CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2018-1000125

    Last Modified: 21 Nov 2024

    inversoft prime-jwt version prior to version 1.3.0 or prior to commit 0d94dcef0133d699f21d217e922564adbb83a227 contains an input validation vulnerability in JWTDecoder.decode that can result in a JWT that is decoded and thus implicitly validated even if it lacks a valid signature. This attack appear to be exploitable via an attacker crafting a token with a valid header and body and then requests it to be validated. This vulnerability appears to have been fixed in 1.3.0 and later or after commit 0d94dcef0133d699f21d217e922564adbb83a227.

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-1000126

    Last Modified: 21 Nov 2024

    Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. This attack appears to be exploitable via network connectivity to the web application.

    Published: 13 Mar 2018
    Unknown

    CVE-2018-1000128

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-7752. Reason: This candidate is a reservation duplicate of CVE-2018-7752. Notes: All CVE users should reference CVE-2018-7752 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-1000123

    Last Modified: 21 Nov 2024

    Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that can result in login, password and other sensitive data leakage. This attack appear to be exploitable via Attacker must have access to victim's iOS logs. This vulnerability appears to have been fixed in after commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf.

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-1227

    Last Modified: 21 Nov 2024

    Pivotal Concourse after 2018-03-05 might allow remote attackers to have an unspecified impact, if a customer obtained the Concourse software from a DNS domain that is no longer controlled by Pivotal. The original domain for the Concourse CI (concourse-dot-ci) open source project has been registered by an unknown actor, and is therefore no longer the official website for Concourse CI. The new official domain is concourse-ci.org. At approximately 4 am EDT on March 7, 2018 the Concourse OSS team began receiving reports that the Concourse domain was not responding. The Concourse OSS team discovered, upon investigation with both the original and the new domain registrars, that the originating domain registrar had made the domain available for purchase. This was done despite the domain being renewed by the Concourse OSS team through August 2018. For a customer to be affected, they would have needed to access a download from a "concourse-dot-ci" domain web site after March 6, 2018 18:00:00 EST. Accessing that domain is NOT recommended by Pivotal. Anyone who had been using that domain should immediately begin using the concourse-ci.org domain instead. Customers can also safely access Concourse software from the traditionally available locations on the Pivotal Network or GitHub.

    Published: 13 Mar 2018
    6.1
    Medium

    CVE-2018-7405

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) in Zoho ManageEngine EventLog Analyzer before 11.12 Build 11120 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 13 Mar 2018
    5.3
    Medium

    CVE-2017-16250

    Last Modified: 21 Nov 2024

    A vulnerability in Mitel ST 14.2, release GA28 and earlier, could allow an attacker to use the API function to enumerate through user-ids which could be used to identify valid user ids and associated user names.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2017-16251

    Last Modified: 21 Nov 2024

    A vulnerability in the conferencing component of Mitel ST 14.2, release GA28 and earlier, could allow an authenticated user to upload a malicious script to the Personal Library by a crafted POST request. Successful exploit could allow an attacker to execute arbitrary code within the context of the application.

    Published: 13 Mar 2018
    6.1
    Medium

    CVE-2017-17442

    Last Modified: 21 Nov 2024

    In BlackBerry UEM Management Console version 12.7.1 and earlier, a reflected cross-site scripting vulnerability that could allow an attacker to execute script commands in the context of the affected UEM Management Console account by crafting a malicious link and then persuading a user with legitimate access to the Management Console to click on the malicious link.

    Published: 13 Mar 2018
    5.3
    Medium

    CVE-2018-6296

    Last Modified: 21 Nov 2024

    An undocumented (hidden) capability for switching the web interface in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-6297

    Last Modified: 21 Nov 2024

    Buffer overflow in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-6298

    Last Modified: 21 Nov 2024

    Remote code execution in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-6299

    Last Modified: 21 Nov 2024

    Authentication bypass in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-6300

    Last Modified: 21 Nov 2024

    Remote password change in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-6301

    Last Modified: 21 Nov 2024

    Arbitrary camera access and monitoring via cloud in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-6303

    Last Modified: 21 Nov 2024

    Denial of service by uploading malformed firmware in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-6304

    Last Modified: 21 Nov 2024

    Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-6305

    Last Modified: 21 Nov 2024

    Denial of service in Gemalto's Sentinel LDK RTE version before 7.65

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-6294

    Last Modified: 21 Nov 2024

    Unsecured way of firmware update in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    9.8
    Critical

    CVE-2018-6295

    Last Modified: 21 Nov 2024

    Unencrypted way of remote control and communications in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-6302

    Last Modified: 21 Nov 2024

    Denial of service by blocking of new camera registration on the cloud server in Hanwha Techwin Smartcams

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-0875

    Last Modified: 21 Nov 2024

    .NET Core 1.0, .NET Core 1.1, NET Core 2.0 and PowerShell Core 6.0.0 allow a denial of Service vulnerability due to how specially crafted requests are handled, aka ".NET Core Denial of Service Vulnerability".

