6.5
    Medium

    CVE-2018-1002202

    Last Modified: 21 Nov 2024

    zip4j before 1.3.3 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published:5 Jun 2018
    5.5
    Medium

    CVE-2018-1002201

    Last Modified: 21 Nov 2024

    zt-zip before 1.13 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in a Zip archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published:5 Jun 2018
    5.5
    Medium

    CVE-2018-1002200

    Last Modified: 21 Nov 2024

    plexus-archiver before 3.6.0 is vulnerable to directory traversal, allowing attackers to write to arbitrary files via a ../ (dot dot slash) in an archive entry that is mishandled during extraction. This vulnerability is also known as 'Zip-Slip'.

    Published:5 Jun 2018
    9.8
    Critical

    CVE-2018-1002105

    Last Modified: 24 Dec 2018

    In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to establish a connection through the Kubernetes API server to backend servers, then send arbitrary requests over the same connection directly to the backend, authenticated with the Kubernetes API server's TLS credentials used to establish the backend connection.

    Source:evict
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002009

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in unsubscribe.html.php:3: via GET reuqest to the email variable.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002008

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in list-user.html.php:4: via GET request offset variable.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002007

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:15: via POST request variable html_id.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002006

    Last Modified: 20 Nov 2018

    These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002005

    Last Modified: 20 Nov 2018

    These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002004

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002003

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002002

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    4.8
    Medium

    CVE-2018-1002001

    Last Modified: 20 Nov 2018

    There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    7.2
    High

    CVE-2018-1002000

    Last Modified: 20 Nov 2018

    There is blind SQL injection in WordPress Arigato Autoresponder and Newsletter v2.5.1.8 These vulnerabilities require administrative privileges to exploit. There is an exploitable blind SQL injection vulnerability via the del_ids variable by POST request.

    Source:Larry W. Cashdollar
    Published:3 Dec 2018
    8.8
    High

    CVE-2018-1000888

    Last Modified: 10 Jan 2019

    PEAR Archive_Tar version 1.4.3 and earlier contains a CWE-502, CWE-915 vulnerability in the Archive_Tar class. There are several file operations with `$v_header['filename']` as parameter (such as file_exists, is_file, is_dir, etc). When extract is called without a specific prefix path, we can trigger unserialization by crafting a tar file with `phar://[path_to_malicious_phar_file]` as path. Object injection can be used to trigger destruct in the loaded PHP classes, e.g. the Archive_Tar class itself. With Archive_Tar object injection, arbitrary file deletion can occur because `@unlink($this->_temp_tarname)` is called. If another class with useful gadget is loaded, it may possible to cause remote code execution that can result in files being deleted or possibly modified. This vulnerability appears to have been fixed in 1.4.4.

    Source:Fariskhi Vidyan
    Published:27 Dec 2018
    6.5
    Medium

    CVE-2018-1000873

    Last Modified: 21 Nov 2024

    Fasterxml Jackson version Before 2.9.8 contains a CWE-20: Improper Input Validation vulnerability in Jackson-Modules-Java8 that can result in Causes a denial-of-service (DoS). This attack appear to be exploitable via The victim deserializes malicious input, specifically very large values in the nanoseconds field of a time value. This vulnerability appears to have been fixed in 2.9.8.

    Published:24 Oct 2018
    9.8
    Critical

    CVE-2018-1000861

    Last Modified: 5 Nov 2025

    A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that allows attackers to invoke some methods on Java objects by accessing crafted URLs that were not intended to be invoked this way.

    Published:5 Dec 2018
    7.5
    High

    CVE-2018-1000850

    Last Modified: 21 Nov 2024

    Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipulating the URL an attacker could add or delete resources otherwise unavailable to her.. This attack appear to be exploitable via An attacker should have access to an encoded path parameter on POST, PUT or DELETE request.. This vulnerability appears to have been fixed in 2.5.0 and later.

    Published:21 Oct 2018
    9.1
    Critical

    CVE-2018-1000844

    Last Modified: 21 Nov 2024

    Square Open Source Retrofit version Prior to commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437 contains a XML External Entity (XXE) vulnerability in JAXB that can result in An attacker could use this to remotely read files from the file system or to perform SSRF.. This vulnerability appears to have been fixed in After commit 4a693c5aeeef2be6c7ecf80e7b5ec79f6ab59437.

    Published:17 Apr 2018
    10
    Critical

    CVE-2018-1000822

    Last Modified: 21 Nov 2024

    codelibs fess version before commit faa265b contains a XML External Entity (XXE) vulnerability in GSA XML file parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via specially crafted GSA XML files. This vulnerability appears to have been fixed in after commit faa265b.

    Published:20 Dec 2018
    8.8
    High

    CVE-2018-1000811

    Last Modified: 2 Jan 2019

    bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be exploitable via malicious user have to upload a crafted payload containing PHP code.

