CVE Feed

    Dashboard / CVE

    5.4
    Medium

    CVE-2014-8780

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in Jease 2.11 allows remote authenticated users to inject arbitrary web script or HTML via a content section note.

    Published: 7 Mar 2018
    6.1
    Medium

    CVE-2018-7473

    Last Modified: 21 Nov 2024

    Open redirect vulnerability in the SO Connect SO WIFI hotspot web interface, prior to version 140, allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL.

    Published: 7 Mar 2018
    6.7
    Medium

    CVE-2018-1000117

    Last Modified: 21 Nov 2024

    Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

    Published: 7 Mar 2018
    8.8
    High

    CVE-2018-1000118

    Last Modified: 21 Nov 2024

    Github Electron version Electron 1.8.2-beta.4 and earlier contains a Command Injection vulnerability in Protocol Handler that can result in command execute. This attack appear to be exploitable via the victim opening an electron protocol handler in their browser. This vulnerability appears to have been fixed in Electron 1.8.2-beta.5. This issue is due to an incomplete fix for CVE-2018-1000006, specifically the black list used was not case insensitive allowing an attacker to potentially bypass it.

    Published: 7 Mar 2018
    6.1
    Medium

    CVE-2018-7741

    Last Modified: 21 Nov 2024

    Eramba e1.0.6.033 has Reflected XSS in the Date Filter via the created parameter to the /crons URI.

    Published: 7 Mar 2018
    8.8
    High

    CVE-2018-7720

    Last Modified: 21 Nov 2024

    A cross-site request forgery (CSRF) vulnerability exists in Western Bridge Cobub Razor 0.7.2 via /index.php?/user/createNewUser/, resulting in account creation.

    Published: 7 Mar 2018
    6.1
    Medium

    CVE-2018-7721

    Last Modified: 21 Nov 2024

    Cross Site Scripting (XSS) exists in MetInfo 6.0.0 via /feedback/index.php because app/system/feedback/web/feedback.class.php mishandles input data.

    Published: 7 Mar 2018
    9.8
    Critical

    CVE-2018-1000116

    Last Modified: 21 Nov 2024

    NET-SNMP version 5.7.2 contains a heap corruption vulnerability in the UDP protocol handler that can result in command execution.

    Published: 7 Mar 2018
    3.7
    Low

    CVE-2018-1284

    Last Modified: 21 Nov 2024

    In Apache Hive 0.6.0 to 2.3.2, malicious user might use any xpath UDFs (xpath/xpath_string/xpath_boolean/xpath_number/xpath_double/xpath_float/xpath_long/xpath_int/xpath_short) to expose the content of a file on the machine running HiveServer2 owned by HiveServer2 user (usually hive) if hive.server2.enable.doAs=false.

    Published: 7 Mar 2018
    5.5
    Medium

    CVE-2018-7740

    Last Modified: 21 Nov 2024

    The resv_map_release function in mm/hugetlb.c in the Linux kernel through 4.15.7 allows local users to cause a denial of service (BUG) via a crafted application that makes mmap system calls and has a large pgoff argument to the remap_file_pages system call.

    Published: 7 Mar 2018
    5.5
    Medium

    CVE-2018-1099

    Last Modified: 21 Nov 2024

    DNS rebinding vulnerability found in etcd 3.3.1 and earlier. An attacker can control his DNS records to direct to localhost, and trick the browser into sending requests to localhost (or any other address).

    Published: 7 Mar 2018
    5.5
    Medium

    CVE-2017-18221

    Last Modified: 21 Nov 2024

    The __munlock_pagevec function in mm/mlock.c in the Linux kernel before 4.11.4 allows local users to cause a denial of service (NR_MLOCK accounting corruption) via crafted use of mlockall and munlockall system calls.

    Published: 7 Mar 2018
    8.8
    High

    CVE-2018-1098

    Last Modified: 21 Nov 2024

    A cross-site request forgery flaw was found in etcd 3.3.1 and earlier. An attacker can set up a website that tries to send a POST request to the etcd server and modify a key. Adding a key is done with PUT so it is theoretically safe (can't PUT from an HTML form or such) but POST allows creating in-order keys that an attacker can send.

    Published: 7 Mar 2018
    5.5
    Medium

    CVE-2018-1130

    Last Modified: 21 Nov 2024

    Linux kernel before version 4.16-rc7 is vulnerable to a null pointer dereference in dccp_write_xmit() function in net/dccp/output.c in that allows a local user to cause a denial of service by a number of certain crafted system calls.

