CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2017-14465

    Last Modified: 21 Nov 2024

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: REMOTE Description: Any input or output can be forced, causing unpredictable activity from the PLC.

    Published: 5 Apr 2018
    10
    Critical

    CVE-2017-14469

    Last Modified: 21 Nov 2024

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: REMOTE or PROG Associated Fault Code: 0028 Fault Type: Non-User Description: Values 0x01 and 0x02 are invalid values for the user fault routine. By writing directly to the file it is possible to set these values. When this is done and the device is moved into a run state, a fault is triggered. NOTE: This is not possible through RSLogix.

    Published: 5 Apr 2018
    10
    Critical

    CVE-2017-14470

    Last Modified: 21 Nov 2024

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: REMOTE or PROG or RUN Description: The value 0xffffffff is considered NaN for the Float data type. When a float is set to this value and used in the PLC, a fault is triggered. NOTE: This is not possible through RSLogix.

    Published: 5 Apr 2018
    10
    Critical

    CVE-2017-14472

    Last Modified: 21 Nov 2024

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings, or modification of ladder logic. An attacker can send unauthenticated packets to trigger this vulnerability. Required Keyswitch State: Any Description: Requests a specific set of bytes from an undocumented data file and returns the ASCII version of the master password.

    Published: 5 Apr 2018
    6.1
    Medium

    CVE-2018-9328

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Redbus Clone Script 3.0.6 has XSS via the ter_from or tag parameter to results.php.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2017-2869

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the OpenProducer functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in code execution. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2017-2868

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the NewProducerStream functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in code execution. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 5 Apr 2018
    6.5
    Medium

    CVE-2017-12095

    Last Modified: 21 Nov 2024

    An exploitable vulnerability exists in the WiFi Access Point feature of Circle with Disney running firmware 2.0.1. A series of WiFi packets can force Circle to setup an Access Point with default credentials. An attacker needs to send a series of spoofed "de-auth" packets to trigger this vulnerability.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2017-2853

    Last Modified: 21 Nov 2024

    An exploitable Code Execution vulnerability exists in the RequestForPatientInfoEEGfile functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in arbitrary command execution. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 5 Apr 2018
    7.5
    High

    CVE-2017-2861

    Last Modified: 21 Nov 2024

    An exploitable Denial of Service vulnerability exists in the use of a return value in the NewProducerStream command in Natus Xltek NeuroWorks 8. A specially crafted network packet can cause an out of bounds read resulting in a denial of service. An attacker can send a malicious packet to trigger this vulnerability.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2017-2867

    Last Modified: 21 Nov 2024

    An exploitable code execution vulnerability exists in the SavePatientMontage functionality of Natus Xltek NeuroWorks 8. A specially crafted network packet can cause a stack buffer overflow resulting in code execution. An attacker can a malicious packet to trigger this vulnerability.

    Published: 5 Apr 2018
    7.8
    High

    CVE-2017-0431

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32573899.

    Published: 5 Apr 2018
    7.8
    High

    CVE-2016-8482

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the NVIDIA GPU driver. Product: Android. Versions: Android kernel. Android ID: A-31799863. References: N-CVE-2016-8482.

    Published: 5 Apr 2018
    5.3
    Medium

    CVE-2017-0744

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the NVIDIA firmware processing code. Product: Android. Versions: Android kernel. Android ID: A-34112726. References: N-CVE-2017-0744.

    Published: 5 Apr 2018
    5.3
    Medium

    CVE-2017-0748

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Qualcomm audio driver. Product: Android. Versions: Android Kernel. Android ID: A-35764875. References: QC-CR#2029798.

    Published: 5 Apr 2018
    5.3
    Medium

    CVE-2017-0751

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Qualcomm QCE driver. Product: Android. Versions: Android kernel. Android ID: A-36591162. References: QC-CR#2045061.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2014-3413

    Last Modified: 21 Nov 2024

    The MySQL server in Juniper Networks Junos Space before 13.3R1.8 has an unspecified account with a hardcoded password, which allows remote attackers to obtain sensitive information and consequently obtain administrative control by leveraging database access.

