CVE Feed

    Dashboard / CVE

    6.1
    Medium

    CVE-2018-8729

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in the Activity Log plugin before 2.4.1 for WordPress allow remote attackers to inject arbitrary JavaScript or HTML via a title that is not escaped.

    Published: 15 Mar 2018
    6.1
    Medium

    CVE-2018-8728

    Last Modified: 21 Nov 2024

    server/app/views/static/code.html in Kontena before 1.5.0 allows XSS in "kontena master login --remote" code display, as demonstrated by /code#code= in a URI.

    Published: 15 Mar 2018
    5.4
    Medium

    CVE-2018-8720

    Last Modified: 21 Nov 2024

    ServiceNow ITSM 2016-06-02 has XSS via the First Name or Last Name field of My Profile (aka navpage.do), or the Search bar of My Portal (aka search_results.do).

    Published: 15 Mar 2018
    6.1
    Medium

    CVE-2018-8721

    Last Modified: 21 Nov 2024

    Zoho ManageEngine EventLog Analyzer version 11.0 build 11000 has Stored XSS related to the index2.do?url=editAlertForm&tab=alert&alert=profile URI and the Edit Alert Profile screen

    Published: 15 Mar 2018
    6.1
    Medium

    CVE-2018-8722

    Last Modified: 21 Nov 2024

    Zoho ManageEngine Desktop Central version 9.1.0 build 91099 has multiple XSS issues that were fixed in build 92026.

    Published: 15 Mar 2018
    7.5
    High

    CVE-2018-8076

    Last Modified: 21 Nov 2024

    ZenMate 1.5.4 for macOS suffers from a type confusion vulnerability within the com.zenmate.chron-xpc LaunchDaemon component. The LaunchDaemon implements an XPC service that uses an insecure XPC API for accessing data from an inbound XPC message. This could potentially result in an XPC object of the wrong type being passed as the first argument to the xpc_connection_create_from_endpoint function if controlled by an attacker. In recent versions of macOS and OS X, Apple has implemented an internal check to prevent such XPC API abuse from occurring, thus making this vulnerability only result in a denial of service if exploited by an attacker.

    Published: 15 Mar 2018
    7.8
    High

    CVE-2018-7886

    Last Modified: 21 Nov 2024

    An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" client application listening on 127.0.0.1 port 8888 can send a malicious payload causing a buffer overflow condition. This will result in code execution, as demonstrated by a TCP reverse shell, or a crash. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-6892.

    Published: 15 Mar 2018
    7.5
    High

    CVE-2018-1080

    Last Modified: 21 Nov 2024

    Dogtag PKI, through version 10.6.1, has a vulnerability in AAclAuthz.java that, under certain configurations, causes the application of ACL allow and deny rules to be reversed. If a server is configured to process allow rules before deny rules (authz.evaluateOrder=allow,deny), then allow rules will deny access and deny rules will grant access. This may result in an escalation of privileges or have other unintended consequences.

    Published: 15 Mar 2018
    5.5
    Medium

    CVE-2018-8975

    Last Modified: 21 Nov 2024

    The pm_mallocarray2 function in lib/util/mallocvar.c in Netpbm through 10.81.03 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted image file, as demonstrated by pbmmask.

    Published: 15 Mar 2018
    8.8
    High

    CVE-2018-8741

    Last Modified: 21 Nov 2024

    A directory traversal flaw in SquirrelMail 1.4.22 allows an authenticated attacker to exfiltrate (or potentially delete) files from the hosting server, related to ../ in the att_local_name field in Deliver.class.php.

    Published: 15 Mar 2018
    5.5
    Medium

    CVE-2018-18690

    Last Modified: 21 Nov 2024

    In the Linux kernel before 4.17, a local attacker able to set attributes on an xfs filesystem could make this filesystem non-operational until the next mount by triggering an unchecked error condition during an xfs attribute change, because xfs_attr_shortform_addname in fs/xfs/libxfs/xfs_attr.c mishandles ATTR_REPLACE operations with conversion of an attr from short to long form.

    Published: 15 Mar 2018
    6.1
    Medium

    CVE-2018-8048

    Last Modified: 21 Nov 2024

    In the Loofah gem through 2.2.0 for Ruby, non-whitelisted HTML attributes may occur in sanitized output by republishing a crafted HTML fragment.

    Published: 15 Mar 2018
    8.8
    High

    CVE-2018-8804

    Last Modified: 21 Nov 2024

    WriteEPTImage in coders/ept.c in ImageMagick 7.0.7-25 Q16 allows remote attackers to cause a denial of service (MagickCore/memory.c double free and application crash) or possibly have unspecified other impact via a crafted file.

    Published: 15 Mar 2018
    6.1
    Medium

    CVE-2018-7703

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via the mailboxid parameter to secmail/getmessage.exe.

    Published: 14 Mar 2018
    6.5
    Medium

    CVE-2018-7704

    Last Modified: 21 Nov 2024

    SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via the option1 parameter in a reply action to secmail/getmessage.exe.

