CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2018-14567

    Last Modified: 21 Nov 2024

    libxml2 2.9.8, if --with-lzma is used, allows remote attackers to cause a denial of service (infinite loop) via a crafted XML file that triggers LZMA_MEMLIMIT_ERROR, as demonstrated by xmllint, a different vulnerability than CVE-2015-8035 and CVE-2018-9251.

    Published: 3 Apr 2018
    9.8
    Critical

    CVE-2018-9230

    Last Modified: 21 Nov 2024

    In OpenResty through 1.13.6.1, URI parameters are obtained using the ngx.req.get_uri_args and ngx.req.get_post_args functions that ignore parameters beyond the hundredth one, which might allow remote attackers to bypass intended access restrictions or interfere with certain Web Application Firewall (ngx_lua_waf or X-WAF) products. NOTE: the vendor has reported that 100 parameters is an intentional default setting, but is adjustable within the API. The vendor's position is that a security-relevant misuse of the API by a WAF product is a vulnerability in the WAF product, not a vulnerability in OpenResty

    Published: 2 Apr 2018
    9.8
    Critical

    CVE-2018-9127

    Last Modified: 21 Nov 2024

    Botan 2.2.0 - 2.4.0 (fixed in 2.5.0) improperly handled wildcard certificates and could accept certain certificates as valid for hostnames when, under RFC 6125 rules, they should not match. This only affects certificates issued to the same domain as the host, so to impersonate a host one must already have a wildcard certificate matching other hosts in the same domain. For example, b*.example.com would match some hostnames that do not begin with a 'b' character.

    Published: 2 Apr 2018
    3.7
    Low

    CVE-2018-6659

    Last Modified: 21 Nov 2024

    Reflected Cross-Site Scripting vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows remote authenticated users to exploit an XSS issue via not sanitizing the user input.

    Published: 2 Apr 2018
    9.8
    Critical

    CVE-2016-8717

    Last Modified: 21 Nov 2024

    An exploitable Use of Hard-coded Credentials vulnerability exists in the Moxa AWK-3131A Wireless Access Point running firmware 1.1. The device operating system contains an undocumented, privileged (root) account with hard-coded credentials, giving attackers full control of affected devices.

    Published: 2 Apr 2018
    8.8
    High

    CVE-2018-6247

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference may lead to denial of service or possible escalation of privileges.

    Published: 2 Apr 2018
    8.8
    High

    CVE-2018-6248

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software uses a sequential operation to read or write a buffer, but it uses an incorrect length value that causes it to access memory that is outside of the bounds of the buffer which may lead to denial of service or possible escalation of privileges.

    Published: 2 Apr 2018
    8.8
    High

    CVE-2018-6249

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver contains a vulnerability in kernel mode layer handler where a NULL pointer dereference may lead to denial of service or potential escalation of privileges.

    Published: 2 Apr 2018
    8.8
    High

    CVE-2018-6250

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer (nvlddmkm.sys) handler for DxgkDdiEscape where a NULL pointer dereference occurs which may lead to denial of service or possible escalation of privileges.

    Published: 2 Apr 2018
    7.8
    High

    CVE-2018-6251

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver contains a vulnerability in the DirectX 10 Usermode driver, where a specially crafted pixel shader can cause writing to unallocated memory, leading to denial of service or potential code execution.

    Published: 2 Apr 2018
    5.5
    Medium

    CVE-2018-6252

    Last Modified: 21 Nov 2024

    NVIDIA Windows GPU Display Driver contains a vulnerability in the kernel mode layer handler for DxgkDdiEscape where the software allows an actor access to restricted functionality that is unnecessary to production usage, and which may result in denial of service.

    Published: 2 Apr 2018
    5.5
    Medium

    CVE-2018-6253

    Last Modified: 21 Nov 2024

    NVIDIA GPU Display Driver contains a vulnerability in the DirectX and OpenGL Usermode drivers where a specially crafted pixel shader can cause infinite recursion leading to denial of service.

    Published: 2 Apr 2018
    5.4
    Medium

    CVE-2018-9183

    Last Modified: 21 Nov 2024

    The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.