    Published: 5 Apr 2018
    7.8
    High

    CVE-2018-9233

    Last Modified: 21 Nov 2024

    Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.

    Published: 5 Apr 2018
    5.5
    Medium

    CVE-2018-4863

    Last Modified: 21 Nov 2024

    Sophos Endpoint Protection 10.7 allows local users to bypass an intended tamper protection mechanism by deleting the HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\Sophos Endpoint Defense\ registry key.

    Published: 5 Apr 2018
    7.3
    High

    CVE-2016-8366

    Last Modified: 21 Nov 2024

    Webvisit in Phoenix Contact ILC PLCs offers a password macro to protect HMI pages on the PLC against casual or coincidental opening of HMI pages by the user. The password macro can be configured in a way that the password is stored and transferred in clear text.

    Published: 5 Apr 2018
    7.3
    High

    CVE-2016-8371

    Last Modified: 21 Nov 2024

    The web server in Phoenix Contact ILC PLCs can be accessed without authenticating even if the authentication mechanism is enabled.

    Published: 5 Apr 2018
    7.3
    High

    CVE-2016-8380

    Last Modified: 21 Nov 2024

    The web server in Phoenix Contact ILC PLCs allows access to read and write PLC variables without authentication.

    Published: 5 Apr 2018
    8.3
    High

    CVE-2018-3624

    Last Modified: 21 Nov 2024

    Buffer overflow in ETWS processing module Intel XMM71xx, XMM72xx, XMM73xx, XMM74xx and Sofia 3G/R allows remote attacker to potentially execute arbitrary code via an adjacent network.

    Published: 5 Apr 2018
    5.4
    Medium

    CVE-2018-7035

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Gleez CMS 1.2.0 and 2.0 might allow remote attackers (users) to inject JavaScript via HTML content in an editor, which will result in Stored XSS when an Administrator tries to edit the same content, as demonstrated by use of the source editor for HTML mode in an Add Blog action.

    Published: 5 Apr 2018
    6.1
    Medium

    CVE-2018-9243

    Last Modified: 21 Nov 2024

    GitLab Community and Enterprise Editions version 8.4 up to 10.4 are vulnerable to XSS because a lack of input validation in the merge request component leads to cross site scripting (specifically, filenames in changes tabs of merge requests). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

    Published: 5 Apr 2018
    6.1
    Medium

    CVE-2018-9244

    Last Modified: 21 Nov 2024

    GitLab Community and Enterprise Editions version 9.2 up to 10.4 are vulnerable to XSS because a lack of input validation in the milestones component leads to cross site scripting (specifically, data-milestone-id in the milestone dropdown feature). This is fixed in 10.6.3, 10.5.7, and 10.4.7.

    Published: 5 Apr 2018
    6.1
    Medium

    CVE-2018-1000144

    Last Modified: 21 Nov 2024

    A cross site scripting vulnerability exists in Jenkins Cucumber Living Documentation Plugin 1.0.12 and older in CukedoctorBaseAction#doDynamic that disables the Content-Security-Policy protection for archived artifacts and workspace files, allowing attackers able to control the content of these files to attack Jenkins users.

    Published: 5 Apr 2018
    6.5
    Medium

    CVE-2018-1000148

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins Copy To Slave Plugin version 1.4.4 and older in CopyToSlaveBuildWrapper.java that allows attackers with permission to configure jobs to read arbitrary files from the Jenkins master file system.

    Published: 5 Apr 2018
    5.6
    Medium

    CVE-2018-1000149

    Last Modified: 21 Nov 2024

    A man in the middle vulnerability exists in Jenkins Ansible Plugin 0.8 and older in AbstractAnsibleInvocation.java, AnsibleAdHocCommandBuilder.java, AnsibleAdHocCommandInvocationTest.java, AnsibleContext.java, AnsibleJobDslExtension.java, AnsiblePlaybookBuilder.java, AnsiblePlaybookStep.java that disables host key verification by default.

