CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-4938

    Last Modified: 6 May 2025

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Insecure Library Loading vulnerability. Successful exploitation could lead to local privilege escalation.

    Published: 19 May 2018
    6.1
    Medium

    CVE-2018-4940

    Last Modified: 21 Nov 2024

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 May 2018
    6.1
    Medium

    CVE-2018-4941

    Last Modified: 21 Nov 2024

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Cross-Site Scripting vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2018-4991

    Last Modified: 21 Nov 2024

    Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper certificate validation vulnerability. Successful exploitation could lead to a security bypass.

    Published: 19 May 2018
    7.8
    High

    CVE-2018-4992

    Last Modified: 21 Nov 2024

    Adobe Creative Cloud Desktop Application versions 4.4.1.298 and earlier have an exploitable Improper input validation vulnerability. Successful exploitation could lead to local privilege escalation.

    Published: 19 May 2018
    7.5
    High

    CVE-2018-4994

    Last Modified: 21 Nov 2024

    Adobe Connect versions 9.7.5 and earlier have an exploitable Authentication Bypass vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2017-11240

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2017-11250

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2018-4939

    Last Modified: 23 Oct 2025

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Deserialization of Untrusted Data vulnerability. Successful exploitation could lead to arbitrary code execution.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2017-11253

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2017-11307

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2017-11308

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable heap overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2018-4918

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.009.20050 and earlier, 2017.011.30070 and earlier, 2015.006.30394 and earlier have an exploitable out-of-bounds write vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    7.5
    High

    CVE-2018-4942

    Last Modified: 6 May 2025

    Adobe ColdFusion Update 5 and earlier versions, ColdFusion 11 Update 13 and earlier versions have an exploitable Unsafe XML External Entity Processing vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2017-11306

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2017.012.20098 and earlier, 2017.011.30066 and earlier, 2015.006.30355 and earlier, 11.0.22 and earlier have an exploitable out-of-bounds read vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    9.8
    Critical

    CVE-2018-4924

    Last Modified: 21 Nov 2024

    Adobe Dreamweaver CC versions 18.0 and earlier have an OS Command Injection vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    7.8
    High

    CVE-2018-4928

    Last Modified: 21 Nov 2024

    Adobe InDesign versions 13.0 and below have an exploitable Memory corruption vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published: 19 May 2018
    6.1
    Medium

    CVE-2018-4930

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.3 and earlier have an exploitable Cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 19 May 2018
    6.1
    Medium

    CVE-2018-4931

    Last Modified: 21 Nov 2024

    Adobe Experience Manager versions 6.1 and earlier have an exploitable stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.

    Published: 19 May 2018
    5.5
    Medium

    CVE-2018-4926

    Last Modified: 21 Nov 2024

    Adobe Digital Editions versions 4.5.7 and below have an exploitable Stack Overflow vulnerability. Successful exploitation could lead to information disclosure.

    Published: 19 May 2018
    9.1
    Critical

    CVE-2018-4923

    Last Modified: 21 Nov 2024

    Adobe Connect versions 9.7 and earlier have an exploitable OS Command Injection. Successful exploitation could lead to arbitrary file deletion.

    Published: 19 May 2018
    7.5
    High

    CVE-2018-1132

    Last Modified: 21 Nov 2024

    A flaw was found in Opendaylight's SDNInterfaceapp (SDNI). Attackers can SQL inject the component's database (SQLite) without authenticating to the controller or SDNInterfaceapp. SDNInterface has been deprecated in OpenDayLight since it was last used in the final Carbon series release. In addition to the component not being included in OpenDayLight in newer releases, the SDNInterface component is not packaged in the opendaylight package included in RHEL.

    Published: 19 May 2018
    5.4
    Medium

    CVE-2018-1147

    Last Modified: 21 Nov 2024

    In Nessus before 7.1.0, a XSS vulnerability exists due to improper input validation. A remote authenticated attacker could create and upload a .nessus file, which may be viewed by an administrator allowing for the execution of arbitrary script code in a user's browser session. In other scenarios, XSS could also occur by altering variables from the Advanced Settings.