    Published: 2 Apr 2018
    7.8
    High

    CVE-2018-0194

    Last Modified: 29 Nov 2024

    Multiple vulnerabilities in the CLI parser of Cisco IOS XE Software could allow an authenticated, local attacker to inject arbitrary commands into the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell of an affected device and execute commands with root privileges on the device. The vulnerabilities exist because the affected software does not sufficiently sanitize command arguments before passing commands to the Linux shell for execution. An attacker could exploit these vulnerabilities by submitting a malicious CLI command to the affected software. A successful exploit could allow the attacker to break from the CLI of the affected software, which could allow the attacker to gain access to the underlying Linux shell on an affected device and execute arbitrary commands with root privileges on the device. Cisco Bug IDs: CSCuz03145, CSCuz56419, CSCva31971, CSCvb09542.

    Published: 2 Apr 2018
    7.8
    High

    CVE-2018-1038

    Last Modified: 21 Nov 2024

    The Windows kernel in Windows 7 SP1 and Windows Server 2008 R2 SP1 allows an elevation of privilege vulnerability due to the way it handles objects in memory, aka "Windows Kernel Elevation of Privilege Vulnerability."

    Published: 2 Apr 2018
    7.8
    High

    CVE-2018-6661

    Last Modified: 21 Nov 2024

    DLL Side-Loading vulnerability in Microsoft Windows Client in McAfee True Key before 4.20.110 allows local users to gain privilege elevation via not verifying a particular DLL file signature.

    Published: 2 Apr 2018
    6.2
    Medium

    CVE-2018-6660

    Last Modified: 21 Nov 2024

    Directory Traversal vulnerability in McAfee ePolicy Orchestrator (ePO) 5.3.2, 5.3.1, 5.3.0 and 5.9.0 allows administrators to use Windows alternate data streams, which could be used to bypass the file extensions, via not properly validating the path when exporting a particular XML file.

    Published: 2 Apr 2018
    5.4
    Medium

    CVE-2018-9163

    Last Modified: 21 Nov 2024

    A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.

    Published: 2 Apr 2018
    6.1
    Medium

    CVE-2018-9173

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.

    Published: 2 Apr 2018
    9.8
    Critical

    CVE-2018-9174

    Last Modified: 21 Nov 2024

    sys_verifies.php in DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the refiles array parameter, because the contents of modifytmp.inc are under an attacker's control.

    Published: 2 Apr 2018
    9.8
    Critical

    CVE-2018-9175

    Last Modified: 21 Nov 2024

    DedeCMS 5.7 allows remote attackers to execute arbitrary PHP code via the egroup parameter to uploads/dede/stepselect_main.php because code within the database is accessible to uploads/dede/sys_cache_up.php.

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9197

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9198

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9199

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9200

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9201

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9202

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9203

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9204

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    6.5
    Medium

    CVE-2018-9252

    Last Modified: 21 Nov 2024

    JasPer 2.0.14 allows denial of service via a reachable assertion in the function jpc_abstorelstepsize in libjasper/jpc/jpc_enc.c.

    Published: 2 Apr 2018
    Unknown

    CVE-2018-9196

    Last Modified: 17 Mar 2025

    Not used

    Published: 2 Apr 2018
    9.8
    Critical

    CVE-2018-1295

    Last Modified: 21 Nov 2024

    In Apache Ignite 2.3 or earlier, the serialization mechanism does not have a list of classes allowed for serialization/deserialization, which makes it possible to run arbitrary code when 3-rd party vulnerable classes are present in Ignite classpath. The vulnerability can be exploited if the one sends a specially prepared form of a serialized object to one of the deserialization endpoints of some Ignite components - discovery SPI, Ignite persistence, Memcached endpoint, socket steamer.

    Published: 2 Apr 2018
    5.4
    Medium

    CVE-2018-9172

    Last Modified: 21 Nov 2024

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

    Published: 1 Apr 2018
    6.8
    Medium

    CVE-2018-9149

    Last Modified: 21 Nov 2024

    The Zyxel Multy X (AC3000 Tri-Band WiFi System) device doesn't use a suitable mechanism to protect the UART. After an attacker dismantles the device and uses a USB-to-UART cable to connect the device, he can use the 1234 password for the root account to login to the system. Furthermore, an attacker can start the device's TELNET service as a backdoor.

    Published: 1 Apr 2018
    7.5
    High

    CVE-2018-9157

    Last Modified: 21 Nov 2024

    An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionality

    Published: 1 Apr 2018
    4.3
    Medium

    CVE-2018-6849

    Last Modified: 21 Nov 2024

    In the WebRTC component in DuckDuckGo 4.2.0, after visiting a web site that attempts to gather complete client information (such as https://ip.voidsec.com), the browser can disclose a private IP address in a STUN request.

