CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2018-6846

    Last Modified: 21 Nov 2024

    Z-BlogPHP 1.5.1 allows remote attackers to discover the full path via a direct request to zb_system/function/lib/upload.php.

    Published: 8 Feb 2018
    8.8
    High

    CVE-2017-7351

    Last Modified: 21 Nov 2024

    A SQL injection issue exists in a file upload handler in REDCap 7.x before 7.0.11 via a trailing substring to SendITController:upload.

    Published: 8 Feb 2018
    6.1
    Medium

    CVE-2018-0513

    Last Modified: 21 Nov 2024

    Cross-site scripting vulnerability in MTS Simple Booking C, MTS Simple Booking Business version 1.28.0 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

    Published: 8 Feb 2018
    9.8
    Critical

    CVE-2018-0514

    Last Modified: 21 Nov 2024

    MP Form Mail CGI eCommerce Edition Ver 2.0.13 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 8 Feb 2018
    6.8
    Medium

    CVE-2018-0512

    Last Modified: 21 Nov 2024

    Devices with IP address setting tool "MagicalFinder" provided by I-O DATA DEVICE, INC. allow authenticated attackers to execute arbitrary OS commands via unspecified vectors.

    Published: 8 Feb 2018
    7.8
    High

    CVE-2018-0517

    Last Modified: 21 Nov 2024

    Untrusted search path vulnerability in Anshin net security for Windows Version 16.0.1.44 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

    Published: 8 Feb 2018
    5.3
    Medium

    CVE-2018-0138

    Last Modified: 11 Aug 2026

    A vulnerability in the detection engine of Cisco Firepower System Software could allow an unauthenticated, remote attacker to bypass file policies that are configured to block files transmitted to an affected device via the BitTorrent protocol. The vulnerability exists because the affected software does not detect BitTorrent handshake messages correctly. An attacker could exploit this vulnerability by sending a crafted BitTorrent connection request to an affected device. A successful exploit could allow the attacker to bypass file policies that are configured to block files transmitted to the affected device via the BitTorrent protocol. Cisco Bug IDs: CSCve26946.

    Published: 8 Feb 2018
    9.8
    Critical

    CVE-2018-0125

    Last Modified: 14 Jan 2026

    A vulnerability in the web interface of the Cisco RV132W ADSL2+ Wireless-N VPN and RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to execute arbitrary code and gain full control of an affected system, including issuing commands with root privileges. The attacker could also cause an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to an incomplete input validation on user-controlled input in an HTTP request to the targeted device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected system. A successful exploit could allow the attacker to execute arbitrary code as the root user and gain full control of the affected system or cause it to reload, resulting in a DoS condition. This vulnerability is fixed in firmware version 1.0.1.11 for the following Cisco products: RV132W ADSL2+ Wireless-N VPN Router and RV134W VDSL2 Wireless-AC VPN Router. Cisco Bug IDs: CSCvg92737, CSCvh60170.

    Published: 8 Feb 2018
    6.1
    Medium

    CVE-2018-6834

    Last Modified: 21 Nov 2024

    static/js/pad_utils.js in Etherpad Lite before v1.6.3 has XSS via window.location.href.

    Published: 8 Feb 2018
    8.6
    High

    CVE-2018-0117

    Last Modified: 2 Dec 2024

    A vulnerability in the ingress packet processing functionality of the Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software could allow an unauthenticated, remote attacker to cause both control function (CF) instances on an affected system to reload, resulting in a denial of service (DoS) condition. The vulnerability is due to insufficient handling of user-supplied data by the affected software. An attacker could exploit this vulnerability by sending malicious traffic to the internal distributed instance (DI) network address on an affected system. A successful exploit could allow the attacker to cause an unhandled error condition on the affected system, which would cause the CF instances to reload and consequently cause the entire VPC to reload, resulting in the disconnection of all subscribers and a DoS condition on the affected system. This vulnerability affects Cisco Virtualized Packet Core-Distributed Instance (VPC-DI) Software N4.0 through N5.5 with the Cisco StarOS operating system 19.2 through 21.3. Cisco Bug IDs: CSCve17656.