    Published: 18 May 2018
    6.5
    Medium

    CVE-2018-1148

    Last Modified: 21 Nov 2024

    In Nessus before 7.1.0, Session Fixation exists due to insufficient session management within the application. An authenticated attacker could maintain system access due to session fixation after a user password change.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-8867

    Last Modified: 21 Nov 2024

    In GE PACSystems RX3i CPE305/310 version 9.20 and prior, RX3i CPE330 version 9.21 and prior, RX3i CPE 400 version 9.30 and prior, PACSystems RSTi-EP CPE 100 all versions, and PACSystems CPU320/CRU320 RXi all versions, the device does not properly validate input, which could allow a remote attacker to send specially crafted packets causing the device to become unavailable.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-6562

    Last Modified: 21 Nov 2024

    totemomail Encryption Gateway before 6.0_b567 allows remote attackers to obtain sensitive information about user sessions and encryption key material via a JSONP hijacking attack.

    Published: 18 May 2018
    5.5
    Medium

    CVE-2018-11254

    Last Modified: 21 Nov 2024

    An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a denial of service through a crafted pdf file, a related issue to CVE-2017-8054.

    Published: 18 May 2018
    5.5
    Medium

    CVE-2018-11255

    Last Modified: 21 Nov 2024

    An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

    Published: 18 May 2018
    6.5
    Medium

    CVE-2018-11256

    Last Modified: 21 Nov 2024

    An issue was discovered in PoDoFo 0.9.5. The function PdfDocument::Append() in PdfDocument.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted PDF document.

    Published: 18 May 2018
    6.1
    Medium

    CVE-2018-11245

    Last Modified: 21 Nov 2024

    app/webroot/js/misp.js in MISP 2.4.91 has a DOM based XSS with cortex type attributes.

    Published: 18 May 2018
    9.8
    Critical

    CVE-2018-11248

    Last Modified: 21 Nov 2024

    util/FileDownloadUtils.java in FileDownloader 1.7.3 does not check an attachment's name. If an attacker places "../" in the file name, the file can be stored in an unintended directory because of Directory Traversal.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-8015

    Last Modified: 21 Nov 2024

    In Apache ORC 1.0.0 to 1.4.3 a malformed ORC file can trigger an endlessly recursive function call in the C++ or Java parser. The impact of this bug is most likely denial-of-service against software that uses the ORC file parser. With the C++ parser, the stack overflow might possibly corrupt the stack.

    Published: 18 May 2018
    7.8
    High

    CVE-2018-11243

    Last Modified: 11 Apr 2025

    PackLinuxElf64::unpack in p_lx_elf.cpp in UPX 3.95 allows remote attackers to cause a denial of service (double free), limit the ability of a malware scanner to operate on the entire original data, or possibly have unspecified other impact via a crafted file.

    Published: 18 May 2018
    5.3
    Medium

    CVE-2018-11244

    Last Modified: 21 Nov 2024

    The BBE theme before 1.53 for WordPress allows a direct launch of an HTML editor.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-5256

    Last Modified: 21 Nov 2024

    CoreOS Tectonic 1.7.x before 1.7.9-tectonic.4 and 1.8.x before 1.8.4-tectonic.3 mounts a direct proxy to the kubernetes cluster at /api/kubernetes/ which is accessible without authentication to Tectonic and allows an attacker to directly connect to the kubernetes API server. Unauthenticated users are able to list all Namespaces through the Console, resulting in an information disclosure. Tectonic's exposure of an unauthenticated API endpoint containing information regarding the internal state of the cluster can provide an attacker with information that may assist in other attacks against the cluster. For example, an attacker may not have the permissions required to list all namespaces in the cluster but can instead leverage this vulnerability to enumerate the namespaces and then begin to check each namespace for weak authorization policies that may allow further escalation of privileges.

    Published: 18 May 2018
    8.8
    High

    CVE-2018-10967

    Last Modified: 21 Nov 2024

    On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can forge an HTTP request to inject operating system commands that can be executed on the device with higher privileges, aka remote code execution.

    Published: 18 May 2018
    8.8
    High

    CVE-2018-9250

    Last Modified: 21 Nov 2024

    interface\super\edit_list.php in OpenEMR before v5_0_1_1 allows remote authenticated users to execute arbitrary SQL commands via the newlistname parameter.

