CVE Feed

    Dashboard / CVE

    2.7
    Low

    CVE-2016-0369

    Last Modified: 21 Nov 2024

    XML external entity (XXE) vulnerability in IBM Forms Experience Builder 8.5, 8.5.1, and 8.6 allows remote authenticated users to obtain sensitive information via crafted XML data. IBM X-Force ID: 112088.

    Published: 21 Feb 2018
    8.8
    High

    CVE-2013-0267

    Last Modified: 21 Nov 2024

    The Privileges portion of the web GUI and the XMLRPC API in Apache VCL 2.3.x before 2.3.2, 2.2.x before 2.2.2 and 2.1 allow remote authenticated users with nodeAdmin, manageGroup, resourceGrant, or userGrant permissions to gain privileges, cause a denial of service, or conduct cross-site scripting (XSS) attacks by leveraging improper data validation.

    Published: 21 Feb 2018
    8.1
    High

    CVE-2018-5716

    Last Modified: 30 Apr 2025

    An issue was discovered in Reprise License Manager 11.0. This vulnerability is a Path Traversal where the attacker, by changing a field in the Web Request, can have access to files on the File System of the Server. By specifying a pathname in the POST parameter "lf" to the goform/edit_lf_get_data URI, the attacker can retrieve the content of a file.

    Published: 21 Feb 2018
    5.4
    Medium

    CVE-2018-7260

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in db_central_columns.php in phpMyAdmin before 4.7.8 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

    Published: 21 Feb 2018
    5.9
    Medium

    CVE-2015-6569

    Last Modified: 21 Nov 2024

    Race condition in the LoadBalancer module in the Atlassian Floodlight Controller before 1.2 allows remote attackers to cause a denial of service (NULL pointer dereference and thread crash) via a state manipulation attack.

    Published: 21 Feb 2018
    7.8
    High

    CVE-2018-1168

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of ABB MicroSCADA 9.3 with FP 1-2-3. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the configuration of the access controls for the installed product files. The installation procedure leaves critical files open to manipulation by any authenticated user. An attacker can leverage this vulnerability to escalate privileges to SYSTEM. Was ZDI-CAN-5097.

    Published: 21 Feb 2018
    7.8
    High

    CVE-2018-1166

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMBIOC_TREE_RELE ioctl. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4984.

    Published: 21 Feb 2018
    Unknown

    CVE-2015-0262

    Last Modified: 7 Nov 2023

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Published: 21 Feb 2018
    9.8
    Critical

    CVE-2018-1164

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to cause a denial-of-service condition on vulnerable installations of ZyXEL P-870H-51 DSL Router 1.00(AWG.3)D5. Authentication is not required to exploit this vulnerability. The specific flaw exists within numerous exposed CGI endpoints. The vulnerability is caused by improper access controls that allow access to critical functions without authentication. An attacker can use this vulnerability to reboot affected devices, along with other actions. Was ZDI-CAN-4540.

    Published: 21 Feb 2018
    7
    High

    CVE-2018-1165

    Last Modified: 21 Nov 2024

    This vulnerability allows local attackers to escalate privileges on vulnerable installations of Joyent SmartOS release-20170803-20170803T064301Z. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the SMB_IOC_SVCENUM IOCTL. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length, heap-based buffer. An attacker can leverage this vulnerability to execute code under the context of the host OS. Was ZDI-CAN-4983.

    Published: 21 Feb 2018
    6.1
    Medium

    CVE-2018-7278

    Last Modified: 21 Nov 2024

    An issue was discovered on RLE Protocol Converter FDS-PC / FDS-PC-DP 2.1 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.

    Published: 21 Feb 2018
    7.5
    High

    CVE-2018-7276

    Last Modified: 21 Nov 2024

    An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive information via a /DbXmlInfo.xml request, as demonstrated by the Latitude/Longitude of the device.

    Published: 21 Feb 2018
    6.1
    Medium

    CVE-2018-7277

    Last Modified: 21 Nov 2024

    An issue was discovered on RLE Wi-MGR/FDS-Wi 6.2 devices. Persistent XSS exists in the web server. Remote attackers can inject malicious JavaScript code using the device's BACnet implementation. This is similar to a Cross Protocol Injection with SNMP.

    Published: 21 Feb 2018
    6.5
    Medium

    CVE-2018-7272

    Last Modified: 21 Nov 2024

    The REST APIs in ForgeRock AM before 5.5.0 include SSOToken IDs as part of the URL, which allows attackers to obtain sensitive information by finding an ID value in a log file.