    Published: 8 Feb 2018
    9.8
    Critical

    CVE-2018-0127

    Last Modified: 2 Dec 2024

    A vulnerability in the web interface of Cisco RV132W ADSL2+ Wireless-N VPN Routers and Cisco RV134W VDSL2 Wireless-AC VPN Routers could allow an unauthenticated, remote attacker to view configuration parameters for an affected device, which could lead to the disclosure of confidential information. The vulnerability is due to the absence of user authentication requirements for certain pages that are part of the web interface and contain confidential information for an affected device. An attacker could exploit this vulnerability by sending a crafted HTTP request to an affected device and examining the HTTP response to the request. A successful exploit could allow the attacker to view configuration parameters, including the administrator password, for the affected device. Cisco Bug IDs: CSCvg92739, CSCvh60172.

    Published: 8 Feb 2018
    5.3
    Medium

    CVE-2018-0134

    Last Modified: 2 Dec 2024

    A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to determine whether a subscriber username is valid. The vulnerability occurs because the Cisco Policy Suite RADIUS server component returns different authentication failure messages based on the validity of usernames. An attacker could use these messages to determine whether a valid subscriber username has been identified. The attacker could use this information in subsequent attacks against the system. Cisco Bug IDs: CSCvg47830.

    Published: 8 Feb 2018
    6.5
    Medium

    CVE-2018-0140

    Last Modified: 2 Dec 2024

    A vulnerability in the spam quarantine of Cisco Email Security Appliance and Cisco Content Security Management Appliance could allow an authenticated, remote attacker to download any message from the spam quarantine by modifying browser string information. The vulnerability is due to a lack of verification of authenticated user accounts. An attacker could exploit this vulnerability by modifying browser strings to see messages submitted by other users to the spam quarantine within their company. Cisco Bug IDs: CSCvg39759, CSCvg42295.

    Published: 8 Feb 2018
    9.8
    Critical

    CVE-2018-6835

    Last Modified: 21 Nov 2024

    node/hooks/express/apicalls.js in Etherpad Lite before v1.6.3 mishandles JSONP, which allows remote attackers to bypass intended access restrictions.

    Published: 8 Feb 2018
    5.4
    Medium

    CVE-2018-6844

    Last Modified: 21 Nov 2024

    MyBB 1.8.14 has XSS via the Title or Description field on the Edit Forum screen.

    Published: 8 Feb 2018
    4.7
    Medium

    CVE-2018-0119

    Last Modified: 2 Dec 2024

    A vulnerability in certain authentication controls in the account services of Cisco Spark could allow an authenticated, remote attacker to interact with and view information on an affected device that would normally be prohibited. The vulnerability is due to the improper display of user-account tokens generated in the system. An attacker could exploit this vulnerability by logging in to the device with a token in use by another account. Successful exploitation could allow the attacker to cause a partial impact to the device's confidentiality, integrity, and availability. Cisco Bug IDs: CSCvg05206.

    Published: 8 Feb 2018
    5.5
    Medium

    CVE-2018-0123

    Last Modified: 2 Dec 2024

    A Path Traversal vulnerability in the diagnostic shell for Cisco IOS and IOS XE Software could allow an authenticated, local attacker to use certain diagnostic shell commands that can overwrite system files. These system files may be sensitive and should not be able to be overwritten by a user of the diagnostic shell. The vulnerability is due to lack of proper input validation for certain diagnostic shell commands. An attacker could exploit this vulnerability by authenticating to the device, entering the diagnostic shell, and providing crafted user input to commands at the local diagnostic shell CLI. Successful exploitation could allow the attacker to overwrite system files that should be restricted. Cisco Bug IDs: CSCvg41950.

    Published: 8 Feb 2018
    6.1
    Medium

    CVE-2018-0128

    Last Modified: 2 Dec 2024

    A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvh02082.

