CVE Feed

    Dashboard / CVE

    8
    High

    CVE-2017-6323

    Last Modified: 21 Nov 2024

    The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

    Published: 16 Apr 2018
    6.1
    Medium

    CVE-2018-10135

    Last Modified: 21 Nov 2024

    iScripts eSwap v2.4 has Reflected XSS via the "catwiseproducts.php" catid parameter in the User Panel.

    Published: 16 Apr 2018
    6.1
    Medium

    CVE-2018-10136

    Last Modified: 21 Nov 2024

    iScripts UberforX 2.2 has Stored XSS in the "manage_settings" section of the Admin Panel via a value field to the /cms?section=manage_settings&action=edit URI.

    Published: 16 Apr 2018
    8.8
    High

    CVE-2018-10137

    Last Modified: 21 Nov 2024

    iScripts UberforX 2.2 has CSRF in the "manage_settings" section of the Admin Panel via the /cms?section=manage_settings&action=edit URI.

    Published: 16 Apr 2018
    5.4
    Medium

    CVE-2015-1952

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in IBM AppScan Enterprise Edition 9.0.x before 9.0.2 iFix 001 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 103416.

    Published: 16 Apr 2018
    8.8
    High

    CVE-2018-10127

    Last Modified: 21 Nov 2024

    An issue was discovered in XYHCMS 3.5. It has CSRF via an index.php?g=Manage&m=Rbac&a=addUser request, resulting in addition of an account with the administrator role.

    Published: 16 Apr 2018
    6.1
    Medium

    CVE-2018-10128

    Last Modified: 21 Nov 2024

    An issue was discovered in XYHCMS 3.5. It has XSS via the test parameter to index.php.

    Published: 16 Apr 2018
    8.8
    High

    CVE-2018-10132

    Last Modified: 21 Nov 2024

    PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter.

    Published: 16 Apr 2018
    9.8
    Critical

    CVE-2018-10133

    Last Modified: 21 Nov 2024

    PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php.

    Published: 16 Apr 2018
    5.4
    Medium

    CVE-2018-0551

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.1 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Apr 2018
    7.8
    High

    CVE-2018-0562

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Installer of SoundEngine Free ver.5.21 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 16 Apr 2018
    4.3
    Medium

    CVE-2018-0531

    Last Modified: 21 Nov 2024

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to view or alter an access privilege of a folder and/or notification settings via unspecified vectors.

    Published: 16 Apr 2018
    2.7
    Low

    CVE-2018-0532

    Last Modified: 21 Nov 2024

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of the Standard database via unspecified vectors.

    Published: 16 Apr 2018
    6.5
    Medium

    CVE-2018-0560

    Last Modified: 21 Nov 2024

    Hatena Bookmark App for iOS Version 3.0 to 3.70 allows remote attackers to spoof the address bar via vectors related to URL display.

    Published: 16 Apr 2018
    8.8
    High

    CVE-2018-0530

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the Cybozu Garoon 3.5.0 to 4.2.6 allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 16 Apr 2018
    4.9
    Medium

    CVE-2018-0533

    Last Modified: 21 Nov 2024

    Cybozu Garoon 3.0.0 to 4.2.6 allows remote authenticated attackers to bypass access restriction to alter setting data of session authentication via unspecified vectors.

    Published: 16 Apr 2018
    4.3
    Medium

    CVE-2018-0548

    Last Modified: 21 Nov 2024

    Cybozu Garoon 4.0.0 to 4.6.0 allows remote authenticated attackers to bypass access restriction to view the closed title of "Space" via unspecified vectors.

    Published: 16 Apr 2018
    5.4
    Medium

    CVE-2018-0549

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in Cybozu Garoon 3.0.0 to 4.6.0 allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 16 Apr 2018
    4.3
    Medium

    CVE-2018-0550

    Last Modified: 21 Nov 2024

    Cybozu Garoon 3.5.0 to 4.6.1 allows remote authenticated attackers to bypass access restriction to view the closed title of "Cabinet" via unspecified vectors.