    Published: 21 Feb 2018
    8.1
    High

    CVE-2018-7271

    Last Modified: 21 Nov 2024

    An issue was discovered in MetInfo 6.0.0. In install/install.php in the installation process, the config/config_db.php configuration file filtering is not rigorous: one can insert malicious code in the installation process to execute arbitrary commands or obtain a web shell.

    Published: 21 Feb 2018
    7.8
    High

    CVE-2018-1000097

    Last Modified: 21 Nov 2024

    Sharutils sharutils (unshar command) version 4.15.2 contains a Buffer Overflow vulnerability in Affected component on the file unshar.c at line 75, function looks_like_c_code. Failure to perform checking of the buffer containing input line. that can result in Could lead to code execution. This attack appear to be exploitable via Victim have to run unshar command on a specially crafted file..

    Published: 21 Feb 2018
    6.1
    Medium

    CVE-2018-7274

    Last Modified: 21 Nov 2024

    Yab Quarx through 2.4.3 is prone to multiple persistent cross-site scripting vulnerabilities: Blog (Title), FAQ (Question), Pages (Title), Widgets (Name), and Menus (Name).

    Published: 21 Feb 2018
    7.5
    High

    CVE-2017-12415

    Last Modified: 21 Nov 2024

    OXID eShop Community Edition before 6.0.0 RC2 (development), 4.10.x before 4.10.5 (maintenance), and 4.9.x before 4.9.10 (legacy), Enterprise Edition before 6.0.0 RC2 (development), 5.2.x before 5.2.10 (legacy), and 5.3.x before 5.3.5 (maintenance), and Professional Edition before 6.0.0 RC2 (development), 4.9.x before 4.9.10 (legacy) and 4.10.x before 4.10.5 (maintenance) allow remote attackers to hijack the cart session of a client via Cross-Site Request Forgery (CSRF) if the following pre-conditions are met: (1) the attacker knows which shop is presently used by the client, (2) the attacker knows the exact time when the customer will add product items to the cart, (3) the attacker knows which product items are already in the cart (has to know their article IDs), and (4) the attacker would be able to trick user into clicking a button (submit form) of an e-mail or remote site within the period of visiting the shop and placing an order.

    Published: 20 Feb 2018
    7.5
    High

    CVE-2017-14993

    Last Modified: 21 Nov 2024

    OXID eShop Community Edition before 6.0.0 RC3 (development), 4.10.x before 4.10.6 (maintenance), and 4.9.x before 4.9.11 (legacy), Enterprise Edition before 6.0.0 RC3 (development), 5.2.x before 5.2.11 (legacy), and 5.3.x before 5.3.6 (maintenance), and Professional Edition before 6.0.0 RC3 (development), 4.9.x before 4.9.11 (legacy) and 4.10.x before 4.10.6 (maintenance) allow remote attackers to crawl specially crafted URLs (aka "forced browsing") in order to overflow the database of the shop and consequently make it stop working. Prerequisite: the shop allows rendering empty categories to the storefront via an admin option.

    Published: 20 Feb 2018
    6.1
    Medium

    CVE-2018-7265

    Last Modified: 21 Nov 2024

    Shimmie 2 2.6.0 allows an attacker to upload a crafted SVG file that enables stored XSS.

    Published: 20 Feb 2018
    5.9
    Medium

    CVE-2017-17455

    Last Modified: 21 Nov 2024

    Mahara 16.10 before 16.10.7, 17.04 before 17.04.5, and 17.10 before 17.10.2 are vulnerable to being forced, via a man-in-the-middle attack, to interact with Mahara on the HTTP protocol rather than HTTPS even when an SSL certificate is present.

    Published: 20 Feb 2018
    5.4
    Medium

    CVE-2017-17454

    Last Modified: 21 Nov 2024

    Mahara 16.10 before 16.10.7 and 17.04 before 17.04.5 and 17.10 before 17.10.2 have a Cross Site Scripting (XSS) vulnerability when a user enters invalid UTF-8 characters. These are now going to be discarded in Mahara along with NULL characters and invalid Unicode characters. Mahara will also avoid direct $_GET and $_POST usage where possible, and instead use param_exists() and the correct param_*() function to fetch the expected value.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2018-6487

    Last Modified: 21 Nov 2024

    Remote Disclosure of Information in Micro Focus Universal CMDB Foundation Software, version numbers 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 4.10, 4.11. This vulnerability could be remotely exploited to allow disclosure of information.

