CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2018-9034

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.

    Published: 4 Apr 2018
    9.6
    Critical

    CVE-2018-9035

    Last Modified: 21 Nov 2024

    CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-9126

    Last Modified: 21 Nov 2024

    The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.

    Published: 4 Apr 2018
    5.3
    Medium

    CVE-2018-8719

    Last Modified: 21 Nov 2024

    An issue was discovered in the WP Security Audit Log plugin 3.1.1 for WordPress. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. For example, these files are indexed by Google and allows for attackers to possibly find sensitive information.

    Published: 4 Apr 2018
    5.3
    Medium

    CVE-2018-9115

    Last Modified: 21 Nov 2024

    Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-9284

    Last Modified: 21 Nov 2024

    authentication.cgi on D-Link DIR-868L devices with Singapore StarHub firmware before v1.21SHCb03 allows remote attackers to execute arbitrary code.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-9285

    Last Modified: 21 Nov 2024

    Main_Analysis_Content.asp in /apply.cgi on ASUS RT-AC66U, RT-AC68U, RT-AC86U, RT-AC88U, RT-AC1900, RT-AC2900, and RT-AC3100 devices before 3.0.0.4.384_10007; RT-N18U devices before 3.0.0.4.382.39935; RT-AC87U and RT-AC3200 devices before 3.0.0.4.382.50010; and RT-AC5300 devices before 3.0.0.4.384.20287 allows OS command injection via the pingCNT and destIP fields of the SystemCmd variable.

    Published: 4 Apr 2018
    7.1
    High

    CVE-2018-1421

    Last Modified: 21 Nov 2024

    IBM WebSphere DataPower Appliances 7.1, 7.2, 7.5, 7.5.1, 7.5.2, and 7.6 is vulnerable to a XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 139023.

    Published: 4 Apr 2018
    5.1
    Medium

    CVE-2018-1447

    Last Modified: 21 Nov 2024

    The GSKit (IBM Spectrum Protect 7.1 and 7.2) and (IBM Spectrum Protect Snapshot 4.1.3, 4.1.4, and 4.1.6) CMS KDB logic fails to salt the hash function resulting in weaker than expected protection of passwords. A weak password may be recovered. Note: After update the customer should change password to ensure the new password is stored more securely. Products should encourage customers to take this step as a high priority action. IBM X-Force ID: 139972.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-8487

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823724.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9959

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36383694.

    Published: 4 Apr 2018
    7.8
    High

    CVE-2016-10231

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Qualcomm sound codec driver. Product: Android. Versions: Android kernel. Android ID: A-33966912. References: QC-CR#1096799.

    Published: 4 Apr 2018
    5.5
    Medium

    CVE-2016-10234

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Qualcomm IPA driver. Product: Android. Versions: Android kernel. Android ID: A-34390017. References: QC-CR#1069060.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-10298

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393252.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2016-8486

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823691.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9012

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384691.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9013

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393251.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-10230

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability in the Qualcomm crypto driver. Product: Android. Versions: Android kernel. Android ID: A-34389927. References: QC-CR#1091408.

    Published: 4 Apr 2018
    7
    High

    CVE-2017-6423

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Qualcomm kyro L2 driver. Product: Android. Versions: Android kernel. Android ID: A-32831370. References: QC-CR#1103158.

    Published: 4 Apr 2018
    8.2
    High

    CVE-2018-9275

    Last Modified: 21 Nov 2024

    In check_user_token in util.c in the Yubico PAM module (aka pam_yubico) 2.18 through 2.25, successful logins can leak file descriptors to the auth mapping file, which can lead to information disclosure (serial number of a device) and/or DoS (reaching the maximum number of file descriptors).

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-1469

    Last Modified: 21 Nov 2024

    IBM API Connect Developer Portal 5.0.0.0 through 5.0.8.2 could allow an unauthenticated attacker to execute system commands using specially crafted HTTP requests. IBM X-Force ID: 140605.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9953

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714770.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9954

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36388559.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9955

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384686.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9956

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36389611.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9957

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36387564.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2014-9958

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384774.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9008

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36384689.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9009

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393600.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9010

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393101.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9011

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714882.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2015-9014

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36393750.

    Published: 4 Apr 2018
    7.8
    High

    CVE-2015-9015

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-36714120.

    Published: 4 Apr 2018
    3.3
    Low

    CVE-2016-10236

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Qualcomm USB driver. Product: Android. Versions: Android kernel. Android ID: A-33280689. References: QC-CR#1102418.

    Published: 4 Apr 2018
    7.8
    High

    CVE-2016-10232

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34386696. References: QC-CR#1024872.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-10233

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-34389926. References: QC-CR#897452.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2016-10235

    Last Modified: 21 Nov 2024

    A denial of service vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-34390620. References: QC-CR#1046409.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-10299

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-32577244.

    Published: 4 Apr 2018
    7.5
    High

    CVE-2016-8485

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823681.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-8484

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-28823575.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2016-8488

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in Qualcomm closed source components. Product: Android. Versions: Android kernel. Android ID: A-31625756.

    Published: 4 Apr 2018
    4.2
    Medium

    CVE-2017-1624

    Last Modified: 21 Nov 2024

    IBM QRadar 7.3 and 7.3.1 specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors. IBM X-Force ID: 133122.

    Published: 4 Apr 2018
    4
    Medium

    CVE-2017-1733

    Last Modified: 21 Nov 2024

    IBM QRadar 7.3 stores potentially sensitive information in log files that could be read by a local user. IBM X-Force ID: 134914.

    Published: 4 Apr 2018
    3.3
    Low

    CVE-2017-6425

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Qualcomm video driver. Product: Android. Versions: Android kernel. Android ID: A-32577085. References: QC-CR#1103689.

    Published: 4 Apr 2018
    3.3
    Low

    CVE-2017-6426

    Last Modified: 21 Nov 2024

    An information disclosure vulnerability in the Qualcomm SPMI driver. Product: Android. Versions: Android kernel. Android ID: A-33644474. References: QC-CR#1106842.

    Published: 4 Apr 2018
    6.1
    Medium

    CVE-2017-1772

    Last Modified: 21 Nov 2024

    IBM Worklight (IBM MobileFirst Platform Foundation 6.3, 7.0, 7.1, and 8.0) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 136786.

    Published: 4 Apr 2018
    7
    High

    CVE-2017-6424

    Last Modified: 21 Nov 2024

    An elevation of privilege vulnerability in the Qualcomm WiFi driver. Product: Android. Versions: Android kernel. Android ID: A-32086742. References: QC-CR#1102648.

    Published: 4 Apr 2018
    9.8
    Critical

    CVE-2018-6873

    Last Modified: 21 Nov 2024

    The Auth0 authentication service before 2017-10-15 allows privilege escalation because the JWT audience is not validated.

    Published: 4 Apr 2018
    8.8
    High

    CVE-2018-6874

    Last Modified: 21 Nov 2024

    CSRF exists in the Auth0 authentication service through 14591 if the Legacy Lock API flag is enabled.

    Published: 4 Apr 2018
    7.8
    High

    CVE-2017-13252

    Last Modified: 21 Nov 2024

    In CryptoHal::decrypt of CryptoHal.cpp, there is an out of bounds write due to improper input validation that results in a read from uninitialized memory. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Product: Android. Versions: 8.0, 8.1. Android ID: A-70526702.

    Published: 4 Apr 2018