    Published: 8 Feb 2018
    8.6
    High

    CVE-2018-0132

    Last Modified: 2 Dec 2024

    A vulnerability in the forwarding information base (FIB) code of Cisco IOS XR Software could allow an unauthenticated, remote attacker to cause inconsistency between the routing information base (RIB) and the FIB, resulting in a denial of service (DoS) condition. The vulnerability is due to incorrect processing of extremely long routing updates. An attacker could exploit this vulnerability by sending a large routing update. A successful exploit could allow the attacker to trigger inconsistency between the FIB and the RIB, resulting in a DoS condition. Cisco Bug IDs: CSCus84718.

    Published: 8 Feb 2018
    4.3
    Medium

    CVE-2018-0135

    Last Modified: 2 Dec 2024

    A vulnerability in Cisco Unified Communications Manager could allow an authenticated, remote attacker to access sensitive information on an affected system. The vulnerability exists because the affected software improperly validates user-supplied search input. An attacker could exploit this vulnerability by sending malicious requests to an affected system. A successful exploit could allow the attacker to retrieve sensitive information from the affected system. Cisco Bug IDs: CSCvf17644.

    Published: 8 Feb 2018
    8.6
    High

    CVE-2018-0137

    Last Modified: 2 Dec 2024

    A vulnerability in the TCP throttling process of Cisco Prime Network could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is due to insufficient rate limiting protection for TCP listening ports. An attacker could exploit this vulnerability by sending the affected device a high rate of TCP SYN packets to the local IP address of the targeted application. A successful exploit could allow the attacker to cause the device to consume a high amount of memory and become slow, or to stop accepting new TCP connections to the application. Cisco Bug IDs: CSCvg48152.

    Published: 8 Feb 2018
    8.8
    High

    CVE-2018-0113

    Last Modified: 2 Dec 2024

    A vulnerability in an operations script of Cisco UCS Central could allow an authenticated, remote attacker to execute arbitrary shell commands with the privileges of the daemon user. The vulnerability is due to insufficient input validation. An attacker could exploit this vulnerability by posting a crafted request to the user interface of Cisco UCS Central. This vulnerability affects Cisco UCS Central Software prior to Release 2.0(1c). Cisco Bug IDs: CSCve70825.

    Published: 8 Feb 2018
    7.2
    High

    CVE-2018-0116

    Last Modified: 2 Dec 2024

    A vulnerability in the RADIUS authentication module of Cisco Policy Suite could allow an unauthenticated, remote attacker to be authorized as a subscriber without providing a valid password; however, the attacker must provide a valid username. The vulnerability is due to incorrect RADIUS user credential validation. An attacker could exploit this vulnerability by attempting to access a Cisco Policy Suite domain configured with RADIUS authentication. An exploit could allow the attacker to be authorized as a subscriber without providing a valid password. This vulnerability affects the Cisco Policy Suite application running a release prior to 13.1.0 with Hotfix Patch 1 when RADIUS authentication is configured for a domain. Cisco Policy Suite Release 14.0.0 is also affected, as it includes vulnerable code, but RADIUS authentication is not officially supported in Cisco Policy Suite Releases 14.0.0 and later. Cisco Bug IDs: CSCvg40124.

    Published: 8 Feb 2018
    4.3
    Medium

    CVE-2018-0120

    Last Modified: 2 Dec 2024

    A vulnerability in the web framework of Cisco Unified Communications Manager could allow an authenticated, remote attacker to conduct an SQL injection attack against an affected system. The vulnerability exists because the affected software fails to validate user-supplied input in certain SQL queries that bypass protection filters. An attacker could exploit this vulnerability by submitting crafted HTTP requests that contain malicious SQL statements to an affected system. A successful exploit could allow the attacker to determine the presence of certain values in the database of the affected system. Cisco Bug IDs: CSCvg74810.

    Published: 8 Feb 2018
    4.4
    Medium

    CVE-2018-0122

    Last Modified: 2 Dec 2024

    A vulnerability in the CLI of the Cisco StarOS operating system for Cisco ASR 5000 Series Aggregation Services Routers could allow an authenticated, local attacker to overwrite system files that are stored in the flash memory of an affected system. The vulnerability is due to insufficient validation of user-supplied input by the affected operating system. An attacker could exploit this vulnerability by injecting crafted command arguments into a vulnerable CLI command for the affected operating system. A successful exploit could allow the attacker to overwrite or modify arbitrary files that are stored in the flash memory of an affected system. To exploit this vulnerability, the attacker would need to authenticate to an affected system by using valid administrator credentials. Cisco Bug IDs: CSCvf93335.