    Published: 20 Feb 2018
    6.1
    Medium

    CVE-2015-6544

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in application/dashboard.class.inc.php in Combodo iTop before 2.2.0-2459 allows remote attackers to inject arbitrary web script or HTML via a dashboard title.

    Published: 20 Feb 2018
    5.8
    Medium

    CVE-2018-5477

    Last Modified: 21 Nov 2024

    An Information Exposure issue was discovered in ABB netCADOPS Web Application Version 3.4 and prior, netCADOPS Web Application Version 7.1 and prior, netCADOPS Web Application Version 7.2x and prior, netCADOPS Web Application Version 8.0 and prior, and netCADOPS Web Application Version 8.1 and prior. A vulnerability exists in the password entry section of netCADOPS Web Application that may expose critical database information.

    Published: 20 Feb 2018
    5.9
    Medium

    CVE-2017-10963

    Last Modified: 21 Nov 2024

    In Knox SDS IAM (Identity Access Management) and EMM (Enterprise Mobility Management) 16.11 on Samsung mobile devices, a man-in-the-middle attacker can install any application into the Knox container (without the user's knowledge) by inspecting network traffic from a Samsung server and injecting content at a certain point in the update sequence. This installed application can further leak information stored inside the Knox container to the outside world.

    Published: 20 Feb 2018
    5.5
    Medium

    CVE-2017-6193

    Last Modified: 21 Nov 2024

    Buffer overflow in APNGDis 2.8 and earlier allows remote attackers to cause a denial of service and possibly execute arbitrary code via a crafted image containing a malformed image size descriptor in the IHDR chunk.

    Published: 20 Feb 2018
    5.5
    Medium

    CVE-2017-6192

    Last Modified: 21 Nov 2024

    Buffer overflow in APNGDis 2.8 and earlier allows a remote attackers to cause denial of service and possibly execute arbitrary code via a crafted image containing a malformed chunk size descriptor.

    Published: 20 Feb 2018
    4.8
    Medium

    CVE-2018-7205

    Last Modified: 19 Dec 2025

    Reflected Cross-Site Scripting vulnerability in "Design" on "Edit device layout" in Kentico 9 through 11 allows remote attackers to execute malicious JavaScript via a malicious devicename parameter in a link that is entered via the "Pages -> Edit template properties -> Device Layouts -> Create device layout (and edit created device layout) -> Design" screens. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout

    Published: 20 Feb 2018
    7.2
    High

    CVE-2018-7046

    Last Modified: 19 Dec 2025

    Arbitrary code execution vulnerability in Kentico 9 through 11 allows remote authenticated users to execute arbitrary operating system commands in a dynamic .NET code evaluation context via C# code in a "Pages -> Edit -> Template -> Edit template properties -> Layout" box. NOTE: the vendor has responded that there is intended functionality for authorized users to edit and update ascx code layout

    Published: 20 Feb 2018
    6.1
    Medium

    CVE-2018-6940

    Last Modified: 21 Nov 2024

    A /shell?cmd= XSS issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with CSRF.

    Published: 20 Feb 2018
    8.8
    High

    CVE-2018-6941

    Last Modified: 21 Nov 2024

    A /shell?cmd= CSRF issue exists in the HTTPD component of NAT32 v2.2 Build 22284 devices that can be exploited for Remote Code Execution in conjunction with XSS.

    Published: 20 Feb 2018
    7.5
    High

    CVE-2016-6272

    Last Modified: 21 Nov 2024

    XPath injection vulnerability in Epic MyChart allows remote attackers to access contents of an XML document containing static display strings, such as field labels, via the topic parameter to help.asp. NOTE: this was originally reported as a SQL injection vulnerability, but this may be inaccurate.

    Published: 20 Feb 2018
    6.1
    Medium

    CVE-2017-16356

    Last Modified: 21 Nov 2024

    Reflected XSS in Kubik-Rubik SIGE (aka Simple Image Gallery Extended) before 3.3.0 allows attackers to execute JavaScript in a victim's browser by having them visit a plugins/content/sige/plugin_sige/print.php link with a crafted img, name, or caption parameter.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2015-2081

    Last Modified: 21 Nov 2024

    Datto ALTO and SIRIS devices allow Remote Code Execution via unauthenticated requests to PHP scripts.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2015-9254

    Last Modified: 21 Nov 2024

    Datto ALTO and SIRIS devices have a default VNC password.

    Published: 20 Feb 2018
    5.3
    Medium

    CVE-2015-9255

    Last Modified: 21 Nov 2024

    Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information about data, software versions, configuration, and virtual machines via a request to a Web Virtual Directory.