    Published: 18 May 2018
    9.8
    Critical

    CVE-2018-10968

    Last Modified: 21 Nov 2024

    On D-Link DIR-550A and DIR-604M devices through v2.10KR, a malicious user can use a default TELNET account to get unauthorized access to vulnerable devices, aka a backdoor access vulnerability.

    Published: 18 May 2018
    6.1
    Medium

    CVE-2018-10307

    Last Modified: 21 Nov 2024

    error.php in ILIAS 5.2.x through 5.3.x before 5.3.4 allows XSS via the text of a PDO exception.

    Published: 18 May 2018
    4.6
    Medium

    CVE-2018-8849

    Last Modified: 27 Jun 2025

    Medtronic N'Vision Clinician Programmer 8840 N'Vision Clinician Programme and 8870 N'Vision removable Application Card do not encrypt PII and PHI while at rest.

    Published: 18 May 2018
    4.1
    Medium

    CVE-2017-9637

    Last Modified: 21 Nov 2024

    Schneider Electric Ampla MES 6.4 provides capability to interact with data from third party databases. When connectivity to those databases is configured to use a SQL user name and password, an attacker may be able to sniff details from the connection string. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

    Published: 18 May 2018
    3.9
    Low

    CVE-2017-9635

    Last Modified: 21 Nov 2024

    Schneider Electric Ampla MES 6.4 provides capability to configure users and their privileges. When Ampla MES users are configured to use Simple Security, a weakness in the password hashing algorithm could be exploited to reverse the user's password. Schneider Electric recommends that users of Ampla MES versions 6.4 and prior should upgrade to Ampla MES version 6.5 as soon as possible.

    Published: 18 May 2018
    6.1
    Medium

    CVE-2018-10306

    Last Modified: 21 Nov 2024

    Services/Form/classes/class.ilDateDurationInputGUI.php and Services/Form/classes/class.ilDateTimeInputGUI.php in ILIAS 5.1.x through 5.3.x before 5.3.4 allow XSS via an invalid date.

    Published: 18 May 2018
    6.5
    Medium

    CVE-2018-5185

    Last Modified: 21 Nov 2024

    Plaintext of decrypted emails can leak through by user submitting an embedded form. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

    Published: 18 May 2018
    4.3
    Medium

    CVE-2018-5161

    Last Modified: 21 Nov 2024

    Crafted message headers can cause a Thunderbird process to hang on receiving the message. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

    Published: 18 May 2018
    5.3
    Medium

    CVE-2018-1000204

    Last Modified: 21 Nov 2024

    Linux Kernel version 3.18 to 4.16 incorrectly handles an SG_IO ioctl on /dev/sg0 with dxfer_direction=SG_DXFER_FROM_DEV and an empty 6-byte cmdp. This may lead to copying up to 1000 kernel heap pages to the userspace. This has been fixed upstream in https://github.com/torvalds/linux/commit/a45b599ad808c3c982fdcdc12b0b8611c2f92824 already. The problem has limited scope, as users don't usually have permissions to access SCSI devices. On the other hand, e.g. the Nero user manual suggests doing `chmod o+r+w /dev/sg*` to make the devices accessible. NOTE: third parties dispute the relevance of this report, noting that the requirement for an attacker to have both the CAP_SYS_ADMIN and CAP_SYS_RAWIO capabilities makes it "virtually impossible to exploit.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-11359

    Last Modified: 21 Nov 2024

    In Wireshark 2.6.0, 2.4.0 to 2.4.6, and 2.2.0 to 2.2.14, the RRC dissector and other dissectors could crash. This was addressed in epan/proto.c by avoiding a NULL pointer dereference.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-5162

    Last Modified: 21 Nov 2024

    Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

    Published: 18 May 2018
    4.3
    Medium

    CVE-2018-5170

    Last Modified: 21 Nov 2024

    It is possible to spoof the filename of an attachment and display an arbitrary attachment name. This could lead to a user opening a remote attachment which is a different file type than expected. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

    Published: 18 May 2018
    7.5
    High

    CVE-2018-5184

    Last Modified: 21 Nov 2024

    Using remote content in encrypted messages can lead to the disclosure of plaintext. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8.

    Published: 18 May 2018