CVE Feed

    Dashboard / CVE

    3.7
    Low

    CVE-2017-17314

    Last Modified: 21 Nov 2024

    Huawei DP300 V500R002C00, RP200 V600R006C00, TE30 V100R001C10, V500R002C00, V600R006C00, TE40 V500R002C00, V600R006C00, TE50 V500R002C00, V600R006C00, TE60 V100R001C10, V500R002C00, V600R006C00 have an invalid memory access vulnerability. An unauthenticated attacker has to find a way to send malformed SCCP messages to the affected products. Due to insufficient input validation of some values in the messages, successful exploit may cause buffer error and some service abnormal.

    Published: 30 Apr 2018
    6.5
    Medium

    CVE-2017-17318

    Last Modified: 21 Nov 2024

    Huawei MBB (Mobile Broadband) products E5771h-937 with the versions before E5771h-937TCPU-V200R001B328D62SP00C1133 and the versions before E5771h-937TCPU-V200R001B329D05SP00C1308 have a Denial of Service (DoS) vulnerability. When an attacker accessing device sends special http request to device, the webserver process will try to apply too much memory which can cause the device to become unable to respond. An attacker can launch a DoS attack by exploiting this vulnerability.

    Published: 30 Apr 2018
    4.4
    Medium

    CVE-2018-7901

    Last Modified: 21 Nov 2024

    RCS module in Huawei ALP-AL00B smart phones with software versions earlier than 8.0.0.129, BLA-AL00B smart phones with software versions earlier than 8.0.0.129 has a remote control vulnerability. An attacker can trick a user to install a malicious application. When the application connects with RCS for the first time, it needs user to manually click to agree. In addition, the attacker needs to obtain the key that RCS uses to authenticate the application. Successful exploitation may cause the attacker to control keyboard remotely.

    Published: 30 Apr 2018
    6.1
    Medium

    CVE-2018-0711

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in QNAP QTS 4.3.3 build 20180126, QTS 4.3.4 build 20180315, and their earlier versions could allow remote attackers to inject arbitrary web script or HTML.

    Published: 30 Apr 2018
    6.1
    Medium

    CVE-2017-18262

    Last Modified: 21 Nov 2024

    Blackboard Learn (Since at least 17th of October 2017) has allowed Unvalidated Redirects on any signed-in user through its endpoints for handling Shibboleth logins, as demonstrated by a webapps/bb-auth-provider-shibboleth-BBLEARN/execute/shibbolethLogin?returnUrl= URI.

    Published: 30 Apr 2018
    7.5
    High

    CVE-2018-10550

    Last Modified: 21 Nov 2024

    In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.

    Published: 30 Apr 2018
    6.5
    Medium

    CVE-2018-10553

    Last Modified: 21 Nov 2024

    An issue was discovered in Nagios XI 5.4.13. A registered user is able to use directory traversal to read local files, as demonstrated by URIs beginning with index.php?xiwindow=./ and config/?xiwindow=../ substrings.

    Published: 30 Apr 2018
    5.4
    Medium

    CVE-2018-10554

    Last Modified: 21 Nov 2024

    An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting; (2) includes/components/xicore/downtime.php, related to the update_pages function; (3) the ajaxhelper.php opts or background parameter; (4) the i[] array parameter to ajax_handler.php; or (5) the deploynotification.php title parameter.

    Published: 30 Apr 2018
    7.5
    High

    CVE-2018-20834

    Last Modified: 4 Feb 2026

    A vulnerability was found in node-tar before version 4.4.2 (excluding version 2.2.2). An Arbitrary File Overwrite issue exists when extracting a tarball containing a hardlink to a file that already exists on the system, in conjunction with a later plain file with the same name as the hardlink. This plain file content replaces the existing file content. A patch has been applied to node-tar v2.2.2).

    Published: 30 Apr 2018
    9.8
    Critical

    CVE-2018-9845

    Last Modified: 21 Nov 2024

    Etherpad Lite before 1.6.4 is exploitable for admin access.

    Published: 29 Apr 2018
    5.4
    Medium

    CVE-2018-10527

    Last Modified: 21 Nov 2024

    EasyCMS 1.3 is prone to Stored XSS when posting an article; four fields are affected: title, keyword, abstract, and content, as demonstrated by the /admin/index/index.html#listarticle URI.

    Published: 28 Apr 2018
    7.5
    High

    CVE-2018-10468

    Last Modified: 21 Nov 2024

    The transferFrom function of a smart contract implementation for Useless Ethereum Token (UET), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer all victims' balances into their account) because certain computations involving _value are incorrect, as exploited in the wild starting in December 2017, aka the "transferFlaw" issue.

    Published: 28 Apr 2018
    7.5
    High

    CVE-2017-18263

    Last Modified: 21 Nov 2024

    Seagate Media Server in Seagate Personal Cloud before 4.3.18.4 has directory traversal in getPhotoPlaylistPhotos.psp via a parameter named url.

    Published: 28 Apr 2018
    7.2
    High

    CVE-2018-10515

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted ZIP archive.

