7.5
    High

    CVE-2018-20658

    Last Modified: 7 Jan 2019

    The server in Core FTP 2.0 build 653 on 32-bit platforms allows remote attackers to cause a denial of service (daemon crash) via a crafted XRMD command.

    Source:Erik David Martin
    Published:2 Jan 2019
    8.8
    High

    CVE-2018-20580

    Last Modified: 6 May 2019

    The WSDL import functionality in SmartBear ReadyAPI 2.5.0 and 2.6.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL file.

    Source:Gilson Camelo
    Published:3 May 2019
    8.8
    High

    CVE-2018-20556

    Last Modified: 16 Mar 2019

    SQL injection vulnerability in Booking Calendar plugin 8.4.3 for WordPress allows remote attackers to execute arbitrary SQL commands via the booking_id parameter.

    Source:B0UG
    Published:18 Mar 2019
    9.8
    Critical

    CVE-2018-20555

    Last Modified: 21 Nov 2024

    The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover.

    Published:18 Mar 2019
    9.8
    Critical

    CVE-2018-20526

    Last Modified: 7 Jan 2019

    Roxy Fileman 1.4.5 allows unrestricted file upload in upload.php.

    Source:Pongtorn Angsuchotmetee_ Vittawat Masaree
    Published:18 Mar 2019
    9.1
    Critical

    CVE-2018-20525

    Last Modified: 7 Jan 2019

    Roxy Fileman 1.4.5 allows Directory Traversal in copydir.php, copyfile.php, and fileslist.php.

    Source:Pongtorn Angsuchotmetee_ Vittawat Masaree
    Published:18 Mar 2019
    5.3
    Medium

    CVE-2018-20523

    Last Modified: 10 Aug 2021

    Xiaomi Stock Browser 10.2.4.g on Xiaomi Redmi Note 5 Pro devices and other Redmi Android phones allows content provider injection. In other words, a third-party application can read the user's cleartext browser history via an app.provider.query content://com.android.browser.searchhistory/searchhistory request.

    Source:Vishwaraj Bhattrai
    Published:7 Jun 2019
    6.1
    Medium

    CVE-2018-20503

    Last Modified: 24 Jan 2019

    Allied Telesis 8100L/8 devices allow XSS via the edit-ipv4_interface.php vlanid or subnet_mask parameter.

    Source:AkkuS
    Published:7 May 2019
    6.1
    Medium

    CVE-2018-20485

    Last Modified: 13 May 2019

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the employee search feature.

    Source:Ibrahim Raafat
    Published:26 Dec 2018
    6.1
    Medium

    CVE-2018-20484

    Last Modified: 13 May 2019

    Zoho ManageEngine ADSelfService Plus 5.7 before build 5702 has XSS in the self-update layout implementation.

    Source:Ibrahim Raafat
    Published:26 Dec 2018
    5.4
    Medium

    CVE-2018-20472

    Last Modified: 12 Jul 2019

    An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. The logs web interface is vulnerable to stored XSS.

    Source:Goutham Madhwaraj
    Published:17 Jun 2019
    7.5
    High

    CVE-2018-20470

    Last Modified: 18 Jun 2019

    An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A directory traversal (arbitrary file access) vulnerability exists in the web reports module. This allows an outside attacker to view contents of sensitive files.

    Source:Goutham Madhwaraj
    Published:17 Jun 2019
    9.8
    Critical

    CVE-2018-20469

    Last Modified: 12 Jul 2019

    An issue was discovered in Tyto Sahi Pro through 7.x.x and 8.0.0. A parameter in the web reports module is vulnerable to h2 SQL injection. This can be exploited to inject SQL queries and run standard h2 system functions.

    Source:Goutham Madhwaraj
    Published:17 Jun 2019
    7.5
    High

    CVE-2018-20463

    Last Modified: 21 Nov 2024

    An issue was discovered in the JSmol2WP plugin 1.07 for WordPress. There is an arbitrary file read vulnerability via ../ directory traversal in query=php://filter/resource= in the jsmol.php query string. This can also be used for SSRF.

    Published:25 Dec 2018
    5.4
    Medium

    CVE-2018-20448

    Last Modified: 2 Jan 2019

    Frog CMS 0.9.5 has XSS via the Database name field to the /install/index.php URI.