    Published: 14 Mar 2018
    8.1
    High

    CVE-2018-7705

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read e-mail messages to arbitrary recipients via a .. (dot dot) in the filename parameter to secupload2/upload.aspx.

    Published: 14 Mar 2018
    6.5
    Medium

    CVE-2018-7706

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote authenticated users to read arbitrary e-mail messages via a .. (dot dot) in the option2 parameter in an attachment action to secmail/getmessage.exe.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-7756

    Last Modified: 21 Nov 2024

    RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remote attackers to execute arbitrary code or access internal commands, as demonstrated by a RUN command that launches a .EXE file located at an arbitrary external URL, or a "SETFIREWALL Off" command.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-8045

    Last Modified: 21 Nov 2024

    In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

    Published: 14 Mar 2018
    8.1
    High

    CVE-2018-8715

    Last Modified: 21 Nov 2024

    The Embedthis HTTP library, and Appweb versions before 7.0.3, have a logic flaw related to the authCondition function in http/httpLib.c. With a forged HTTP request, it is possible to bypass authentication for the form and digest login types.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-8717

    Last Modified: 21 Nov 2024

    joyplus-cms 1.6.0 has CSRF, as demonstrated by adding an administrator account via a manager/admin_ajax.php?action=save&tab={pre}manager request.

    Published: 14 Mar 2018
    9.1
    Critical

    CVE-2018-7702

    Last Modified: 21 Nov 2024

    SecurEnvoy SecurMail before 9.2.501 allows remote attackers to spoof transmission of arbitrary e-mail messages, resend e-mail messages to arbitrary recipients, or modify arbitrary message bodies and attachments by leveraging missing authentication and authorization.

    Published: 14 Mar 2018
    6.1
    Medium

    CVE-2018-7707

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in SecurEnvoy SecurMail before 9.2.501 allows remote attackers to inject arbitrary web script or HTML via an HTML-formatted e-mail message.

    Published: 14 Mar 2018
    6.5
    Medium

    CVE-2018-7701

    Last Modified: 21 Nov 2024

    Multiple cross-site request forgery (CSRF) vulnerabilities in SecurEnvoy SecurMail before 9.2.501 allow remote attackers to hijack the authentication of arbitrary users for requests that (1) delete e-mail messages via a delete action in a request to secmail/getmessage.exe or (2) spoof arbitrary users and reply to their messages via a request to secserver/securectrl.exe.

    Published: 14 Mar 2018
    5.4
    Medium

    CVE-2018-2397

    Last Modified: 21 Nov 2024

    In SAP Business Objects Business Intelligence Platform, 4.00, 4.10, 4.20, 4.30, the Central Management Console (CMC) does not sufficiently encode user controlled inputs which results in Cross-Site Scripting.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-2398

    Last Modified: 27 May 2025

    Under certain conditions SAP Business Client 6.5 allows an attacker to access information which would otherwise be restricted.

    Published: 14 Mar 2018
    5.4
    Medium

    CVE-2018-2401

    Last Modified: 21 Nov 2024

    SAP Business Process Automation (BPA) By Redwood does not sufficiently validate an XML document accepted from an untrusted source resulting in an XML External Entity (XXE) vulnerability.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-6328

    Last Modified: 21 Nov 2024

    It was discovered that the Unitrends Backup (UB) before 10.1.0 user interface was exposed to an authentication bypass, which then could allow an unauthenticated user to inject arbitrary commands into its /api/hosts parameters using backquotes.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-6329

    Last Modified: 21 Nov 2024

    It was discovered that the Unitrends Backup (UB) before 10.1.0 libbpext.so authentication could be bypassed with a SQL injection, allowing a remote attacker to place a privilege escalation exploit on the target system and subsequently execute arbitrary commands.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-8710

    Last Modified: 21 Nov 2024

    A remote code execution issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The plugin implemented a page redraw AJAX function accessible to anyone without any authentication. WordPress shortcode markup in the "shortcode" parameters would be evaluated. Normally unauthenticated users can't evaluate shortcodes as they are often sensitive.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-8711

    Last Modified: 21 Nov 2024

    A local file inclusion issue was discovered in the WooCommerce Products Filter (aka WOOF) plugin before 2.2.0 for WordPress, as demonstrated by the shortcode parameter in a woof_redraw_woof action. The vulnerability is due to the lack of args/input validation on render_html before allowing it to be called by extract(), a PHP built-in function. Because of this, the supplied args/input can be used to overwrite the $pagepath variable, which then could lead to a local file inclusion attack.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-8712

    Last Modified: 21 Nov 2024

    An issue was discovered in Webmin 1.840 and 1.880 when the default Yes setting of "Can view any file as a log file" is enabled. As a result of weak default configuration settings, limited users have full access rights to the underlying Unix system files, allowing the user to read sensitive data from the local system (using Local File Include) such as the '/etc/shadow' file via a "GET /syslog/save_log.cgi?view=1&file=/etc/shadow" request.