    Published: 8 Feb 2018
    6.1
    Medium

    CVE-2018-0129

    Last Modified: 2 Dec 2024

    A vulnerability in the web-based management interface of Cisco Data Center Analytics Framework could allow an unauthenticated, remote attacker to conduct a reflected cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device. The vulnerability is due to insufficient validation of user-supplied input by the web-based management interface of an affected device. An attacker could exploit this vulnerability by persuading a user of the interface to click a crafted link. A successful exploit could allow the attacker to execute arbitrary script code in the context of the interface or allow the attacker to access sensitive browser-based information. Cisco Bug IDs: CSCvh02088.

    Published: 8 Feb 2018
    8.1
    High

    CVE-2018-1000130

    Last Modified: 21 Nov 2024

    A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.

    Published: 8 Feb 2018
    7.5
    High

    CVE-2018-7051

    Last Modified: 21 Nov 2024

    An issue was discovered in Irssi before 1.0.7 and 1.1.x before 1.1.1. Certain nick names could result in out-of-bounds access when printing theme strings.

    Published: 8 Feb 2018
    7.5
    High

    CVE-2018-7420

    Last Modified: 21 Nov 2024

    In Wireshark 2.2.0 to 2.2.12 and 2.4.0 to 2.4.4, the pcapng file parser could crash. This was addressed in wiretap/pcapng.c by adding a block-size check for sysdig event blocks.

    Published: 8 Feb 2018
    6.1
    Medium

    CVE-2018-1000129

    Last Modified: 21 Nov 2024

    An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.

    Published: 8 Feb 2018
    6.5
    Medium

    CVE-2018-1052

    Last Modified: 21 Nov 2024

    Memory disclosure vulnerability in table partitioning was found in postgresql 10.x before 10.2, allowing an authenticated attacker to read arbitrary bytes of server memory via purpose-crafted insert to a partitioned table.

    Published: 8 Feb 2018
    7
    High

    CVE-2018-1053

    Last Modified: 21 Nov 2024

    In postgresql 9.3.x before 9.3.21, 9.4.x before 9.4.16, 9.5.x before 9.5.11, 9.6.x before 9.6.7 and 10.x before 10.2, pg_upgrade creates file in current working directory containing the output of `pg_dumpall -g` under umask which was in effect when the user invoked pg_upgrade, and not under 0077 which is normally used for other temporary files. This can allow an authenticated attacker to read or modify the one file, which may contain encrypted or unencrypted database passwords. The attack is infeasible if a directory mode blocks the attacker searching the current working directory or if the prevailing umask blocks the attacker opening the file.

    Published: 8 Feb 2018
    6.5
    Medium

    CVE-2018-6869

    Last Modified: 10 Jul 2025

    In ZZIPlib 0.13.68, there is an uncontrolled memory allocation and a crash in the __zzip_parse_root_directory function of zzip/zip.c. Remote attackers could leverage this vulnerability to cause a denial of service via a crafted zip file.

    Published: 8 Feb 2018
    7.4
    High

    CVE-2017-15397

    Last Modified: 21 Nov 2024

    Inappropriate implementation in ChromeVox in Google Chrome OS prior to 62.0.3202.74 allowed a remote attacker in a privileged network position to observe or tamper with certain cleartext HTTP requests by leveraging that position.

    Published: 7 Feb 2018
    7.5
    High

    CVE-2018-6829

    Last Modified: 21 Nov 2024

    cipher/elgamal.c in Libgcrypt through 1.8.2, when used to encrypt messages directly, improperly encodes plaintexts, which allows attackers to obtain sensitive information by reading ciphertext data (i.e., it does not have semantic security in face of a ciphertext-only attack). The Decisional Diffie-Hellman (DDH) assumption does not hold for Libgcrypt's ElGamal implementation.