    Published: 20 Feb 2018
    5.3
    Medium

    CVE-2015-9256

    Last Modified: 21 Nov 2024

    Datto ALTO and SIRIS devices allow remote attackers to obtain sensitive information via access to device/VM restore mount points, because they do not have ACLs by default.

    Published: 20 Feb 2018
    7.5
    High

    CVE-2017-18192

    Last Modified: 21 Nov 2024

    smart/calculator/gallerylock/CalculatorActivity.java in the "Photo,Video Locker-Calculator" application through 18 for Android allows attackers to access files via the backdoor 17621762 PIN.

    Published: 20 Feb 2018
    7.5
    High

    CVE-2017-16835

    Last Modified: 21 Nov 2024

    The "Photo,Video Locker-Calculator" application 12.0 for Android has android:allowBackup="true" in AndroidManifest.xml, which allows attackers to obtain sensitive cleartext information via an "adb backup '-f smart.calculator.gallerylock'" command.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2018-7263

    Last Modified: 21 Nov 2024

    The mad_decoder_run() function in decoder.c in Underbit libmad through 0.15.1b allows remote attackers to cause a denial of service (SIGABRT because of double free or corruption) or possibly have unspecified other impact via a crafted file. NOTE: this may overlap CVE-2017-11552.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2018-7259

    Last Modified: 21 Nov 2024

    The FSX / P3Dv4 installer 2.0.1.231 for Flight Sim Labs A320-X sends a user's Google account credentials to http://installLog.flightsimlabs.com/LogHandler3.ashx if a pirated serial number has been entered, which allows remote attackers to obtain sensitive information, e.g., by sniffing the network for cleartext HTTP traffic. This behavior was removed in 2.0.1.232.

    Published: 20 Feb 2018
    8.1
    High

    CVE-2018-1417

    Last Modified: 21 Nov 2024

    Under certain circumstances, a flaw in the J9 JVM (IBM SDK, Java Technology Edition 7.1 and 8.0) allows untrusted code running under a security manager to elevate its privileges. IBM X-Force ID: 138823.

    Published: 20 Feb 2018
    5.5
    Medium

    CVE-2018-7273

    Last Modified: 21 Nov 2024

    In the Linux kernel through 4.15.4, the floppy driver reveals the addresses of kernel functions and global variables using printk calls within the function show_floppy in drivers/block/floppy.c. An attacker can read this information from dmesg and use the addresses to find the locations of kernel code and data and bypass kernel security protections such as KASLR.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2018-7584

    Last Modified: 21 Nov 2024

    In PHP through 5.6.33, 7.0.x before 7.0.28, 7.1.x through 7.1.14, and 7.2.x through 7.2.2, there is a stack-based buffer under-read while parsing an HTTP response in the php_stream_url_wrap_http_ex function in ext/standard/http_fopen_wrapper.c. This subsequently results in copying a large string.

    Published: 20 Feb 2018
    9.8
    Critical

    CVE-2018-7251

    Last Modified: 21 Nov 2024

    An issue was discovered in config/error.php in Anchor 0.12.3. The error log is exposed at an errors.log URI, and contains MySQL credentials if a MySQL error (such as "Too many connections") has occurred.

    Published: 19 Feb 2018
    5.9
    Medium

    CVE-2018-5763

    Last Modified: 21 Nov 2024

    An issue was discovered in OXID eShop Enterprise Edition before 5.3.7 and 6.x before 6.0.1. By entering specially crafted URLs, an attacker is able to bring the shop server to a standstill and hence, it stops working. This is only valid if OXID High Performance Option is activated and Varnish is used.

    Published: 19 Feb 2018
    7.2
    High

    CVE-2016-10007

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the "Marketing > Forms" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_FORM_HANDLER_orderBy parameter.

    Published: 19 Feb 2018
    7.2
    High

    CVE-2016-10008

    Last Modified: 21 Nov 2024

    SQL injection vulnerability in the "Content Types > Content Types" screen in dotCMS before 3.7.2 and 4.x before 4.1.1 allows remote authenticated administrators to execute arbitrary SQL commands via the _EXT_STRUCTURE_direction parameter.

    Published: 19 Feb 2018
    5.3
    Medium

    CVE-2014-3972

    Last Modified: 21 Nov 2024

    Directory traversal vulnerability in Apexis APM-J601-WS cameras with firmware before 17.35.2.49 allows remote attackers to read arbitrary files via unspecified vectors.

    Published: 19 Feb 2018