    Source:BouSalman
    Published:20 Dec 2018
    9.8
    Critical

    CVE-2018-1000802

    Last Modified: 21 Nov 2024

    Python Software Foundation Python (CPython) version 2.7 contains a CWE-77: Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in shutil module (make_archive function) that can result in Denial of service, Information gain via injection of arbitrary files on the system or entire drive. This attack appear to be exploitable via Passage of unfiltered user input to the function. This vulnerability appears to have been fixed in after commit add531a1e55b0a739b0f42582f1c9747e5649ace.

    Published:29 Aug 2018
    6.1
    Medium

    CVE-2018-1000638

    Last Modified: 13 Apr 2025

    MiniCMS version 1.1 contains a Cross Site Scripting (XSS) vulnerability in http://example.org/mc-admin/page.php?date={payload} that can result in code injection.

    Source:CodeSecLab
    Published:20 Aug 2018
    7.8
    High

    CVE-2018-1000542

    Last Modified: 21 Nov 2024

    netbeans-mmd-plugin version <= 1.4.3 contains a XML External Entity (XXE) vulnerability in MMD file import that can result in Possible information disclosure, server-side request forgery, or remote code execution. This attack appear to be exploitable via Specially crafted MMD file.

    Published:26 Jun 2018
    9.8
    Critical

    CVE-2018-1000533

    Last Modified: 21 Nov 2024

    klaussilveira GitList version <= 0.6 contains a Passing incorrectly sanitized input to system function vulnerability in `searchTree` function that can result in Execute any code as PHP user. This attack appear to be exploitable via Send POST request using search form. This vulnerability appears to have been fixed in 0.7 after commit 87b8c26b023c3fc37f0796b14bb13710f397b322.

    Published:26 Jun 2018
    7.5
    High

    CVE-2018-1000531

    Last Modified: 21 Nov 2024

    inversoft prime-jwt version prior to commit abb0d479389a2509f939452a6767dc424bb5e6ba contains a CWE-20 vulnerability in JWTDecoder.decode that can result in an incorrect signature validation of a JWT token. This attack can be exploitable when an attacker crafts a JWT token with a valid header using 'none' as algorithm and a body to requests it be validated. This vulnerability was fixed after commit abb0d479389a2509f939452a6767dc424bb5e6ba.

    Published:26 Jun 2018
    6.1
    Medium

    CVE-2018-1000529

    Last Modified: 21 Nov 2024

    Grails Fields plugin version 2.2.7 contains a Cross Site Scripting (XSS) vulnerability in Using the display tag that can result in XSS . This vulnerability appears to have been fixed in 2.2.8.

    Published:26 Jun 2018
    7.5
    High

    CVE-2018-1000224

    Last Modified: 21 Nov 2024

    Godot Engine version All versions prior to 2.1.5, all 3.0 versions prior to 3.0.6. contains a Signed/unsigned comparison, wrong buffer size chackes, integer overflow, missing padding initialization vulnerability in (De)Serialization functions (core/io/marshalls.cpp) that can result in DoS (packet of death), possible leak of uninitialized memory. This attack appear to be exploitable via A malformed packet is received over the network by a Godot application that uses built-in serialization (e.g. game server, or game client). Could be triggered by multiplayer opponent. This vulnerability appears to have been fixed in 2.1.5, 3.0.6, master branch after commit feaf03421dda0213382b51aff07bd5a96b29487b.

    Published:20 Aug 2018
    5.5
    Medium

    CVE-2018-1000199

    Last Modified: 21 Nov 2024

    The Linux Kernel version 3.18 contains a dangerous feature vulnerability in modify_user_hw_breakpoint() that can result in crash and possibly memory corruption. This attack appear to be exploitable via local code execution and the ability to use ptrace. This vulnerability appears to have been fixed in git commit f67b15037a7a50c57f72e69a6d59941ad90a0f0f.

    Published:1 May 2018
    9.8
    Critical

    CVE-2018-1000140

    Last Modified: 21 Nov 2024

    rsyslog librelp version 1.2.14 and earlier contains a Buffer Overflow vulnerability in the checking of x509 certificates from a peer that can result in Remote code execution. This attack appear to be exploitable a remote attacker that can connect to rsyslog and trigger a stack buffer overflow by sending a specially crafted x509 certificate.