    Published: 7 Feb 2018
    5.4
    Medium

    CVE-2018-6795

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Naukri Clone Script 3.0.3 has Stored XSS via every profile input field.

    Published: 7 Feb 2018
    5.4
    Medium

    CVE-2018-6655

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Doctor Search Script 1.0.2 has Stored XSS via an arbitrary profile field.

    Published: 7 Feb 2018
    5.4
    Medium

    CVE-2018-6796

    Last Modified: 21 Nov 2024

    PHP Scripts Mall Multilanguage Real Estate MLM Script 3.0 has Stored XSS via every profile input field.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12471

    Last Modified: 21 Nov 2024

    The cnb_parse_lev function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact by leveraging failure to check for out-of-bounds conditions, which triggers an invalid read in the hexdump function.

    Published: 7 Feb 2018
    7.5
    High

    CVE-2017-12463

    Last Modified: 21 Nov 2024

    Memory leak in the ccnl_app_RX function in ccnl-uapi.c in CCN-lite before 2.00 allows context-dependent attackers to cause a denial of service (memory consumption) via vectors involving an envelope_s structure pointer when the packet format is unknown.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2018-1366

    Last Modified: 21 Nov 2024

    IBM Content Navigator 2.0 and 3.0 is vulnerable to Comma Separated Value (CSV) Injection. An attacker could exploit this vulnerability to exploit other vulnerabilities in spreadsheet software. IBM X-Force ID: 137452.

    Published: 7 Feb 2018
    5.4
    Medium

    CVE-2018-1382

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.0.0 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 138079.

    Published: 7 Feb 2018
    7.5
    High

    CVE-2018-1388

    Last Modified: 21 Nov 2024

    GSKit V7 may disclose side channel information via discrepancies between valid and invalid PKCS#1 padding. IBM X-Force ID: 138212.

    Published: 7 Feb 2018
    6.1
    Medium

    CVE-2018-6824

    Last Modified: 21 Nov 2024

    Cozy version 2 has XSS allowing remote attackers to obtain administrative access via JavaScript code in the url parameter to the /api/proxy URI, as demonstrated by an XMLHttpRequest call with an 'email:"[email protected]"' request, which can be followed by a password reset.

    Published: 7 Feb 2018
    4.3
    Medium

    CVE-2017-1785

    Last Modified: 21 Nov 2024

    IBM API Connect 5.0.7 and 5.0.8 could allow an authenticated remote user to modify query parameters to obtain sensitive information. IBM X-Force ID: 136859.

    Published: 7 Feb 2018
    9.8
    Critical

    CVE-2017-12470

    Last Modified: 21 Nov 2024

    Integer overflow in the ndn_parse_sequence function in CCN-lite before 2.00 allows context-dependent attackers to have unspecified impact via vectors involving the typ and vallen variables.

    Published: 7 Feb 2018
    7.8
    High

    CVE-2016-6169

    Last Modified: 21 Nov 2024

    Heap-based buffer overflow in Foxit Reader and PhantomPDF 7.3.4.311 and earlier on Windows allows remote attackers to cause a denial of service (memory corruption and application crash) or potentially execute arbitrary code via the Bezier data in a crafted PDF file.

    Published: 7 Feb 2018
    8.8
    High

    CVE-2017-17552

    Last Modified: 24 Oct 2025

    /LoadFrame in Zoho ManageEngine AD Manager Plus build 6590 - 6613 allows attackers to conduct URL Redirection attacks via the src parameter, resulting in a bypass of CSRF protection, or potentially masquerading a malicious URL as trusted.

    Published: 7 Feb 2018
    5.5
    Medium

    CVE-2016-2540

    Last Modified: 21 Nov 2024

    Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted FORMATCHUNK structure.

    Published: 7 Feb 2018
    5.5
    Medium

    CVE-2016-2541

    Last Modified: 21 Nov 2024

    Audacity before 2.1.2 allows remote attackers to cause a denial of service (memory corruption and application crash) via a crafted MP2 file.

    Published: 7 Feb 2018