    Published: 5 Apr 2018
    3.3
    Low

    CVE-2018-1000150

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins Reverse Proxy Auth Plugin 1.5 and older in ReverseProxySecurityRealm#authContext that allows attackers with local file system access to obtain a list of authorities for logged in users.

    Published: 5 Apr 2018
    5.6
    Medium

    CVE-2018-1000151

    Last Modified: 21 Nov 2024

    A man in the middle vulnerability exists in Jenkins vSphere Plugin 2.16 and older in VSphere.java that disables SSL/TLS certificate validation by default.

    Published: 5 Apr 2018
    6.7
    Medium

    CVE-2018-1000143

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.

    Published: 5 Apr 2018
    6.5
    Medium

    CVE-2018-1000145

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with local file system access to obtain encrypted Perforce passwords and decrypt them.

    Published: 5 Apr 2018
    8.8
    High

    CVE-2018-1000146

    Last Modified: 21 Nov 2024

    An arbitrary code execution vulnerability exists in Liquibase Runner Plugin version 1.3.0 and older that allows an attacker with permission to configure jobs to load and execute arbitrary code on the Jenkins master JVM.

    Published: 5 Apr 2018
    6.3
    Medium

    CVE-2018-1000152

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java, Reconfigure.java, Rename.java, RenameSnapshot.java, RevertToSnapshot.java, SuspendVm.java, TakeSnapshot.java, VSphereBuildStepContainer.java, vSphereCloudProvisionedSlave.java, vSphereCloudSlave.java, vSphereCloudSlaveTemplate.java, VSphereConnectionConfig.java, vSphereStep.java that allows attackers to perform form validation related actions, including sending numerous requests to the configured vSphere server, potentially resulting in denial of service, or send credentials stored in Jenkins with known ID to an attacker-specified server ("test connection").

    Published: 5 Apr 2018
    7.8
    High

    CVE-2018-1000142

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins GitHub Pull Request Builder Plugin version 1.39.0 and older in GhprbCause.java that allows an attacker with local file system access to obtain GitHub credentials.

    Published: 5 Apr 2018
    6.5
    Medium

    CVE-2018-1000147

    Last Modified: 21 Nov 2024

    An exposure of sensitive information vulnerability exists in Jenkins Perforce Plugin version 1.3.36 and older in PerforcePasswordEncryptor.java that allows attackers with insufficient permission to obtain Perforce passwords configured in jobs to obtain them

    Published: 5 Apr 2018
    8.8
    High

    CVE-2018-1000153

    Last Modified: 21 Nov 2024

    A cross-site request forgery vulnerability exists in Jenkins vSphere Plugin 2.16 and older in Clone.java, CloudSelectorParameter.java, ConvertToTemplate.java, ConvertToVm.java, Delete.java, DeleteSnapshot.java, Deploy.java, ExposeGuestInfo.java, FolderVSphereCloudProperty.java, PowerOff.java, PowerOn.java, Reconfigure.java, Rename.java, RenameSnapshot.java, RevertToSnapshot.java, SuspendVm.java, TakeSnapshot.java, VSphereBuildStepContainer.java, vSphereCloudProvisionedSlave.java, vSphereCloudSlave.java, vSphereCloudSlaveTemplate.java, VSphereConnectionConfig.java, vSphereStep.java that allows attackers to perform form validation related actions, including sending numerous requests to the configured vSphere server, potentially resulting in denial of service, or send credentials stored in Jenkins with known ID to an attacker-specified server ("test connection").

    Published: 5 Apr 2018
    6.1
    Medium

    CVE-2018-1000154

    Last Modified: 21 Nov 2024

    Zammad GmbH Zammad version 2.3.0 and earlier contains a Improper Neutralization of Script-Related HTML Tags in a Web Page (CWE-80) vulnerability in the subject of emails which are not html quoted in certain cases. This can result in the embedding and execution of java script code on users browser. This attack appear to be exploitable via the victim openning a ticket. This vulnerability appears to have been fixed in 2.3.1, 2.2.2 and 2.1.3.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2018-9309

    Last Modified: 21 Nov 2024

    An issue was discovered in zzcms 8.2. It allows SQL injection via the id parameter in a dl/dl_sendsms.php request.

