4925

    Last Modified: 21 Nov 2024

    Adobe Digital Editions versions 4.5.7 and below have an exploitable Out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 May 2018
    7.8
    High

    CVE-2018-4927

    Last Modified: 21 Nov 2024

    Adobe InDesign versions 13.0 and below have an exploitable Untrusted Search Path vulnerability. Successful exploitation could lead to local privilege escalation.

    Published: 19 May 2018
    6.1
    Medium

    CVE-2018-4929

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.2 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 19 May 2018