CVE Feed

    Dashboard / CVE

    7.8
    High

    CVE-2018-6619

    Last Modified: 21 Nov 2024

    Easy Hosting Control Panel (EHCP) v0.37.12.b makes it easier for attackers to crack database passwords by leveraging use of a weak hashing algorithm without a salt.

    Published: 11 May 2018
    7.8
    High

    CVE-2018-6617

    Last Modified: 21 Nov 2024

    Easy Hosting Control Panel (EHCP) v0.37.12.b, when using a local MySQL server, allows attackers to change passwords of arbitrary database users by leveraging failure to ask for the current password.

    Published: 11 May 2018
    6.1
    Medium

    CVE-2018-6362

    Last Modified: 21 Nov 2024

    Easy Hosting Control Panel (EHCP) v0.37.12.b has XSS via the domainop action parameter, as demonstrated by reading the PHPSESSID cookie.

    Published: 11 May 2018
    5.5
    Medium

    CVE-2018-10832

    Last Modified: 21 Nov 2024

    ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.

    Published: 11 May 2018
    6.5
    Medium

    CVE-2018-1278

    Last Modified: 21 Nov 2024

    Apps Manager included in Pivotal Application Service, versions 1.12.x prior to 1.12.22, 2.0.x prior to 2.0.13, and 2.1.x prior to 2.1.4 contains an authorization enforcement vulnerability. A member of any org is able to create invitations to any org for which the org GUID can be discovered. Accepting this invitation gives unauthorized access to view the member list, domains, quotas and other information about the org.

    Published: 11 May 2018
    7.5
    High

    CVE-2018-1280

    Last Modified: 21 Nov 2024

    Pivotal Greenplum Command Center versions 2.x prior to 2.5.1 contains a blind SQL injection vulnerability. An unauthenticated user can perform a SQL injection in the command center which results in disclosure of database contents.

    Published: 11 May 2018
    4.7
    Medium

    CVE-2018-1261

    Last Modified: 21 Nov 2024

    Spring-integration-zip versions prior to 1.0.1 exposes an arbitrary file write vulnerability, which can be achieved using a specially crafted zip archive (affects other archives as well, bzip2, tar, xz, war, cpio, 7z) that holds path traversal filenames. So when the filename gets concatenated to the target extraction directory, the final path ends up outside of the target folder.

    Published: 11 May 2018
    6.7
    Medium

    CVE-2009-5150

    Last Modified: 21 Nov 2024

    Absolute Computrace Agent V80.845 and V80.866 does not have a digital signature for the configuration block, which allows attackers to set up communication with a web site other than the intended search.namequery.com site by modifying data within a disk's inter-partition space. This allows a privileged local user to execute arbitrary code even after that user loses access and all disk partitions are reformatted.

    Published: 11 May 2018
    6.7
    Medium

    CVE-2009-5151

    Last Modified: 21 Nov 2024

    The stub component of Absolute Computrace Agent V70.785 executes code from a disk's inter-partition space without requiring a digital signature for that code, which allows attackers to execute code on the BIOS. This allows a privileged local user to achieve persistent control of BIOS behavior, independent of later disk changes.

    Published: 11 May 2018
    4.1
    Medium

    CVE-2009-5152

    Last Modified: 21 Nov 2024

    Absolute Computrace Agent, as distributed on certain Dell Inspiron systems through 2009, has a race condition with the Dell Client Configuration Utility (DCCU), which allows privileged local users to change Computrace Agent's activation/deactivation status to the factory default via a crafted TaskResult.xml file.

    Published: 11 May 2018
    5.3
    Medium

    CVE-2018-7248

    Last Modified: 21 Nov 2024

    An issue was discovered in Zoho ManageEngine ServiceDesk Plus 9.3 Build 9317. Unauthenticated users are able to validate domain user accounts by sending a request containing the username to an API endpoint. The endpoint will return the user's logon domain if the accounts exists, or 'null' if it does not.

    Published: 11 May 2018
    5.4
    Medium

    CVE-2018-10580

    Last Modified: 21 Nov 2024

    The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

    Published: 11 May 2018
    7.8
    High

    CVE-2017-6015

    Last Modified: 21 Nov 2024

    Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, but not privileged local user to execute arbitrary code with elevated privileges on the system. CVSS v3 base score: 8.8, CVSS vector string: (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Rockwell Automation has released a new version of FactoryTalk Activation, Version 4.01, which addresses the identified vulnerability. Rockwell Automation recommends upgrading to the latest version of FactoryTalk Activation, Version 4.01 or later.

    Published: 11 May 2018
    5.5
    Medium

    CVE-2018-11508

    Last Modified: 21 Nov 2024

    The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.