    Published: 5 Apr 2018
    6.5
    Medium

    CVE-2018-13785

    Last Modified: 29 May 2026

    In libpng 1.6.34, a wrong calculation of row_factor in the png_check_chunk_length function (pngrutil.c) may trigger an integer overflow and resultant divide-by-zero while processing a crafted PNG file, leading to a denial of service.

    Published: 5 Apr 2018
    7.8
    High

    CVE-2018-1000156

    Last Modified: 14 Apr 2025

    GNU Patch version 2.7.6 contains an input validation vulnerability when processing patch files, specifically the EDITOR_PROGRAM invocation (using ed) can result in code execution. This attack appear to be exploitable via a patch file processed via the patch utility. This is similar to FreeBSD's CVE-2015-1418 however although they share a common ancestry the code bases have diverged over time.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2018-1270

    Last Modified: 21 Nov 2024

    Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to expose STOMP over WebSocket endpoints with a simple, in-memory STOMP broker through the spring-messaging module. A malicious user (or attacker) can craft a message to the broker that can lead to a remote code execution attack.

    Published: 5 Apr 2018
    5.9
    Medium

    CVE-2018-1271

    Last Modified: 21 Nov 2024

    Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, allow applications to configure Spring MVC to serve static resources (e.g. CSS, JS, images). When static resources are served from a file system on Windows (as opposed to the classpath, or the ServletContext), a malicious user can send a request using a specially crafted URL that can lead a directory traversal attack.

    Published: 5 Apr 2018
    7.5
    High

    CVE-2018-1272

    Last Modified: 21 Nov 2024

    Spring Framework, versions 5.0 prior to 5.0.5 and versions 4.3 prior to 4.3.15 and older unsupported versions, provide client-side support for multipart requests. When Spring MVC or Spring WebFlux server application (server A) receives input from a remote client, and then uses that input to make a multipart request to another server (server B), it can be exposed to an attack, where an extra multipart is inserted in the content of the request from server A, causing server B to use the wrong value for a part it expects. This could to lead privilege escalation, for example, if the part content represents a username or user roles.

    Published: 5 Apr 2018
    9.8
    Critical

    CVE-2019-10196

    Last Modified: 21 Nov 2024

    A flaw was found in http-proxy-agent, prior to version 2.1.0. It was discovered http-proxy-agent passes an auth option to the Buffer constructor without proper sanitization. This could result in a Denial of Service through the usage of all available CPU resources and data exposure through an uninitialized memory leak in setups where an attacker could submit typed input to the auth parameter.

    Published: 5 Apr 2018
    5.3
    Medium

    CVE-2018-1081

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle 3.4 to 3.4.1, 3.3 to 3.3.4, 3.2 to 3.2.7, 3.1 to 3.1.10 and earlier unsupported versions. Unauthenticated users can trigger custom messages to admin via paypal enrol script. Paypal IPN callback script should only send error emails to admin after request origin was verified, otherwise admin email can be spammed.

    Published: 4 Apr 2018
    8.1
    High

    CVE-2018-1082

    Last Modified: 21 Nov 2024

    A flaw was found in Moodle 3.4 to 3.4.1, and 3.3 to 3.3.4. If a user account using OAuth2 authentication method was once confirmed but later suspended, the user could still login to the site.

    Published: 4 Apr 2018
    6.1
    Medium

    CVE-2018-9307

    Last Modified: 21 Nov 2024

    dsmall v20180320 allows XSS via the pdr_sn parameter to public/index.php/home/predeposit/index.html.

    Published: 4 Apr 2018
    9.1
    Critical

    CVE-2018-1002150

    Last Modified: 21 Nov 2024

    Koji version 1.12, 1.13, 1.14 and 1.15 contain an incorrect access control vulnerability resulting in arbitrary filesystem read/write access. This vulnerability has been fixed in versions 1.12.1, 1.13.1, 1.14.1 and 1.15.1.

    Published: 4 Apr 2018