    Published: 13 Mar 2018
    5.5
    Medium

    CVE-2018-1000069

    Last Modified: 21 Nov 2024

    FreePlane version 1.5.9 and earlier contains a XML External Entity (XXE) vulnerability in XML Parser in mindmap loader that can result in stealing data from victim's machine. This attack appears to require the victim to open a specially crafted mind map file. This vulnerability appears to have been fixed in 1.6+.

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-1000072

    Last Modified: 21 Nov 2024

    iRedMail version prior to commit f04b8ef contains a Insecure Permissions vulnerability in Roundcube Webmail that can result in Exfiltrate a user's password protected secret GPG key file and other important configuration files.. This attack appear to be exploitable via network connectivity. This vulnerability appears to have been fixed in Beta: 0.9.8-BETA1, Stable: 0.9.7.

    Published: 13 Mar 2018
    6.5
    Medium

    CVE-2018-1000080

    Last Modified: 21 Nov 2024

    Ajenti version version 2 contains a Insecure Permissions vulnerability in Plugins download that can result in The download of any plugins as being a normal user. This attack appear to be exploitable via By knowing how the requisition is made, and sending it as a normal user, the server, in response, downloads the plugin.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2018-1000082

    Last Modified: 21 Nov 2024

    Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed..

    Published: 13 Mar 2018
    5.3
    Medium

    CVE-2018-1000083

    Last Modified: 21 Nov 2024

    Ajenti version version 2 contains a Improper Error Handling vulnerability in Login JSON request that can result in The requisition leaks a path of the server. This attack appear to be exploitable via By sending a malformed JSON, the tool responds with a traceback error that leaks a path of the server.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2018-1000086

    Last Modified: 21 Nov 2024

    NPR Visuals Team Pym.js version versions 0.4.2 up to 1.3.1 contains a Cross ite Request Forgery (CSRF) vulnerability in Pym.js _onNavigateToMessage function. https://github.com/nprapps/pym.js/blob/master/src/pym.js#L573 that can result in Arbitrary javascript code execution. This attack appear to be exploitable via Attacker gains full javascript access to pages with Pym.js embeds when user visits an attacker crafted page.. This vulnerability appears to have been fixed in versions 1.3.2 and later.

    Published: 13 Mar 2018
    4.8
    Medium

    CVE-2018-1000087

    Last Modified: 21 Nov 2024

    WolfCMS version version 0.8.3.1 contains a Reflected Cross Site Scripting vulnerability in "Create New File" and "Create New Directory" input box from 'files' Tab that can result in Session Hijacking, Spread Worms,Control the browser remotely. . This attack appear to be exploitable via Attacker can execute the JavaScript into the "Create New File" and "Create New Directory" input box from 'files'.

    Published: 13 Mar 2018
    6.1
    Medium

    CVE-2018-1000088

    Last Modified: 21 Nov 2024

    Doorkeeper version 2.1.0 through 4.2.5 contains a Cross Site Scripting (XSS) vulnerability in web view's OAuth app form, user authorization prompt web view that can result in Stored XSS on the OAuth Client's name will cause users interacting with it will execute payload. This attack appear to be exploitable via The victim must be tricked to click an opaque link to the web view that runs the XSS payload. A malicious version virtually indistinguishable from a normal link.. This vulnerability appears to have been fixed in 4.2.6, 4.3.0.

    Published: 13 Mar 2018
    7.4
    High

    CVE-2018-1000089

    Last Modified: 21 Nov 2024

    Anymail django-anymail version version 0.2 through 1.3 contains a CWE-532, CWE-209 vulnerability in WEBHOOK_AUTHORIZATION setting value that can result in An attacker with access to error logs could fabricate email tracking events. This attack appear to be exploitable via If you have exposed your Django error reports, an attacker could discover your ANYMAIL_WEBHOOK setting and use this to post fabricated or malicious Anymail tracking/inbound events to your app. This vulnerability appears to have been fixed in v1.4.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2018-1000092

    Last Modified: 21 Nov 2024

    CMS Made Simple version versions 2.2.5 contains a Cross ite Request Forgery (CSRF) vulnerability in Admin profile page that can result in Details can be found here http://dev.cmsmadesimple.org/bug/view/11715. This attack appear to be exploitable via A specially crafted web page. This vulnerability appears to have been fixed in 2.2.6.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2018-1000093

    Last Modified: 21 Nov 2024

    CryptoNote version version 0.8.9 and possibly later contain a local RPC server which does not require authentication, as a result the walletd and the simplewallet RPC daemons will process any commands sent to them, resulting in remote command execution and a takeover of the cryptocurrency wallet if an attacker can trick an application such as a web browser into connecting and sending a command for example. This attack appears to be exploitable via a victim visiting a webpage hosting malicious content that trigger such behavior.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2018-1000070

    Last Modified: 21 Nov 2024

    Bitmessage PyBitmessage version v0.6.2 (and introduced in or after commit 8ce72d8d2d25973b7064b1cf76a6b0b3d62f0ba0) contains a Eval injection vulnerability in main program, file src/messagetypes/__init__.py function constructObject that can result in Code Execution. This attack appears to be exploitable via remote attacker using a malformed message which must be processed by the victim - e.g. arrive from any sender on bitmessage network. This vulnerability appears to have been fixed in v0.6.3.