    Published: 16 Apr 2018
    7.8
    High

    CVE-2018-0561

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in The installer of PhishWall Client Internet Explorer edition Ver. 3.7.15 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 16 Apr 2018
    6.1
    Medium

    CVE-2018-10107

    Last Modified: 21 Nov 2024

    D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.

    Published: 16 Apr 2018
    6.1
    Medium

    CVE-2018-10108

    Last Modified: 21 Nov 2024

    D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.

    Published: 16 Apr 2018
    9.8
    Critical

    CVE-2018-10106

    Last Modified: 21 Nov 2024

    D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.php?a=%0a_POST_SERVICES%3DDEVICE.ACCOUNT%0aAUTHORIZED_GROUP%3D1 request.

    Published: 16 Apr 2018
    7.5
    High

    CVE-2018-10122

    Last Modified: 21 Nov 2024

    QingDao Nature Easy Soft Chanzhi Enterprise Portal System (aka chanzhieps) pro1.6 allows remote attackers to read arbitrary files via directory traversal sequences in the pathname parameter to www/file.php.

    Published: 16 Apr 2018
    5.9
    Medium

    CVE-2018-0737

    Last Modified: 21 Nov 2024

    The OpenSSL RSA Key generation algorithm has been shown to be vulnerable to a cache timing side channel attack. An attacker with sufficient access to mount cache timing attacks during the RSA key generation process could recover the private key. Fixed in OpenSSL 1.1.0i-dev (Affected 1.1.0-1.1.0h). Fixed in OpenSSL 1.0.2p-dev (Affected 1.0.2b-1.0.2o).

    Published: 16 Apr 2018
    5
    Medium

    CVE-2018-10876

    Last Modified: 21 Nov 2024

    A flaw was found in Linux kernel in the ext4 filesystem code. A use-after-free is possible in ext4_ext_remove_space() function when mounting and operating a crafted ext4 image.

    Published: 16 Apr 2018
    7.3
    High

    CVE-2018-10877

    Last Modified: 21 Nov 2024

    Linux kernel ext4 filesystem is vulnerable to an out-of-bound access in the ext4_ext_drop_refs() function when operating on a crafted ext4 filesystem image.

    Published: 16 Apr 2018
    4.8
    Medium

    CVE-2018-10121

    Last Modified: 21 Nov 2024

    plugins/box/pages/pages.admin.php in Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the title section of an admin/index.php?id=pages&action=edit_page&name=error404 (aka Edit 404 page) action.

    Published: 15 Apr 2018
    4.8
    Medium

    CVE-2018-9169

    Last Modified: 21 Nov 2024

    Z-BlogPHP 1.5.1 has XSS via the zb_users/plugin/AppCentre/plugin_edit.php app_id parameter. The component must be accessed directly by an administrator, or through CSRF.

    Published: 15 Apr 2018
    7.2
    High

    CVE-2018-9153

    Last Modified: 21 Nov 2024

    The plugin upload component in Z-BlogPHP 1.5.1 allows remote attackers to execute arbitrary PHP code via the app_id parameter to zb_users/plugin/AppCentre/plugin_edit.php because of an unanchored regular expression, a different vulnerability than CVE-2018-8893. The component must be accessed directly by an administrator, or through CSRF.

    Published: 15 Apr 2018
    4.8
    Medium

    CVE-2018-10118

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.

    Published: 15 Apr 2018
    8.8
    High

    CVE-2018-10117

    Last Modified: 21 Nov 2024

    An issue was discovered in idreamsoft iCMS V7.0.7. There is a CSRF vulnerability that can add an admin account via admincp.php?app=members&do=save&frame=iPHP.

    Published: 15 Apr 2018
    6.1
    Medium

    CVE-2018-10100

    Last Modified: 21 Nov 2024

    Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.

    Published: 14 Apr 2018
    6.1
    Medium

    CVE-2018-10101

    Last Modified: 21 Nov 2024

    Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.

    Published: 14 Apr 2018
    4.8
    Medium

    CVE-2018-10109

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.