    Published:23 Mar 2018
    9.8
    Critical

    CVE-2018-1000134

    Last Modified: 21 Nov 2024

    UnboundID LDAP SDK version from commit 801111d8b5c732266a5dbd4b3bb0b6c7b94d7afb up to commit 8471904a02438c03965d21367890276bc25fa5a6, where the issue was reported and fixed contains an Incorrect Access Control vulnerability in process function in SimpleBindRequest class doesn't check for empty password when running in synchronous mode. commit with applied fix https://github.com/pingidentity/ldapsdk/commit/8471904a02438c03965d21367890276bc25fa5a6#diff-f6cb23b459be1ec17df1da33760087fd that can result in Ability to impersonate any valid user. This attack appear to be exploitable via Providing valid username and empty password against servers that do not do additional validation as per https://tools.ietf.org/html/rfc4513#section-5.1.1. This vulnerability appears to have been fixed in after commit 8471904a02438c03965d21367890276bc25fa5a6.

    Published:16 Mar 2018
    6.1
    Medium

    CVE-2018-1000129

    Last Modified: 21 Nov 2024

    An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.

    Published:8 Feb 2018
    9.8
    Critical

    CVE-2018-1000125

    Last Modified: 21 Nov 2024

    inversoft prime-jwt version prior to version 1.3.0 or prior to commit 0d94dcef0133d699f21d217e922564adbb83a227 contains an input validation vulnerability in JWTDecoder.decode that can result in a JWT that is decoded and thus implicitly validated even if it lacks a valid signature. This attack appear to be exploitable via an attacker crafting a token with a valid header and body and then requests it to be validated. This vulnerability appears to have been fixed in 1.3.0 and later or after commit 0d94dcef0133d699f21d217e922564adbb83a227.

    Published:13 Mar 2018
    6.7
    Medium

    CVE-2018-1000117

    Last Modified: 21 Nov 2024

    Python Software Foundation CPython version From 3.2 until 3.6.4 on Windows contains a Buffer Overflow vulnerability in os.symlink() function on Windows that can result in Arbitrary code execution, likely escalation of privilege. This attack appears to be exploitable via a python script that creates a symlink with an attacker controlled name or location. This vulnerability appears to have been fixed in 3.7.0 and 3.6.5.

    Published:7 Mar 2018
    7.5
    High

    CVE-2018-1000115

    Last Modified: 9 Mar 2018

    Memcached version 1.5.5 contains an Insufficient Control of Network Message Volume (Network Amplification, CWE-406) vulnerability in the UDP support of the memcached server that can result in denial of service via network flood (traffic amplification of 1:50,000 has been reported by reliable sources). This attack appear to be exploitable via network connectivity to port 11211 UDP. This vulnerability appears to have been fixed in 1.5.6 due to the disabling of the UDP protocol by default.

    Source:649
    Published:2 Mar 2018
    7.2
    High

    CVE-2018-1000094

    Last Modified: 11 Sept 2018

    CMS Made Simple version 2.2.5 contains a Remote Code Execution vulnerability in File Manager that can result in Allows an authenticated admin that has access to the file manager to execute code on the server. This attack appear to be exploitable via File upload -> copy to any extension.

    Source:Mustafa Hasan
    Published:13 Mar 2018
    8.8
    High

    CVE-2018-1000082

    Last Modified: 21 Nov 2024

    Ajenti version version 2 contains a Cross ite Request Forgery (CSRF) vulnerability in the command execution panel of the tool used to manage the server. that can result in Code execution on the server . This attack appear to be exploitable via Being a CSRF, victim interaction is needed, when the victim access the infected trigger of the CSRF any code that match the victim privledges on the server can be executed..

    Published:13 Mar 2018
    7.5
    High

    CVE-2018-1000049

    Last Modified: 18 Jul 2018

    Nanopool Claymore Dual Miner version 7.3 and earlier contains a remote code execution vulnerability by abusing the miner API. The flaw can be exploited only if the software is executed with read/write mode enabled.

    Source:Metasploit
    Published:9 Feb 2018
    3.6
    Low

    CVE-2018-1000030

    Last Modified: 21 Nov 2024

    Python 2.7.14 is vulnerable to a Heap-Buffer-Overflow as well as a Heap-Use-After-Free. Python versions prior to 2.7.14 may also be vulnerable and it appears that Python 2.7.17 and prior may also be vulnerable however this has not been confirmed. The vulnerability lies when multiply threads are handling large amounts of data. In both cases there is essentially a race condition that occurs. For the Heap-Buffer-Overflow, Thread 2 is creating the size for a buffer, but Thread1 is already writing to the buffer without knowing how much to write. So when a large amount of data is being processed, it is very easy to cause memory corruption using a Heap-Buffer-Overflow. As for the Use-After-Free, Thread3->Malloc->Thread1->Free's->Thread2-Re-uses-Free'd Memory. The PSRT has stated that this is not a security vulnerability due to the fact that the attacker must be able to run code, however in some situations, such as function as a service, this vulnerability can potentially be used by an attacker to violate a trust boundary, as such the DWF feels this issue deserves a CVE.