    Published: 27 Apr 2018
    6.5
    Medium

    CVE-2018-10516

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "file rename" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by an admin user, that can cause DoS by moving config.php to the upload/ directory.

    Published: 27 Apr 2018
    7.2
    High

    CVE-2018-10517

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

    Published: 27 Apr 2018
    6.5
    Medium

    CVE-2018-10518

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "file delete" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.

    Published: 27 Apr 2018
    6.5
    Medium

    CVE-2018-10520

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "module remove" operation in the admin dashboard contains an arbitrary file deletion vulnerability that can cause DoS, exploitable by an admin user, because the attacker can remove all lib/ files in all directories.

    Published: 27 Apr 2018
    4.9
    Medium

    CVE-2018-10522

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "file view" operation in the admin dashboard contains a sensitive information disclosure vulnerability, exploitable by ordinary users, because the product exposes unrestricted access to the PHP file_get_contents function.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-10519

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) 2.2.7 contains a privilege escalation vulnerability from ordinary user to admin user by arranging for the eff_uid value within $_COOKIE[$this->_loginkey] to equal 1, because files in the tmp/ directory are accessible through HTTP requests. NOTE: this vulnerability exists because of an incorrect fix for CVE-2018-10084.

    Published: 27 Apr 2018
    2.7
    Low

    CVE-2018-10521

    Last Modified: 21 Nov 2024

    In CMS Made Simple (CMSMS) through 2.2.7, the "file move" operation in the admin dashboard contains an arbitrary file movement vulnerability that can cause DoS, exploitable by an admin user, because config.php can be moved into an incorrect directory.

    Published: 27 Apr 2018
    5.3
    Medium

    CVE-2018-10523

    Last Modified: 21 Nov 2024

    CMS Made Simple (CMSMS) through 2.2.7 contains a physical path leakage Vulnerability via /modules/DesignManager/action.ajax_get_templates.php, /modules/DesignManager/action.ajax_get_stylesheets.php, /modules/FileManager/dunzip.php, or /modules/FileManager/untgz.php.

    Published: 27 Apr 2018
    5.3
    Medium

    CVE-2013-5391

    Last Modified: 21 Nov 2024

    IBM Worklight Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.x before 6.0.0 Fix Pack 2, and Mobile Foundation Consumer and Enterprise Editions 5.0.x before 5.0.6 Fix Pack 2 and 6.0.0 Fix Pack 2 make it easier for attackers to defeat cryptographic protection mechanisms by leveraging improper initialization of the pseudo random number generator (PRNG) in Android and use of the Java Cryptography Architecture (JCA) by a Worklight program. IBM X-Force ID: 87128.

    Published: 27 Apr 2018
    8.1
    High

    CVE-2013-7202

    Last Modified: 21 Nov 2024

    The WebHybridClient class in PayPal 5.3 and earlier for Android allows remote attackers to execute arbitrary JavaScript on the system.

    Published: 27 Apr 2018
    5.3
    Medium

    CVE-2014-0841

    Last Modified: 21 Nov 2024

    IBM Rational Focal Point 6.4.0, 6.4.1, 6.5.1, 6.5.2, and 6.6.0 use a weak algorithm to hash passwords, which makes it easier for context-dependent attackers to obtain cleartext values via a brute-force attack. IBM X-Force ID: 90704.

    Published: 27 Apr 2018
    7.8
    High

    CVE-2014-1845

    Last Modified: 21 Nov 2024

    An unspecified setuid root helper in Enlightenment before 0.17.6 allows local users to gain privileges by leveraging failure to properly sanitize the environment.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-10503

    Last Modified: 21 Nov 2024

    An issue was discovered in index.php in baijiacms V4 v4_1_4_20170105. CSRF allows adding an administrator account via op=edituser, changing the administrator password via op=changepwd, or deleting an account via op=deleteuser.

    Published: 27 Apr 2018
    7.8
    High

    CVE-2018-10504

    Last Modified: 21 Nov 2024

    The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2013-5461

    Last Modified: 21 Nov 2024

    IBM Endpoint Manager for Remote Control 9.0.0 and 9.0.1 and Tivoli Remote Control 5.1.2 store multiple hashes of partial passwords, which makes it easier for remote attackers to decrypt passwords by leveraging access to the hashes. IBM X-Force ID: 88309.

    Published: 27 Apr 2018
    5.4
    Medium

    CVE-2013-6739

    Last Modified: 21 Nov 2024

    IBM SPSS Modeler before 16 on UNIX allows remote authenticated users to bypass intended access restrictions via an SSO token. IBM X-Force ID: 89855.

    Published: 27 Apr 2018
    7.4
    High

    CVE-2013-7201

    Last Modified: 21 Nov 2024

    WebHybridClient.java in PayPal 5.3 and earlier for Android ignores SSL errors, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information.

    Published: 27 Apr 2018
    7.8
    High

    CVE-2014-1846

    Last Modified: 21 Nov 2024

    Enlightenment before 0.17.6 might allow local users to gain privileges via vectors involving the gdb method.