    Published: 1 Apr 2018
    7.5
    High

    CVE-2018-9156

    Last Modified: 21 Nov 2024

    An issue was discovered on AXIS P1354 (IP camera) Firmware version 5.90.1.1 devices. The upload web page doesn't verify the file type, and an attacker can upload a webshell by making a fileUpload.shtml request for a custom .shtml file, which is interpreted by the Apache HTTP Server mod_include module with "<!--#exec cmd=" support. The file needs to include a specific string to meet the internal system architecture. After the webshell upload, an attacker can use the webshell to perform remote code execution such as running a system command (ls, ping, cat /etc/passwd, etc.). NOTE: the vendor reportedly indicates that this is an intended feature or functionality

    Published: 1 Apr 2018
    7.5
    High

    CVE-2018-9158

    Last Modified: 21 Nov 2024

    An issue was discovered on AXIS M1033-W (IP camera) Firmware version 5.40.5.1 devices. They don't employ a suitable mechanism to prevent a DoS attack, which leads to a response time delay. An attacker can use the hping3 tool to perform an IPv4 flood attack, and the services are interrupted from attack start to end.

    Published: 1 Apr 2018
    6.5
    Medium

    CVE-2018-9165

    Last Modified: 21 Nov 2024

    The pushdup function in util/decompile.c in libming through 0.4.8 does not recognize the need for ActionPushDuplicate to perform a deep copy when a String is at the top of the stack, making the library vulnerable to a util/decompile.c getName NULL pointer dereference, which may allow attackers to cause a denial of service via a crafted SWF file.

    Published: 1 Apr 2018
    7.8
    High

    CVE-2018-9128

    Last Modified: 21 Nov 2024

    DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.

    Published: 1 Apr 2018
    8.8
    High

    CVE-2018-8893

    Last Modified: 21 Nov 2024

    Z-BlogPHP 1.5.1 Zero has CSRF in plugin_edit.php, resulting in the ability to execute arbitrary PHP code.

    Published: 31 Mar 2018
    8.8
    High

    CVE-2018-8908

    Last Modified: 21 Nov 2024

    An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.

    Published: 31 Mar 2018
    9.8
    Critical

    CVE-2018-9161

    Last Modified: 21 Nov 2024

    Prisma Industriale Checkweigher PrismaWEB 1.21 allows remote attackers to discover the hardcoded prisma password for the prismaweb account by reading user/scripts/login_par.js.

    Published: 31 Mar 2018
    9.8
    Critical

    CVE-2018-9162

    Last Modified: 21 Nov 2024

    Contec Smart Home 4.15 devices do not require authentication for new_user.php, edit_user.php, delete_user.php, and user.php, as demonstrated by changing the admin password and then obtaining control over doors.

    Published: 31 Mar 2018
    9.8
    Critical

    CVE-2018-9160

    Last Modified: 21 Nov 2024

    SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.

    Published: 31 Mar 2018
    9.8
    Critical

    CVE-2015-9259

    Last Modified: 21 Nov 2024

    In Docker Notary before 0.1, the checkRoot function in gotuf/client/client.go does not check expiry of root.json files, despite a comment stating that it does. Even if a user creates a new root.json file after a key compromise, an attacker can produce update files referring to an old root.json file.

    Published: 31 Mar 2018
    7.5
    High

    CVE-2015-9258

    Last Modified: 21 Nov 2024

    In Docker Notary before 0.1, gotuf/signed/verify.go has a Signature Algorithm Not Matched to Key vulnerability. Because an attacker controls the field specifying the signature algorithm, they might (for example) be able to forge a signature by forcing a misinterpretation of an RSA-PSS key as Ed25519 elliptic-curve data.

    Published: 31 Mar 2018
    9.8
    Critical

    CVE-2015-9235

    Last Modified: 21 Nov 2024

    In jsonwebtoken node module before 4.2.2 it is possible for an attacker to bypass verification when a token digitally signed with an asymmetric key (RS/ES family) of algorithms but instead the attacker send a token digitally signed with a symmetric algorithm (HS* family).

    Published: 31 Mar 2018
    7.5
    High

    CVE-2018-1232

    Last Modified: 21 Nov 2024

    RSA Authentication Agent version 8.0.1 and earlier for Web for both IIS and Apache Web Server are impacted by a stack-based buffer overflow which may occur when handling certain malicious web cookies that have invalid formats. The attacker could exploit this vulnerability to crash the authentication agent and cause a denial-of-service situation.

    Published: 30 Mar 2018
    6.1
    Medium

    CVE-2018-7203

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.

    Published: 30 Mar 2018