    Source:WangDudu
    Published:25 Dec 2018
    9.8
    Critical

    CVE-2018-20434

    Last Modified: 5 Jun 2019

    LibreNMS 1.46 allows remote attackers to execute arbitrary OS commands by using the $_POST['community'] parameter to html/pages/addhost.inc.php during creation of a new device, and then making a /ajax_output.php?id=capture&format=text&type=snmpwalk&hostname=localhost request that triggers html/includes/output/capture.inc.php command mishandling.

    Source:Metasploit
    Published:24 Apr 2019
    9.8
    Critical

    CVE-2018-20433

    Last Modified: 21 Nov 2024

    c3p0 0.9.5.2 allows XXE in extractXmlConfigFromInputStream in com/mchange/v2/c3p0/cfg/C3P0ConfigXmlUtils.java during initialization.

    Published:20 Dec 2018
    4.8
    Medium

    CVE-2018-20418

    Last Modified: 2 Jan 2019

    index.php?p=admin/actions/entries/save-entry in Craft CMS 3.0.25 allows XSS by saving a new title from the console tab.

    Source:Raif Berkay Dincel
    Published:24 Dec 2018
    9.8
    Critical

    CVE-2018-20377

    Last Modified: 21 Nov 2024

    Orange Livebox 00.96.320S devices allow remote attackers to discover Wi-Fi credentials via /get_getnetworkconf.cgi on port 8080, leading to full control if the admin password equals the Wi-Fi password or has the default admin value. This is related to Firmware 01.11.2017-11:43:44, Boot v0.70.03, Modem 5.4.1.10.1.1A, Hardware 02, and Arcadyan ARV7519RW22-A-L T VR9 1.2.

    Published:23 Dec 2018
    7.8
    High

    CVE-2018-20343

    Last Modified: 21 Nov 2024

    Multiple buffer overflow vulnerabilities have been found in Ken Silverman Build Engine 1. An attacker could craft a special map file to execute arbitrary code when the map file is loaded.

    Published:2 Mar 2020
    6.1
    Medium

    CVE-2018-20326

    Last Modified: 7 Jan 2019

    ChinaMobile PLC Wireless Router GPN2.4P21-C-CN devices with firmware W2001EN-00 have XSS via the cgi-bin/webproc?getpage=html/index.html var:subpage parameter.

    Source:Kumar Saurav
    Published:2 Jan 2019
    9.8
    Critical

    CVE-2018-20318

    Last Modified: 21 Nov 2024

    An issue was discovered in weixin-java-tools v3.2.0. There is an XXE vulnerability in the getXmlDoc method of the BaseWxPayResult.java file.

    Published:21 Dec 2018
    7.8
    High

    CVE-2018-20250

    Last Modified: 25 Apr 2019

    In WinRAR versions prior to and including 5.61, There is path traversal vulnerability when crafting the filename field of the ACE format (in UNACEV2.dll). When the filename field is manipulated with specific patterns, the destination (extraction) folder is ignored, thus treating the filename as an absolute path.

    Source:Metasploit
    Published:5 Feb 2019
    7.5
    High

    CVE-2018-20227

    Last Modified: 21 Nov 2024

    RDF4J 2.4.2 allows Directory Traversal via ../ in an entry in a ZIP archive.

    Published:19 Dec 2018
    7.8
    High

    CVE-2018-20225

    Last Modified: 15 Apr 2026

    An issue was discovered in pip (all versions) because it installs the version with the highest version number, even if the user had intended to obtain a private package from a private index. This only affects use of the --extra-index-url option, and exploitation requires that the package does not already exist in the public index (and thus the attacker can put the package there with an arbitrary version number). NOTE: it has been reported that this is intended functionality and the user is responsible for using --extra-index-url securely

    Published:28 Apr 2020
    8.8
    High

    CVE-2018-20221

    Last Modified: 7 Jan 2019

    Secure/SAService.rem in Deltek Ajera Timesheets 9.10.16 and prior are vulnerable to remote code execution via deserialization of untrusted user input from an authenticated user. The executed code will run as the IIS Application Pool that is running the application.

    Source:Anthony Cole
    Published:17 Mar 2019
    7.5
    High

    CVE-2018-20220

    Last Modified: 22 Feb 2019

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. While the web interface requires authentication before it can be interacted with, a large portion of the HTTP endpoints are missing authentication. An attacker is able to view these pages before being authenticated, and some of these pages may disclose sensitive information.