    Published: 27 Apr 2018
    9.8
    Critical

    CVE-2014-2552

    Last Modified: 21 Nov 2024

    Brookins Consulting (BC) Collected Information Export extension for eZ Publish 1.1.0 does not properly restrict access, which allows remote attackers to gain access to sensitive data.

    Published: 27 Apr 2018
    5.3
    Medium

    CVE-2015-1857

    Last Modified: 21 Nov 2024

    The odl-mdsal-apidocs feature in OpenDaylight Helium allow remote attackers to obtain sensitive information by leveraging missing AAA restrictions.

    Published: 27 Apr 2018
    7.5
    High

    CVE-2018-7669

    Last Modified: 21 Nov 2024

    An issue was discovered in Sitecore Sitecore.NET 8.1 rev. 151207 Hotfix 141178-1 and above. The 'Log Viewer' application is vulnerable to a directory traversal attack, allowing an attacker to access arbitrary files from the host Operating System using a sitecore/shell/default.aspx?xmlcontrol=LogViewerDetails&file= URI. Validation is performed to ensure that the text passed to the 'file' parameter correlates to the correct log file directory. This filter can be bypassed by including a valid log filename and then appending a traditional 'dot dot' style attack.

    Published: 27 Apr 2018
    9.8
    Critical

    CVE-2018-1475

    Last Modified: 21 Nov 2024

    IBM BigFix Platform 9.2 and 9.5 uses an inadequate account lockout setting that could allow a remote attacker to brute force account credentials. IBM X-Force ID: 140756.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-1479

    Last Modified: 21 Nov 2024

    IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 140761.

    Published: 27 Apr 2018
    Unknown

    CVE-2018-1471

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 27 Apr 2018
    4.3
    Medium

    CVE-2017-1116

    Last Modified: 21 Nov 2024

    IBM Campaign 8.6, 9.0, 9.1, 9.1.1, 9.1.2, and 10.0 contains excessive details on the client side which could provide information useful for an authenticated user to conduct other attacks. IBM X-Force ID: 121154.

    Published: 27 Apr 2018
    6.1
    Medium

    CVE-2018-1473

    Last Modified: 21 Nov 2024

    IBM BigFix Platform 9.2 and 9.5 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 140691.

    Published: 27 Apr 2018
    9.8
    Critical

    CVE-2018-10469

    Last Modified: 21 Nov 2024

    b3log Symphony (aka Sym) 2.6.0 allows remote attackers to upload and execute arbitrary JSP files via the name[] parameter to the /upload URI.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-10529

    Last Modified: 21 Nov 2024

    An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and libraw_cxx.cpp.

    Published: 27 Apr 2018
    7.2
    High

    CVE-2018-1101

    Last Modified: 21 Nov 2024

    Ansible Tower before version 3.2.4 has a flaw in the management of system and organization administrators that allows for privilege escalation. System administrators that are members of organizations can have their passwords reset by organization administrators, allowing organization administrators access to the entire system.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-1102

    Last Modified: 21 Nov 2024

    A flaw was found in source-to-image function as shipped with Openshift Enterprise 3.x. An improper path validation of tar files in ExtractTarStreamFromTarReader in tar/tar.go leads to privilege escalation.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-1000400

    Last Modified: 21 Nov 2024

    Kubernetes CRI-O version prior to 1.9 contains a Privilege Context Switching Error (CWE-270) vulnerability in the handling of ambient capabilities that can result in containers running with elevated privileges, allowing users abilities they should not have. This attack appears to be exploitable via container execution. This vulnerability appears to have been fixed in 1.9.

    Published: 27 Apr 2018
    5.3
    Medium

    CVE-2018-14636

    Last Modified: 21 Nov 2024

    Live-migrated instances are briefly able to inspect traffic for other instances on the same hypervisor. This brief window could be extended indefinitely if the instance's port is set administratively down prior to live-migration and kept down after the migration is complete. This is possible due to the Open vSwitch integration bridge being connected to the instance during migration. When connected to the integration bridge, all traffic for instances using the same Open vSwitch instance would potentially be visible to the migrated guest, as the required Open vSwitch VLAN filters are only applied post-migration. Versions of openstack-neutron before 13.0.0.0b2, 12.0.3, 11.0.5 are vulnerable.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-10528

    Last Modified: 21 Nov 2024

    An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp.

    Published: 27 Apr 2018
    6.5
    Medium

    CVE-2018-1070

    Last Modified: 21 Nov 2024

    routing before version 3.10 is vulnerable to an improper input validation of the Openshift Routing configuration which can cause an entire shard to be brought down. A malicious user can use this vulnerability to cause a Denial of Service attack for other users of the router shard.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-1104

    Last Modified: 21 Nov 2024

    Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server.

    Published: 27 Apr 2018
    8.8
    High

    CVE-2018-3845

    Last Modified: 21 Nov 2024

    In Hyland Perceptive Document Filters 11.4.0.2647 - x86/x64 Windows/Linux, a crafted OpenDocument document can lead to a SkCanvas object double free resulting in direct code execution.

    Published: 26 Apr 2018