    Published: 7 Mar 2018
    7.8
    High

    CVE-2018-7738

    Last Modified: 13 Dec 2024

    In util-linux before 2.32-rc1, bash-completion/umount allows local users to gain privileges by embedding shell commands in a mountpoint name, which is mishandled during a umount command (within Bash) by a different user, as demonstrated by logging in as root and entering umount followed by a tab character for autocompletion.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-7739

    Last Modified: 21 Nov 2024

    antsle antman before 0.9.1a allows remote attackers to bypass authentication via invalid characters in the username and password parameters, as demonstrated by a username=>&password=%0a string to the /login URI. This allows obtaining root permissions within the web management console, because the login process uses Java's ProcessBuilder class and a bash script called antsle-auth with insufficient input validation.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2016-5179

    Last Modified: 21 Nov 2024

    Chrome OS before 53.0.2785.144 allows remote attackers to execute arbitrary commands at boot.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2016-7443

    Last Modified: 21 Nov 2024

    Exponent CMS 2.3.0 through 2.3.9 allows remote attackers to have unspecified impact via vectors related to "uploading files to wrong location."

    Published: 6 Mar 2018
    8.8
    High

    CVE-2017-11649

    Last Modified: 21 Nov 2024

    Cross-site request forgery (CSRF) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to hijack the authentication of unspecified users for requests that enable SNMP on the remote device via vectors involving goform/setSnmp.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2017-11650

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in DrayTek Vigor AP910C devices with firmware 1.2.0_RC3 build r6594 allows remote attackers to inject arbitrary web script or HTML via vectors involving home.asp.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-5469

    Last Modified: 21 Nov 2024

    An Improper Restriction of Excessive Authentication Attempts issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An improper restriction of excessive authentication vulnerability in the web interface has been identified, which may allow an attacker to brute force authentication.

    Published: 6 Mar 2018
    5.9
    Medium

    CVE-2018-5471

    Last Modified: 21 Nov 2024

    A Cleartext Transmission of Sensitive Information issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A cleartext transmission of sensitive information vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-7736

    Last Modified: 21 Nov 2024

    In Z-BlogPHP 1.5.1.1740, cmd.php has XSS via the ZC_BLOG_SUBNAME parameter or ZC_UPLOAD_FILETYPE parameter. NOTE: the software maintainer disputes that this is a vulnerability

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-5461

    Last Modified: 21 Nov 2024

    An Inadequate Encryption Strength issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An inadequate encryption strength vulnerability in the web interface has been identified, which may allow an attacker to obtain sensitive information through a successful man-in-the-middle attack.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-5465

    Last Modified: 21 Nov 2024

    A Session Fixation issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. A session fixation vulnerability in the web interface has been identified, which may allow an attacker to hijack web sessions.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-5467

    Last Modified: 21 Nov 2024

    An Information Exposure Through Query Strings in GET Request issue was discovered in Belden Hirschmann RS, RSR, RSB, MACH100, MACH1000, MACH4000, MS, and OCTOPUS Classic Platform Switches. An information exposure through query strings vulnerability in the web interface has been identified, which may allow an attacker to impersonate a legitimate user.

    Published: 6 Mar 2018
    5.3
    Medium

    CVE-2018-7737

    Last Modified: 21 Nov 2024

    In Z-BlogPHP 1.5.1.1740, there is Web Site physical path leakage, as demonstrated by admin_footer.php or admin_footer.php. NOTE: the software maintainer disputes that this is a vulnerability

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-6810

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allows remote attackers to traverse the directory on the target system via a crafted request.

    Published: 6 Mar 2018
    7.5
    High

    CVE-2018-6808

    Last Modified: 21 Nov 2024

    NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to download arbitrary files on the target system.

    Published: 6 Mar 2018
    5.9
    Medium

    CVE-2018-6019

    Last Modified: 21 Nov 2024

    Samsung Display Solutions App before 3.02 for Android allows man-in-the-middle attackers to spoof B2B content by leveraging failure to use encryption during information transmission.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6528

    Last Modified: 21 Nov 2024

    XSS vulnerability in htdocs/webinc/body/bsc_sms_send.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted receiver parameter to soap.cgi.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-6809

    Last Modified: 21 Nov 2024

    NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to gain privilege on a target system.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6811

    Last Modified: 21 Nov 2024

    Multiple cross-site scripting (XSS) vulnerabilities in Citrix NetScaler ADC 10.5, 11.0, 11.1, and 12.0, and NetScaler Gateway 10.5, 11.0, 11.1, and 12.0 allow remote attackers to inject arbitrary web script or HTML via the Citrix NetScaler interface.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-1343

    Last Modified: 21 Nov 2024

    PAM exposure enabling unauthenticated access to remote host

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6527

    Last Modified: 21 Nov 2024

    XSS vulnerability in htdocs/webinc/js/adv_parent_ctrl_map.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted deviceid parameter to soap.cgi.