    Source:Stephen Shkardoon
    Published:17 Mar 2019
    8.1
    High

    CVE-2018-20219

    Last Modified: 22 Feb 2019

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. After successful authentication, the device sends an authentication cookie to the end user such that they can access the devices web administration panel. This token is hard-coded to a string in the source code (/usr/share/www/check.lp file). By setting this cookie in a browser, an attacker is able to maintain access to every ENC-400 device without knowing the password, which results in authentication bypass. Even if a user changes the password on the device, this token is static and unchanged.

    Source:Stephen Shkardoon
    Published:17 Mar 2019
    9.8
    Critical

    CVE-2018-20218

    Last Modified: 22 Feb 2019

    An issue was discovered on Teracue ENC-400 devices with firmware 2.56 and below. The login form passes user input directly to a shell command without any kind of escaping or validation in /usr/share/www/check.lp file. An attacker is able to perform command injection using the "password" parameter in the login form.

    Source:Stephen Shkardoon
    Published:17 Mar 2019
    8.8
    High

    CVE-2018-20166

    Last Modified: 6 Mar 2019

    A file-upload vulnerability exists in Rukovoditel 2.3.1. index.php?module=configuration/save allows the user to upload a background image, and mishandles extension checking. It accepts uploads of PHP content if the first few characters match GIF data, and the filename ends in ".php" with mixed case, such as the .pHp extension.

    Source:AkkuS
    Published:2 Jan 2019
    6.1
    Medium

    CVE-2018-20165

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in OpenText Portal 7.4.4 allows remote attackers to inject arbitrary web script or HTML via the vgnextoid parameter to a menuitem URI.

    Published:22 Mar 2019
    9.9
    Critical

    CVE-2018-20162

    Last Modified: 21 Nov 2024

    Digi TransPort LR54 4.4.0.26 and possible earlier devices have Improper Input Validation that allows users with 'super' CLI access privileges to bypass a restricted shell and execute arbitrary commands as root.

    Published:17 Mar 2019
    7.2
    High

    CVE-2018-20159

    Last Modified: 6 Mar 2019

    i-doit open 1.11.2 allows Remote Code Execution because ZIP archives are mishandled. It has an upload feature that allows an authenticated user with the administrator role to upload arbitrary files to the main website directory. Exploitation involves uploading a ".php" file within a ".zip" file because a ZIP archive is accepted by /admin/?req=modules&action=add as a plugin, and extracted to the main directory. In order for the ".zip" file to be accepted, it must also contain a package.json file.

    Source:AkkuS
    Published:15 Dec 2018
    9.8
    Critical

    CVE-2018-20148

    Last Modified: 21 Nov 2024

    In WordPress before 4.9.9 and 5.x before 5.0.1, contributors could conduct PHP object injection attacks via crafted metadata in a wp.getMediaItem XMLRPC call. This is caused by mishandling of serialized data at phar:// URLs in the wp_get_attachment_thumb_file function in wp-includes/post.php.

    Published:14 Dec 2018
    9.8
    Critical

    CVE-2018-20062

    Last Modified: 16 Apr 2020

    An issue was discovered in NoneCms V1.3. thinkphp/library/think/App.php allows remote attackers to execute arbitrary PHP code via crafted use of the filter parameter, as demonstrated by the s=index/\think\Request/input&filter=phpinfo&data=1 query string.

    Source:Metasploit
    Published:11 Dec 2018
    4.8
    Medium

    CVE-2018-20011

    Last Modified: 14 Feb 2019

    DomainMOD 4.11.01 has XSS via the assets/add/category.php Category Name or Stakeholder field.

    Source:Mohammed Abdul Raheem
    Published:10 Dec 2018
    4.8
    Medium

    CVE-2018-20010

    Last Modified: 14 Feb 2019

    DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider-account.php username field.

    Source:Mohammed Abdul Raheem
    Published:10 Dec 2018
    4.8
    Medium

    CVE-2018-20009

    Last Modified: 14 Feb 2019

    DomainMOD 4.11.01 has XSS via the assets/add/ssl-provider.php SSL Provider Name or SSL Provider URL field.