    Published: 11 May 2018
    7.8
    High

    CVE-2018-12539

    Last Modified: 21 Nov 2024

    In Eclipse OpenJ9 version 0.8, users other than the process owner may be able to use Java Attach API to connect to an Eclipse OpenJ9 or IBM JVM on the same machine and use Attach API operations, which includes the ability to execute untrusted native code. Attach API is enabled by default on Windows, Linux and AIX JVMs and can be disabled using the command line option -Dcom.ibm.tools.attach.enable=no.

    Published: 11 May 2018
    7.8
    High

    CVE-2018-3612

    Last Modified: 21 Nov 2024

    Intel NUC kits with insufficient input validation in system firmware, potentially allows a local attacker to elevate privileges to System Management Mode (SMM).

    Published: 10 May 2018
    Unknown

    CVE-2018-3617

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-3691. Reason: This candidate is a reservation duplicate of CVE-2018-3691. Notes: All CVE users should reference CVE-2018-3691 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 10 May 2018
    7.8
    High

    CVE-2018-3649

    Last Modified: 21 Nov 2024

    DLL injection vulnerability in the installation executables (Autorun.exe and Setup.exe) for Intel's wireless drivers and related software in Intel Dual Band Wireless-AC, Tri-Band Wireless-AC and Wireless-AC family of products allows a local attacker to cause escalation of privilege via remote code execution.

    Published: 10 May 2018
    7.5
    High

    CVE-2018-10706

    Last Modified: 21 Nov 2024

    An integer overflow in the transferMulti function of a smart contract implementation for Social Chain (SCA), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets, aka the "multiOverflow" issue.

    Published: 10 May 2018
    7.5
    High

    CVE-2018-10973

    Last Modified: 21 Nov 2024

    An integer overflow in the transferMulti function of a smart contract implementation for KoreaShow, an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets via crafted _value parameters.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10974

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222100.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10975

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222104.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10976

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222050.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10977

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x002220E4.

    Published: 10 May 2018
    5.5
    Medium

    CVE-2018-10971

    Last Modified: 21 Nov 2024

    An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The Plane function in image/image.hpp allows remote attackers to cause a denial of service (attempted excessive memory allocation) via a crafted file.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10972

    Last Modified: 21 Nov 2024

    An issue was discovered in Free Lossless Image Format (FLIF) 0.3. The TransformPaletteC::process function in transform/palette_C.hpp allows remote attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted file.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10655

    Last Modified: 21 Nov 2024

    DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).

    Published: 10 May 2018
    6.1
    Medium

    CVE-2018-10803

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in the add credentials functionality in Zoho ManageEngine NetFlow Analyzer v12.3 before 12.3.125 (build 123125) allows remote attackers to inject arbitrary web script or HTML via a crafted description value. This can be exploited through CSRF.

    Published: 10 May 2018
    6.2
    Medium

    CVE-2018-7940

    Last Modified: 21 Nov 2024

    Huawei smart phones Mate 10 and Mate 10 Pro with earlier versions than 8.0.0.129(SP2C00) and earlier versions than 8.0.0.129(SP2C01) have an authentication bypass vulnerability. An attacker with high privilege obtains the smart phone and bypass the activation function by some specific operations.

    Published: 10 May 2018
    5.5
    Medium

    CVE-2018-9849

    Last Modified: 21 Nov 2024

    Pulse Secure Pulse Connect Secure 8.1.x before 8.1R14, 8.2.x before 8.2R11, and 8.3.x before 8.3R5 do not properly process nested XML entities, which allows remote attackers to cause a denial of service (memory consumption and memory errors) via a crafted XML document.

    Published: 10 May 2018
    3.3
    Low

    CVE-2018-6254

    Last Modified: 21 Nov 2024

    In Android before the 2018-05-05 security patch level, NVIDIA Media Server contains an out-of-bounds read (due to improper input validation) vulnerability which could lead to local information disclosure. This issue is rated as moderate. Android: A-64340684. Reference: N-CVE-2018-6254.

    Published: 10 May 2018
    7.8
    High

    CVE-2017-6289

    Last Modified: 21 Nov 2024

    In Android before the 2018-05-05 security patch level, NVIDIA Trusted Execution Environment (TEE) contains a memory corruption (due to unusual root cause) vulnerability, which if run within the speculative execution of the TEE, may lead to local escalation of privileges. This issue is rated as critical. Android: A-72830049. Reference: N-CVE-2017-6289.