    Published:20 Sept 2017
    8.8
    High

    CVE-2018-1000006

    Last Modified: 26 Jan 2018

    GitHub Electron versions 1.8.2-beta.3 and earlier, 1.7.10 and earlier, 1.6.15 and earlier has a vulnerability in the protocol handler, specifically Electron apps running on Windows 10, 7 or 2008 that register custom protocol handlers can be tricked in arbitrary command execution if the user clicks on a specially crafted URL. This has been fixed in versions 1.8.2-beta.4, 1.7.11, and 1.6.16.

    Source:Wflki
    Published:24 Jan 2018
    7.8
    High

    CVE-2018-1000001

    Last Modified: 13 Jun 2018

    In glibc 2.26 and earlier there is confusion in the usage of getcwd() by realpath() which can be used to write before the destination buffer leading to a buffer underflow and potential code execution.

    Source:Metasploit
    Published:11 Jan 2018
    3.5
    Low

    CVE-2018-25080

    Last Modified: 3 Dec 2025

    A vulnerability, which was classified as problematic, has been found in MobileDetect 2.8.31. This issue affects the function initLayoutType of the file examples/session_example.php of the component Example. The manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.8.32 is able to address this issue. The identifier of the patch is 31818a441b095bdc4838602dbb17b8377d1e5cce. It is recommended to upgrade the affected component. The identifier VDB-220061 was assigned to this vulnerability.

    Source:CodeSecLab
    Published:4 Feb 2023
    4.6
    Medium

    CVE-2018-25075

    Last Modified: 25 Nov 2024

    A vulnerability classified as critical has been found in karsany OBridge up to 1.3. Affected is the function getAllStandaloneProcedureAndFunction of the file obridge-main/src/main/java/org/obridge/dao/ProcedureDao.java. The manipulation leads to sql injection. The complexity of an attack is rather high. The exploitability is told to be difficult. Upgrading to version 1.4 is able to address this issue. The name of the patch is 52eca4ad05f3c292aed3178b2f58977686ffa376. It is recommended to upgrade the affected component. The identifier of this vulnerability is VDB-218376.

    Published:15 Jan 2023
    7.5
    High

    CVE-2018-25032

    Last Modified: 21 Aug 2025

    zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.

    Published:20 Apr 2018
    4.3
    Medium

    CVE-2018-25031

    Last Modified: 21 Nov 2024

    Swagger UI 4.1.2 and earlier could allow a remote attacker to conduct spoofing attacks. By persuading a victim to open a crafted URL, an attacker could exploit this vulnerability to display remote OpenAPI definitions. Note: This was originally claimed to be resolved in 4.1.3. However, third parties have indicated this is not resolved in 4.1.3 and even occurs in that version and possibly others.

    Published:11 Mar 2022
    10
    Critical

    CVE-2018-21268

    Last Modified: 21 Nov 2024

    The traceroute (aka node-traceroute) package through 1.0.0 for Node.js allows remote command injection via the host parameter. This occurs because the Child.exec() method, which is considered to be not entirely safe, is used. In particular, an OS command can be placed after a newline character.

    Published:25 Jun 2020
    6.1
    Medium

    CVE-2018-20966

    Last Modified: 21 Nov 2024

    The woocommerce-jetpack plugin before 3.8.0 for WordPress has XSS in the Products Per Page feature.

    Published:12 Aug 2019
    7.5
    High

    CVE-2018-20782

    Last Modified: 18 Feb 2019

    The GloBee plugin before 1.1.2 for WooCommerce mishandles IPN messages.

    Source:GeekHack
    Published:17 Feb 2019
    7.8
    High

    CVE-2018-20735

    Last Modified: 18 Mar 2019

    An issue was discovered in BMC PATROL Agent through 11.3.01. It was found that the PatrolCli application can allow for lateral movement and escalation of privilege inside a Windows Active Directory environment. It was found that by default the PatrolCli / PATROL Agent application only verifies if the password provided for the given username is correct; it does not verify the permissions of the user on the network. This means if you have PATROL Agent installed on a high value target (domain controller), you can use a low privileged domain user to authenticate with PatrolCli and then connect to the domain controller and run commands as SYSTEM. This means any user on a domain can escalate to domain admin through PATROL Agent. NOTE: the vendor disputes this because they believe it is adequate to prevent this escalation by means of a custom, non-default configuration

    Source:Metasploit
    Published:17 Jan 2019
    9.8
    Critical

    CVE-2018-20718

    Last Modified: 21 Nov 2024

    In Pydio before 8.2.2, an attack is possible via PHP Object Injection because a user is allowed to use the $phpserial$a:0:{} syntax to store a preference. An attacker either needs a "public link" of a file, or access to any unprivileged user account for creation of such a link.

    Published:15 Jan 2019