    Published: 6 Mar 2018
    7.2
    High

    CVE-2017-15519

    Last Modified: 21 Nov 2024

    Versions of SnapCenter 2.0 through 3.0.1 allow unauthenticated remote attackers to view and modify backup related data via the Plug-in for NAS File Services. All users are urged to move to version 3.0.1 and perform the mitigation steps or upgrade to 4.0 following the product documentation.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-6530

    Last Modified: 7 Nov 2025

    OS command injection vulnerability in soap.cgi (soapcgi_main in cgibin) in D-Link DIR-880L DIR-880L_REVA_FIRMWARE_PATCH_1.08B04 and previous versions, DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-65L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to execute arbitrary OS commands via the service parameter.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2018-6529

    Last Modified: 21 Nov 2024

    XSS vulnerability in htdocs/webinc/js/bsc_sms_inbox.php in D-Link DIR-868L DIR868LA1_FW112b04 and previous versions, DIR-865L DIR-865L_REVA_FIRMWARE_PATCH_1.08.B01 and previous versions, and DIR-860L DIR860LA1_FW110b04 and previous versions allows remote attackers to read a cookie via a crafted Treturn parameter to soap.cgi.

    Published: 6 Mar 2018
    7.2
    High

    CVE-2018-7734

    Last Modified: 21 Nov 2024

    Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=users&section=cpanel&page=list request.

    Published: 6 Mar 2018
    7.2
    High

    CVE-2018-7735

    Last Modified: 21 Nov 2024

    Afian FileRun (before 2018.02.13) suffers from a remote SQL injection vulnerability, when logged in as superuser, via the search parameter in a /?module=metadata&section=cpanel&page=list_filetypes request.

    Published: 6 Mar 2018
    8.8
    High

    CVE-2018-7733

    Last Modified: 21 Nov 2024

    An issue was discovered in YxtCMF 3.1. RbacController.class.php has CSRF, as demonstrated by modifying an administrator account via index.php/admin/user/add_post.html.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-7732

    Last Modified: 21 Nov 2024

    An issue was discovered in YxtCMF 3.1. SQL Injection exists in ShitiController.class.php via the ids array parameter to exam/shiti/delshiti.html.

    Published: 6 Mar 2018
    9.8
    Critical

    CVE-2018-1000101

    Last Modified: 21 Nov 2024

    Mingw-w64 version 5.0.3 and earlier, 5.0.4, 6.0.0 and 7.0.0 contains an Improper Null Termination (CWE-170) vulnerability in mingw-w64-crt (libc)->(v)snprintf that can result in The bug may be used to corrupt subsequent string functions. This attack appear to be exploitable via Depending on the usage, worst case: network.

    Published: 6 Mar 2018
    5.4
    Medium

    CVE-2018-7722

    Last Modified: 21 Nov 2024

    The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /ws.php?format=json request. CSRF exploitation, related to CVE-2017-10681, may be possible.

    Published: 6 Mar 2018
    6.5
    Medium

    CVE-2018-7726

    Last Modified: 10 Jul 2025

    An issue was discovered in ZZIPlib 0.13.68. There is a bus error caused by the __zzip_parse_root_directory function of zip.c. Attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

    Published: 6 Mar 2018
    5.4
    Medium

    CVE-2018-7724

    Last Modified: 21 Nov 2024

    The management panel in Piwigo 2.9.3 has stored XSS via the name parameter in a /admin.php?page=photo-${photo_number} request. CSRF exploitation, related to CVE-2017-10681, may be possible.

    Published: 6 Mar 2018
    5.4
    Medium

    CVE-2018-7723

    Last Modified: 21 Nov 2024

    The management panel in Piwigo 2.9.3 has stored XSS via the virtual_name parameter in a /admin.php?page=cat_list request, a different issue than CVE-2017-9836. CSRF exploitation, related to CVE-2017-10681, may be possible.

    Published: 6 Mar 2018
    7.8
    High

    CVE-2018-1000100

    Last Modified: 21 Nov 2024

    GPAC MP4Box version 0.7.1 and earlier contains a Buffer Overflow vulnerability in src/isomedia/avc_ext.c lines 2417 to 2420 that can result in Heap chunks being modified, this could lead to RCE. This attack appear to be exploitable via an attacker supplied MP4 file that when run by the victim may result in RCE.

    Published: 6 Mar 2018
    6.1
    Medium

    CVE-2017-9786

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in ProjectSend (formerly cFTP) before commit 6c3710430be26feb5371cb0377e5355d6f9a27ca allows remote attackers to inject arbitrary web script or HTML via the Description field in My account Name updated, related to home.php and actions-log.php.

    Published: 6 Mar 2018
    7.8
    High

    CVE-2017-6282

    Last Modified: 21 Nov 2024

    NVIDIA Tegra kernel driver contains a vulnerability in NVMAP where an attacker has the ability to write an arbitrary value to an arbitrary location which may lead to an escalation of privileges. This issue is rated as high.

    Published: 6 Mar 2018