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-1000081

    Last Modified: 21 Nov 2024

    Ajenti version version 2 contains a Input Validation vulnerability in ID string on Get-values POST request that can result in Server Crashing. This attack appear to be exploitable via An attacker can freeze te server by sending a giant string to the ID parameter ..

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-1000090

    Last Modified: 21 Nov 2024

    textpattern version version 4.6.2 contains a XML Injection vulnerability in Import XML feature that can result in Denial of service in context to the web server by exhausting server memory resources. This attack appear to be exploitable via Uploading a specially crafted XML file.

    Published: 13 Mar 2018
    7.5
    High

    CVE-2018-1000071

    Last Modified: 21 Nov 2024

    roundcube version 1.3.4 and earlier contains an Insecure Permissions vulnerability in enigma plugin that can result in exfiltration of gpg private key. This attack appear to be exploitable via network connectivity.

    Published: 13 Mar 2018
    5.4
    Medium

    CVE-2018-1000084

    Last Modified: 21 Nov 2024

    WOlfCMS WolfCMS version version 0.8.3.1 contains a Stored Cross-Site Scripting vulnerability in Layout Name (from Layout tab) that can result in low privilege user can steal the cookie of admin user and compromise the admin account. This attack appear to be exploitable via Need to enter the Javascript code into Layout Name .

    Published: 13 Mar 2018
    5.5
    Medium

    CVE-2018-1000085

    Last Modified: 21 Nov 2024

    ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit chains.. This attack appear to be exploitable via The victim must scan a crafted XAR file. This vulnerability appears to have been fixed in after commit d96a6b8bcc7439fa7e3876207aa0a8e79c8451b6.

    Published: 13 Mar 2018
    8.8
    High

    CVE-2018-1000091

    Last Modified: 21 Nov 2024

    KadNode version version 2.2.0 contains a Buffer Overflow vulnerability in Arguments when starting up the binary that can result in Control of program execution flow, leading to remote code execution.

    Published: 13 Mar 2018
    Unknown

    CVE-2018-1000102

    Last Modified: 16 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000067. Reason: This candidate is a reservation duplicate of CVE-2018-1000067. Notes: All CVE users should reference CVE-2018-1000067 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Mar 2018
    6.5
    Medium

    CVE-2018-1000107

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Job and Node Ownership Plugin 0.11.0 and earlier in OwnershipDescription.java, JobOwnerJobProperty.java, and OwnerNodeProperty.java that allow an attacker with Job/Configure or Computer/Configure permission and without Ownership related permissions to override ownership metadata.

    Published: 13 Mar 2018
    6.1
    Medium

    CVE-2018-1000108

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins CppNCSS Plugin 1.1 and earlier in AbstractProjectAction/index.jelly that allow an attacker to craft links to Jenkins URLs that run arbitrary JavaScript in the user's browser when accessed.

    Published: 13 Mar 2018
    5.4
    Medium

    CVE-2018-1000113

    Last Modified: 21 Nov 2024

    A cross-site scripting vulnerability exists in Jenkins TestLink Plugin 2.12 and earlier in TestLinkBuildAction/summary.jelly and others that allow an attacker who can control e.g. TestLink report names to have Jenkins serve arbitrary HTML and JavaScript

    Published: 13 Mar 2018
    Unknown

    CVE-2018-1000103

    Last Modified: 17 Sept 2024

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2018-1000068. Reason: This candidate is a reservation duplicate of CVE-2018-1000068. Notes: All CVE users should reference CVE-2018-1000068 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Published: 13 Mar 2018
    7.8
    High

    CVE-2018-1000104

    Last Modified: 21 Nov 2024

    A plaintext storage of a password vulnerability exists in Jenkins Coverity Plugin 1.10.0 and earlier in CIMInstance.java that allows an attacker with local file system access or control of a Jenkins administrator's web browser (e.g. malicious extension) to retrieve the configured keystore and private key passwords.

    Published: 13 Mar 2018
    5.4
    Medium

    CVE-2018-1000106

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to modify the Gerrit configuration in Jenkins.

    Published: 13 Mar 2018
    4.3
    Medium

    CVE-2018-1000109

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Google Play Android Publisher Plugin version 1.6 and earlier in GooglePlayBuildStepDescriptor.java that allow an attacker to obtain credential IDs.

    Published: 13 Mar 2018
    4.3
    Medium

    CVE-2018-1000105

    Last Modified: 21 Nov 2024

    An improper authorization vulnerability exists in Jenkins Gerrit Trigger Plugin 2.27.4 and earlier in GerritManagement.java, GerritServer.java, and PluginImpl.java that allows an attacker with Overall/Read access to retrieve some configuration information about Gerrit in Jenkins.

    Published: 13 Mar 2018
    5.4
    Medium

    CVE-2018-8078

    Last Modified: 21 Nov 2024

    YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.

    Published: 13 Mar 2018