    Published: 14 Apr 2018
    6.1
    Medium

    CVE-2018-10102

    Last Modified: 21 Nov 2024

    Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.

    Published: 14 Apr 2018
    7.5
    High

    CVE-2018-10111

    Last Modified: 21 Nov 2024

    An issue was discovered in GEGL through 0.3.32. The render_rectangle function in process/gegl-processor.c has unbounded memory allocation, leading to a denial of service (application crash) upon allocation failure.

    Published: 14 Apr 2018
    8.8
    High

    CVE-2018-10114

    Last Modified: 21 Nov 2024

    An issue was discovered in GEGL through 0.3.32. The gegl_buffer_iterate_read_simple function in buffer/gegl-buffer-access.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PPM file, related to improper restrictions on memory allocation in the ppm_load_read_header function in operations/external/ppm-load.c.

    Published: 14 Apr 2018
    6.5
    Medium

    CVE-2018-10373

    Last Modified: 21 Nov 2024

    concat_filename in dwarf2.c in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.30, allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted binary file, as demonstrated by nm-new.

    Published: 14 Apr 2018
    9.8
    Critical

    CVE-2018-6797

    Last Modified: 21 Nov 2024

    An issue was discovered in Perl 5.18 through 5.26. A crafted regular expression can cause a heap-based buffer overflow, with control over the bytes written.

    Published: 14 Apr 2018
    8.8
    High

    CVE-2018-10112

    Last Modified: 21 Nov 2024

    An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_swap_constructed function in buffer/gegl-tile-backend-swap.c allows remote attackers to cause a denial of service (write access violation) or possibly have unspecified other impact via a malformed PNG file that is mishandled during a call to the babl_format_get_bytes_per_pixel function in babl-format.c in babl 0.1.46.

    Published: 14 Apr 2018
    7.5
    High

    CVE-2018-10113

    Last Modified: 21 Nov 2024

    An issue was discovered in GEGL through 0.3.32. The process function in operations/external/ppm-load.c has unbounded memory allocation, leading to a denial of service (application crash) upon allocation failure.

    Published: 14 Apr 2018
    9.8
    Critical

    CVE-2018-6913

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in the pack function in Perl before 5.26.2 allows context-dependent attackers to execute arbitrary code via a large item count.

    Published: 14 Apr 2018
    5.5
    Medium

    CVE-2018-10372

    Last Modified: 21 Nov 2024

    process_cu_tu_index in dwarf.c in GNU Binutils 2.30 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted binary file, as demonstrated by readelf.

    Published: 14 Apr 2018
    7.5
    High

    CVE-2018-6798

    Last Modified: 21 Nov 2024

    An issue was discovered in Perl 5.22 through 5.26. Matching a crafted locale dependent regular expression can cause a heap-based buffer over-read and potentially information disclosure.

    Published: 14 Apr 2018
    6.1
    Medium

    CVE-2018-10097

    Last Modified: 21 Nov 2024

    XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.

    Published: 13 Apr 2018
    5.3
    Medium

    CVE-2014-1686

    Last Modified: 21 Nov 2024

    MediaWiki 1.18.0 allows remote attackers to obtain the installation path via vectors related to thumbnail creation.

    Published: 13 Apr 2018
    7.5
    High

    CVE-2014-2069

    Last Modified: 21 Nov 2024

    Absolute path traversal vulnerability in Eshtery CMS allows remote attackers to read arbitrary files via a full pathname in the file parameter to FileManager.aspx.

    Published: 13 Apr 2018
    Unknown

    CVE-2018-1000171

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-9092. Reason: This candidate is a reservation duplicate of CVE-2018-9092. Notes: All CVE users should reference CVE-2018-9092 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Apr 2018
    5.5
    Medium

    CVE-2018-4173

    Last Modified: 21 Nov 2024

    An issue was discovered in certain Apple products. iOS before 11.3 is affected. macOS before 10.13.4 is affected. The issue involves the "Status Bar" component. It allows invisible microphone access via a crafted app.

    Published: 13 Apr 2018