CVE Feed

    Dashboard / CVE

    5.3
    Medium

    CVE-2018-5443

    Last Modified: 21 Nov 2024

    A SQL Injection issue was discovered in Advantech WebAccess/SCADA versions prior to V8.2_20170817. WebAccess/SCADA does not properly sanitize its inputs for SQL commands.

    Published: 25 Jan 2018
    4.3
    Medium

    CVE-2017-15546

    Last Modified: 21 Nov 2024

    The Security Console in EMC RSA Authentication Manager 8.2 SP1 P6 and earlier is affected by a blind SQL injection vulnerability. Authenticated malicious users could potentially exploit this vulnerability to read any unencrypted data from the database.

    Published: 25 Jan 2018
    7.8
    High

    CVE-2018-6323

    Last Modified: 21 Nov 2024

    The elf_object_p function in elfcode.h in the Binary File Descriptor (BFD) library (aka libbfd), as distributed in GNU Binutils 2.29.1, has an unsigned integer overflow because bfd_size_type multiplication is not used. A crafted ELF file allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

    Published: 25 Jan 2018
    7.8
    High

    CVE-2017-17969

    Last Modified: 10 Jan 2025

    Heap-based buffer overflow in the NCompress::NShrink::CDecoder::CodeReal method in 7-Zip before 18.00 and p7zip allows remote attackers to cause a denial of service (out-of-bounds write) or potentially execute arbitrary code via a crafted ZIP archive.

    Published: 25 Jan 2018
    7.8
    High

    CVE-2018-6954

    Last Modified: 9 Jun 2025

    systemd-tmpfiles in systemd through 237 mishandles symlinks present in non-terminal path components, which allows local users to obtain ownership of arbitrary files via vectors involving creation of a directory and a file under that directory, and later replacing that directory with a symlink. This occurs even if the fs.protected_symlinks sysctl is turned on.

    Published: 25 Jan 2018
    8.1
    High

    CVE-2017-1000504

    Last Modified: 21 Nov 2024

    A race condition during Jenkins 2.94 and earlier; 2.89.1 and earlier startup could result in the wrong order of execution of commands during initialization. There is a very short window of time after startup during which Jenkins may no longer show the 'Please wait while Jenkins is getting ready to work' message but Cross-Site Request Forgery (CSRF) protection may not yet be effective.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-1000006

    Last Modified: 21 Nov 2024

    GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2017-1000474

    Last Modified: 21 Nov 2024

    Soyket Chowdhury Vehicle Sales Management System version 2017-07-30 is vulnerable to multiple SQL Injecting in login/vehicle.php, login/profile.php, login/Actions.php, login/manage_employee.php, and login/sell.php scripts resulting in the expose of user's login credentials, SQL Injection and Stored XSS vulnerability, which leads to remote code executing.

    Published: 24 Jan 2018
    5.5
    Medium

    CVE-2018-5759

    Last Modified: 21 Nov 2024

    jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file.

    Published: 24 Jan 2018
    5.4
    Medium

    CVE-2018-6190

    Last Modified: 21 Nov 2024

    Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.

    Published: 24 Jan 2018
    5.5
    Medium

    CVE-2018-6191

    Last Modified: 21 Nov 2024

    The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.

    Published: 24 Jan 2018
    5.5
    Medium

    CVE-2018-6192

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0, the pdf_read_new_xref function in pdf/pdf-xref.c allows remote attackers to cause a denial of service (segmentation violation and application crash) via a crafted pdf file.

    Published: 24 Jan 2018
    4.7
    Medium

    CVE-2018-6193

    Last Modified: 21 Nov 2024

    A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl.