    Published: 14 Mar 2018
    7.6
    High

    CVE-2018-2402

    Last Modified: 21 Nov 2024

    In systems using the optional capture & replay functionality of SAP HANA, 1.00 and 2.00, (see SAP Note 2362820 for more information about capture & replay), user credentials may be stored in clear text in the indexserver trace files of the control system. An attacker with the required authorizations on the control system may be able to access the user credentials and gain unauthorized access to data in the captured or target system.

    Published: 14 Mar 2018
    4.3
    Medium

    CVE-2018-2366

    Last Modified: 21 Nov 2024

    SAP Business Process Automation (BPA) By Redwood, 9.0, 9.1, allows an attacker to exploit insufficient validation of path information provided by users, thus characters representing 'traverse to parent directory' are passed through to the file APIs.

    Published: 14 Mar 2018
    6.1
    Medium

    CVE-2018-2399

    Last Modified: 21 Nov 2024

    Cross-Site Scripting in Process Monitoring Infrastructure, from 7.10 to 7.11, 7.20, 7.30, 7.31, 7.40, 7.50, due to inefficient encoding of user controlled inputs.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-2400

    Last Modified: 21 Nov 2024

    Under certain conditions SAP Business Process Automation (BPA) By Redwood, 9.00, 9.10, allows an attacker to access information which would otherwise be restricted.

    Published: 14 Mar 2018
    9.8
    Critical

    CVE-2018-7500

    Last Modified: 21 Nov 2024

    A Permissions, Privileges, and Access Controls issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Privileges may be escalated, giving attackers access to the PI System via the service account.

    Published: 14 Mar 2018
    6.1
    Medium

    CVE-2018-7504

    Last Modified: 21 Nov 2024

    A Protection Mechanism Failure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The X-XSS-Protection response header is not set to block, allowing attempts at reflected cross-site scripting.

    Published: 14 Mar 2018
    5.9
    Medium

    CVE-2018-7531

    Last Modified: 21 Nov 2024

    An Improper Input Validation issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may use unvalidated custom requests to crash the server.

    Published: 14 Mar 2018
    7.8
    High

    CVE-2018-7533

    Last Modified: 21 Nov 2024

    An Incorrect Default Permissions issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Insecure default configuration may allow escalation of privileges that gives the actor full control over the system.

    Published: 14 Mar 2018
    6.1
    Medium

    CVE-2018-7508

    Last Modified: 21 Nov 2024

    A Cross-site Scripting issue was discovered in OSIsoft PI Web API versions 2017 R2 and prior. Cross-site scripting may occur when input is incorrectly neutralized.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-7529

    Last Modified: 21 Nov 2024

    A Deserialization of Untrusted Data issue was discovered in OSIsoft PI Data Archive versions 2017 and prior. Unauthenticated users may modify deserialized data to send custom requests that crash the server.

    Published: 14 Mar 2018
    5.3
    Medium

    CVE-2018-7496

    Last Modified: 21 Nov 2024

    An Information Exposure issue was discovered in OSIsoft PI Vision versions 2017 and prior. The server response header and referrer-policy response header each provide unintended information disclosure.

    Published: 14 Mar 2018
    8.8
    High

    CVE-2018-0787

    Last Modified: 21 Nov 2024

    ASP.NET Core 1.0. 1.1, and 2.0 allow an elevation of privilege vulnerability due to how web applications that are created from templates validate web requests, aka "ASP.NET Core Elevation Of Privilege Vulnerability".

    Published: 14 Mar 2018
    7
    High

    CVE-2018-0868

    Last Modified: 21 Nov 2024

    Windows Installer in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how input is sanitized, aka "Windows Installer Elevation of Privilege Vulnerability".

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-0874

    Last Modified: 21 Nov 2024

    ChakraCore and Microsoft Edge in Microsoft Windows 10 Gold, 1511, 1607, 1703, 1709, and Windows Server 2016 allows remote code execution, due to how the Chakra scripting engine handles objects in memory, aka "Chakra Scripting Engine Memory Corruption Vulnerability". This CVE ID is unique from CVE-2018-0872, CVE-2018-0873, CVE-2018-0930, CVE-2018-0931, CVE-2018-0933, CVE-2018-0934, CVE-2018-0936, and CVE-2018-0937.

    Published: 14 Mar 2018
    7.5
    High

    CVE-2018-0879

    Last Modified: 21 Nov 2024

    Microsoft Edge in Windows 10 1709 allows information disclosure, due to how Edge handles objects in memory, aka "Microsoft Edge Information Disclosure Vulnerability".

    Published: 14 Mar 2018
    7
    High

    CVE-2018-0880

    Last Modified: 21 Nov 2024

    The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0882.

    Published: 14 Mar 2018
    7
    High

    CVE-2018-0882

    Last Modified: 21 Nov 2024

    The Desktop Bridge in Windows 10 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to how the virtual registry is managed, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0880.

    Published: 14 Mar 2018
    7.8
    High

    CVE-2018-0884

    Last Modified: 21 Nov 2024

    Windows Scripting Host (WSH) in Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allows a security feature bypass vulnerability due to how objects are handled in memory, aka "Windows Security Feature Bypass Vulnerability". This CVE is unique from CVE-2018-0902.

    Published: 14 Mar 2018