    Source:Mohammed Abdul Raheem
    Published:10 Dec 2018
    9.8
    Critical

    CVE-2018-19987

    Last Modified: 21 Nov 2024

    D-Link DIR-822 Rev.B 202KRb06, DIR-822 Rev.C 3.10B06, DIR-860L Rev.B 2.03.B03, DIR-868L Rev.B 2.05B02, DIR-880L Rev.A 1.20B01_01_i3se_BETA, and DIR-890L Rev.A 1.21B02_BETA devices mishandle IsAccessPoint in /HNAP1/SetAccessPointMode. In the SetAccessPointMode.php source code, the IsAccessPoint parameter is saved in the ShellPath script file without any regex checking. After the script file is executed, the command injection occurs. A vulnerable /HNAP1/SetAccessPointMode XML message could have shell metacharacters in the IsAccessPoint element such as the `telnetd` string.

    Published:13 May 2019
    6.1
    Medium

    CVE-2018-19933

    Last Modified: 19 Dec 2018

    Bolt CMS <3.6.2 allows XSS via text input click preview button as demonstrated by the Title field of a Configured and New Entry.

    Source:Raif Berkay Dincel
    Published:17 Dec 2018
    4.8
    Medium

    CVE-2018-19915

    Last Modified: 14 Feb 2019

    DomainMOD through 4.11.01 has XSS via the assets/edit/host.php Web Host Name or Web Host URL field.

    Source:Mohammed Abdul Kareem
    Published:6 Dec 2018
    4.8
    Medium

    CVE-2018-19914

    Last Modified: 16 Feb 2019

    DomainMOD through 4.11.01 has XSS via the assets/add/dns.php Profile Name or notes field.

    Source:Mohammed Abdul Kareem
    Published:6 Dec 2018
    4.8
    Medium

    CVE-2018-19913

    Last Modified: 12 Dec 2018

    DomainMOD through 4.11.01 has XSS via the assets/add/registrar-accounts.php UserName, Reseller ID, or notes field.

    Source:Mohammed Abdul Raheem
    Published:6 Dec 2018
    7.5
    High

    CVE-2018-19911

    Last Modified: 21 Nov 2024

    FreeSWITCH through 1.8.2, when mod_xml_rpc is enabled, allows remote attackers to execute arbitrary commands via the api/system or txtapi/system (or api/bg_system or txtapi/bg_system) query string on TCP port 8080, as demonstrated by an api/system?calc URI. This can also be exploited via CSRF. Alternatively, the default password of works for the freeswitch account can sometimes be used.

    Published:6 Dec 2018
    8.8
    High

    CVE-2018-19908

    Last Modified: 18 Feb 2019

    An issue was discovered in MISP 2.4.9x before 2.4.99. In app/Model/Event.php (the STIX 1 import code), an unescaped filename string is used to construct a shell command. This vulnerability can be abused by a malicious authenticated user to execute arbitrary commands by tweaking the original filename of the STIX import.

    Source:Tm9jdGlz
    Published:6 Dec 2018
    6.1
    Medium

    CVE-2018-19877

    Last Modified: 10 Dec 2018

    login.php in Adiscon LogAnalyzer before 4.1.7 has XSS via the Login Button Referer field.

    Source:Gustavo Sorondo
    Published:5 Dec 2018
    9.8
    Critical

    CVE-2018-19864

    Last Modified: 4 Jun 2019

    NUUO NVRmini2 Network Video Recorder firmware through 3.9.1 allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow), resulting in ability to read camera feeds or reconfigure the device.

    Source:@0x00string
    Published:5 Dec 2018
    9.8
    Critical

    CVE-2018-19862

    Last Modified: 19 Dec 2018

    Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP POST request. NOTE: this product is discontinued.

    Source:Rafael Pedrero
    Published:3 Jan 2019
    9.8
    Critical

    CVE-2018-19861

    Last Modified: 19 Dec 2018

    Buffer overflow in MiniShare 1.4.1 and earlier allows remote attackers to execute arbitrary code via a long HTTP HEAD request. NOTE: this product is discontinued.

    Source:Rafael Pedrero
    Published:3 Jan 2019
    6.5
    Medium

    CVE-2018-19859

    Last Modified: 21 Nov 2024

    OpenRefine before 3.2 beta allows directory traversal via a relative pathname in a ZIP archive.

    Published:5 Dec 2018