    Published: 24 Jan 2018
    6.1
    Medium

    CVE-2018-5705

    Last Modified: 21 Nov 2024

    Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-4834

    Last Modified: 21 Nov 2024

    A vulnerability has been identified in Desigo PXC00-E.D V4.10 (All versions < V4.10.111), Desigo PXC00-E.D V5.00 (All versions < V5.0.171), Desigo PXC00-E.D V5.10 (All versions < V5.10.69), Desigo PXC00-E.D V6.00 (All versions < V6.0.204), Desigo PXC00/64/128-U V4.10 (All versions < V4.10.111 only with web module), Desigo PXC00/64/128-U V5.00 (All versions < V5.0.171 only with web module), Desigo PXC00/64/128-U V5.10 (All versions < V5.10.69 only with web module), Desigo PXC00/64/128-U V6.00 (All versions < V6.0.204 only with web module), Desigo PXC001-E.D V4.10 (All versions < V4.10.111), Desigo PXC001-E.D V5.00 (All versions < V5.0.171), Desigo PXC001-E.D V5.10 (All versions < V5.10.69), Desigo PXC001-E.D V6.00 (All versions < V6.0.204), Desigo PXC100-E.D V4.10 (All versions < V4.10.111), Desigo PXC100-E.D V5.00 (All versions < V5.0.171), Desigo PXC100-E.D V5.10 (All versions < V5.10.69), Desigo PXC100-E.D V6.00 (All versions < V6.0.204), Desigo PXC12-E.D V4.10 (All versions < V4.10.111), Desigo PXC12-E.D V5.00 (All versions < V5.0.171), Desigo PXC12-E.D V5.10 (All versions < V5.10.69), Desigo PXC12-E.D V6.00 (All versions < V6.0.204), Desigo PXC200-E.D V4.10 (All versions < V4.10.111), Desigo PXC200-E.D V5.00 (All versions < V5.0.171), Desigo PXC200-E.D V5.10 (All versions < V5.10.69), Desigo PXC200-E.D V6.00 (All versions < V6.0.204), Desigo PXC22-E.D V4.10 (All versions < V4.10.111), Desigo PXC22-E.D V5.00 (All versions < V5.0.171), Desigo PXC22-E.D V5.10 (All versions < V5.10.69), Desigo PXC22-E.D V6.00 (All versions < V6.0.204), Desigo PXC22.1-E.D V4.10 (All versions < V4.10.111), Desigo PXC22.1-E.D V5.00 (All versions < V5.0.171), Desigo PXC22.1-E.D V5.10 (All versions < V5.10.69), Desigo PXC22.1-E.D V6.00 (All versions < V6.0.204), Desigo PXC36.1-E.D V4.10 (All versions < V4.10.111), Desigo PXC36.1-E.D V5.00 (All versions < V5.0.171), Desigo PXC36.1-E.D V5.10 (All versions < V5.10.69), Desigo PXC36.1-E.D V6.00 (All versions < V6.0.204), Desigo PXC50-E.D V4.10 (All versions < V4.10.111), Desigo PXC50-E.D V5.00 (All versions < V5.0.171), Desigo PXC50-E.D V5.10 (All versions < V5.10.69), Desigo PXC50-E.D V6.00 (All versions < V6.0.204), Desigo PXM20-E V4.10 (All versions < V4.10.111), Desigo PXM20-E V5.00 (All versions < V5.0.171), Desigo PXM20-E V5.10 (All versions < V5.10.69), Desigo PXM20-E V6.00 (All versions < V6.0.204). A remote attacker with network access to the device could potentially upload a new firmware image to the devices without prior authentication.

    Published: 24 Jan 2018
    9.1
    Critical

    CVE-2018-6017

    Last Modified: 21 Nov 2024

    Unencrypted transmission of images in Tinder iOS app and Tinder Android app allows an attacker to extract private sensitive information by sniffing network traffic.

    Published: 24 Jan 2018
    9.1
    Critical

    CVE-2018-6018

    Last Modified: 21 Nov 2024

    Fixed sizes of HTTPS responses in Tinder iOS app and Tinder Android app allow an attacker to extract private sensitive information by sniffing network traffic.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2017-13696

    Last Modified: 21 Nov 2024

    A buffer overflow vulnerability lies in the web server component of Dup Scout Enterprise 9.9.14, Disk Savvy Enterprise 9.9.14, Sync Breeze Enterprise 9.9.16, and Disk Pulse Enterprise 9.9.16 where an attacker can craft a malicious GET request and exploit the web server component. Successful exploitation of the software will allow an attacker to gain complete access to the system with NT AUTHORITY / SYSTEM level privileges. The vulnerability lies due to improper handling and sanitization of the incoming request.

    Published: 24 Jan 2018
    7.5
    High

    CVE-2018-5319

    Last Modified: 21 Nov 2024

    RAVPower FileHub 2.000.056 allows remote users to steal sensitive information via a crafted HTTP request.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5777

    Last Modified: 21 Nov 2024

    An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Remote clients can take advantage of a misconfiguration in the TFTP server that could allow attackers to execute arbitrary commands on the TFTP server via unspecified vectors.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5778

    Last Modified: 21 Nov 2024

    An issue was discovered in Ipswitch WhatsUp Gold before 2017 Plus SP1 (17.1.1). Multiple SQL injection vulnerabilities are present in the legacy .ASP pages, which could allow attackers to execute arbitrary SQL commands via unspecified vectors.