    Published: 10 May 2018
    7.8
    High

    CVE-2017-6293

    Last Modified: 21 Nov 2024

    In Android before the 2018-05-05 security patch level, NVIDIA Tegra X1 TZ contains a vulnerability in Widevine TA where the software writes data past the end, or before the beginning, of the intended buffer, which may lead to escalation of Privileges. This issue is rated as high. Android: A-69377364. Reference: N-CVE-2017-6293.

    Published: 10 May 2018
    8.8
    High

    CVE-2018-7941

    Last Modified: 21 Nov 2024

    Huawei iBMC V200R002C60 have an authentication bypass vulnerability. A remote attacker with low privilege may craft specific messages to upload authentication certificate to the affected products. Due to improper validation of the upload authority, successful exploit may cause privilege elevation.

    Published: 10 May 2018
    5.3
    Medium

    CVE-2018-6246

    Last Modified: 21 Nov 2024

    In Android before the 2018-05-05 security patch level, NVIDIA Widevine Trustlet contains a vulnerability in Widevine TA where the software reads data past the end, or before the beginning, of the intended buffer, which may lead to Information Disclosure. This issue is rated as moderate. Android: A-69383916. Reference: N-CVE-2018-6246.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-7933

    Last Modified: 21 Nov 2024

    Huawei home gateway products HiRouter-CD20 and WS5200 with the versions before HiRouter-CD20-10 1.9.6 and the versions before WS5200-10 1.9.6 have a path traversal vulnerability. Due to the lack of validation while these home gateway products install APK plugins, an attacker tricks a user into installing a malicious APK plugin, and plugin can overwrite arbitrary file of devices. Successful exploit may result in arbitrary code execution or privilege escalation.

    Published: 10 May 2018
    7.3
    High

    CVE-2018-8914

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in UPnP DMA in Synology Media Server before 1.7.6-2842 and before 1.4-2654 allows remote attackers to execute arbitrary SQL commands via the ObjectID parameter.

    Published: 10 May 2018
    6.5
    Medium

    CVE-2018-8915

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Notification Center in Synology Calendar before 2.1.1-0502 allows remote authenticated users to inject arbitrary web script or HTML via title parameter.

    Published: 10 May 2018
    6.5
    Medium

    CVE-2018-8910

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Attachment Preview in Synology Drive before 1.0.1-10253 allows remote authenticated users to inject arbitrary web script or HTML via malicious attachments.

    Published: 10 May 2018
    7.1
    High

    CVE-2018-8061

    Last Modified: 21 Nov 2024

    HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send IOCTL 0x85FE2608 to the device driver with the HWiNFO32 symbolic device name, resulting in direct physical memory read or write.

    Published: 10 May 2018
    9.8
    Critical

    CVE-2018-8824

    Last Modified: 21 Nov 2024

    modules/bamegamenu/ajax_phpcode.php in the Responsive Mega Menu (Horizontal+Vertical+Dropdown) Pro module 1.0.32 for PrestaShop 1.5.5.0 through 1.7.2.5 allows remote attackers to execute a SQL Injection through function calls in the code parameter.

    Published: 10 May 2018
    5.4
    Medium

    CVE-2018-10314

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.

    Published: 10 May 2018
    5.5
    Medium

    CVE-2018-8060

    Last Modified: 21 Nov 2024

    HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. This affects IOCTLs higher than 0x85FE2600 with the HWiNFO32 symbolic device name.

    Published: 10 May 2018
    9.8
    Critical

    CVE-2018-10942

    Last Modified: 21 Nov 2024

    modules/attributewizardpro/file_upload.php in the Attribute Wizard addon 1.6.9 for PrestaShop 1.4.0.1 through 1.6.1.18 allows remote attackers to execute arbitrary code by uploading a .phtml file.

    Published: 10 May 2018
    5.4
    Medium

    CVE-2018-9111

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15 via the configuration of a user account. An attacker can execute arbitrary script on an unsuspecting user's browser.

    Published: 10 May 2018
    9.8
    Critical

    CVE-2018-9112

    Last Modified: 21 Nov 2024

    A low privileged admin account with a weak default password of admin exists on the Foxconn FEMTO AP-FC4064-T AP_GT_B38_5.8.3lb15-W47 LTE Build 15. In addition, its web management page relies on the existence or values of cookies when performing security-critical operations. One can gain privileges by modifying cookies.

    Published: 10 May 2018
    8.8
    High

    CVE-2018-10957

    Last Modified: 21 Nov 2024

    CSRF exists on D-Link DIR-868L devices, leading to (for example) a change to the Admin password. hedwig.cgi and pigwidgeon.cgi are two of the affected components.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10952

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222088.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10953

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x0022204C.

    Published: 10 May 2018
    7.8
    High

    CVE-2018-10954

    Last Modified: 21 Nov 2024

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x00222550.

    Published: 10 May 2018