    Published: 24 Jan 2018
    7.8
    High

    CVE-2017-1000475

    Last Modified: 21 Nov 2024

    FreeSSHd 1.3.1 version is vulnerable to an Unquoted Path Service allowing local users to launch processes with elevated privileges.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2017-15718

    Last Modified: 21 Nov 2024

    The YARN NodeManager in Apache Hadoop 2.7.3 and 2.7.4 can leak the password for credential store provider used by the NodeManager to YARN Applications.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2017-1769

    Last Modified: 21 Nov 2024

    IBM Business Process Manager 8.6 is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 136783.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-5969

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5972

    Last Modified: 21 Nov 2024

    SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5977

    Last Modified: 21 Nov 2024

    SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5978

    Last Modified: 21 Nov 2024

    SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5984

    Last Modified: 21 Nov 2024

    SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5985

    Last Modified: 21 Nov 2024

    SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5986

    Last Modified: 21 Nov 2024

    SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5988

    Last Modified: 21 Nov 2024

    SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.

    Published: 24 Jan 2018
    7.5
    High

    CVE-2018-6184

    Last Modified: 21 Nov 2024

    ZEIT Next.js 4 before 4.2.3 has Directory Traversal under the /_next request namespace.

    Published: 24 Jan 2018
    5.5
    Medium

    CVE-2018-6187

    Last Modified: 21 Nov 2024

    In Artifex MuPDF 1.12.0, there is a heap-based buffer overflow vulnerability in the do_pdf_save_document function in the pdf/pdf-write.c file. Remote attackers could leverage the vulnerability to cause a denial of service via a crafted pdf file.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-5976

    Last Modified: 21 Nov 2024

    Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-5979

    Last Modified: 21 Nov 2024

    SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-6035

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user local file data via a crafted Chrome Extension.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6037

    Last Modified: 21 Nov 2024

    Inappropriate implementation in autofill in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to obtain autofill data with insufficient user gestures via a crafted HTML page.

    Published: 24 Jan 2018
    4.3
    Medium

    CVE-2018-6041

    Last Modified: 21 Nov 2024

    Incorrect security UI in navigation in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to spoof the contents of the Omnibox (URL bar) via a crafted HTML page.

    Published: 24 Jan 2018
    6.1
    Medium

    CVE-2018-6046

    Last Modified: 21 Nov 2024

    Insufficient data validation in DevTools in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted Chrome Extension.

    Published: 24 Jan 2018
    4.3
    Medium

    CVE-2018-6048

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak referrer information via a crafted HTML page.

    Published: 24 Jan 2018
    3.3
    Low

    CVE-2018-6053

    Last Modified: 21 Nov 2024

    Inappropriate implementation in New Tab Page in Google Chrome prior to 64.0.3282.119 allowed a local attacker to view website thumbnail images after clearing browser data via a crafted HTML page.

    Published: 24 Jan 2018
    9.1
    Critical

    CVE-2018-1000005

    Last Modified: 21 Nov 2024

    libcurl 7.49.0 to and including 7.57.0 contains an out bounds read in code handling HTTP/2 trailers. It was reported (https://github.com/curl/curl/pull/2231) that reading an HTTP/2 trailer could mess up future trailers since the stored size was one byte less than required. The problem is that the code that creates HTTP/1-like headers from the HTTP/2 trailer data once appended a string like `:` to the target buffer, while this was recently changed to `: ` (a space was added after the colon) but the following math wasn't updated correspondingly. When accessed, the data is read out of bounds and causes either a crash or that the (too large) data gets passed to client write. This could lead to a denial-of-service situation or an information disclosure if someone has a service that echoes back or uses the trailers for something.

    Published: 24 Jan 2018
    9.8
    Critical

    CVE-2018-1000007

    Last Modified: 21 Nov 2024

    libcurl 7.1 through 7.57.0 might accidentally leak authentication data to third parties. When asked to send custom headers in its HTTP requests, libcurl will send that set of headers first to the host in the initial URL but also, if asked to follow redirects and a 30X HTTP response code is returned, to the host mentioned in URL in the `Location:` response header value. Sending the same set of headers to subsequent hosts is in particular a problem for applications that pass on custom `Authorization:` headers, as this header often contains privacy sensitive information or data that could allow others to impersonate the libcurl-using client's request.

    Published: 24 Jan 2018
    7.8
    High

    CVE-2018-1000018

    Last Modified: 21 Nov 2024

    An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file.

    Published: 24 Jan 2018
    8.8
    High

    CVE-2018-6031

    Last Modified: 21 Nov 2024

    Use after free in PDFium in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6032

    Last Modified: 21 Nov 2024

    Insufficient policy enforcement in Blink in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user cross-origin data via a crafted HTML page.

    Published: 24 Jan 2018
    8.1
    High

    CVE-2018-6034

    Last Modified: 21 Nov 2024

    Insufficient data validation in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6036

    Last Modified: 21 Nov 2024

    Insufficient data validation in V8 in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to potentially leak user data via a crafted HTML page.

    Published: 24 Jan 2018
    6.5
    Medium

    CVE-2018-6038

    Last Modified: 21 Nov 2024

    Heap buffer overflow in WebGL in Google Chrome prior to 64.0.3282.119 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Published: 24 Jan 2018