6.5
    Medium

    CVE-2018-19829

    Last Modified: 19 Dec 2018

    Artica Integria IMS 5.0.83 has CSRF in godmode/usuarios/lista_usuarios, resulting in the ability to delete an arbitrary user when the ID number is known.

    Source:Javier Olmedo
    Published:18 Dec 2018
    6.1
    Medium

    CVE-2018-19828

    Last Modified: 19 Dec 2018

    Artica Integria IMS 5.0.83 has XSS via the search_string parameter.

    Source:Javier Olmedo
    Published:17 Dec 2018
    6.1
    Medium

    CVE-2018-19799

    Last Modified: 4 Dec 2018

    Dolibarr ERP/CRM through 8.0.3 has /exports/export.php?datatoexport= XSS.

    Source:AkkuS
    Published:26 Dec 2018
    8.8
    High

    CVE-2018-19788

    Last Modified: 21 Nov 2024

    A flaw was found in PolicyKit (aka polkit) 0.115 that allows a user with a uid greater than INT_MAX to successfully execute any systemctl command.

    Published:3 Dec 2018
    6.1
    Medium

    CVE-2018-19782

    Last Modified: 4 Dec 2018

    Multiple cross-site scripting (XSS) vulnerabilities in GET requests in FreshRSS 1.11.1 allow remote attackers to inject arbitrary web script or HTML via the (1) c parameter or (2) a parameter.

    Source:Netsparker
    Published:29 Jan 2019
    4.8
    Medium

    CVE-2018-19752

    Last Modified: 4 Dec 2018

    DomainMOD through 4.11.01 has XSS via the assets/add/registrar.php notes field for the Registrar.

    Source:Mohammed Abdul Raheem
    Published:29 Nov 2018
    4.8
    Medium

    CVE-2018-19751

    Last Modified: 4 Dec 2018

    DomainMOD through 4.11.01 has XSS via the admin/ssl-fields/add.php notes field for Custom SSL Fields.

    Source:Mohammed Abdul Raheem
    Published:29 Nov 2018
    5.4
    Medium

    CVE-2018-19750

    Last Modified: 4 Dec 2018

    DomainMOD through 4.11.01 has XSS via the admin/domain-fields/ notes field in an Add Custom Field action for Custom Domain Fields.

    Source:Mohammed Abdul Raheem
    Published:29 Nov 2018
    4.8
    Medium

    CVE-2018-19749

    Last Modified: 4 Dec 2018

    DomainMOD through 4.11.01 has XSS via the assets/add/account-owner.php Owner name field.

    Source:Mohammed Abdul Raheem
    Published:29 Nov 2018
    7.5
    High

    CVE-2018-19629

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability in the ImageNow Server service in Hyland Perceptive Content Server before 7.1.5 allows an attacker to crash the service via a TCP connection.

    Published:16 Jul 2019
    7.5
    High

    CVE-2018-19627

    Last Modified: 4 Dec 2018

    In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the IxVeriWave file parser could crash. This was addressed in wiretap/vwr.c by adjusting a buffer boundary.

    Source:Google Security Research
    Published:27 Nov 2018
    8.1
    High

    CVE-2018-19616

    Last Modified: 4 Dec 2018

    An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.

    Source:Luca.Chiou
    Published:26 Dec 2018
    7.8
    High

    CVE-2018-19592

    Last Modified: 21 Nov 2024

    The "CLink4Service" service is installed with Corsair Link 4.9.7.35 with insecure permissions by default. This allows unprivileged users to take control of the service and execute commands in the context of NT AUTHORITY\SYSTEM, leading to total system takeover, a similar issue to CVE-2018-12441.

    Published:27 Sept 2019
    7.5
    High

    CVE-2018-19585

    Last Modified: 25 Feb 2021

    GitLab CE/EE versions 8.18 up to 11.x before 11.3.11, 11.4.x before 11.4.8, and 11.5.x before 11.5.1 have CRLF Injection in Project Mirroring when using the Git protocol.

    Source:Norbert Hofmann
    Published:17 May 2019
    7.7
    High

    CVE-2018-19571

    Last Modified: 25 Feb 2021

    GitLab CE/EE, versions 8.18 up to 11.x before 11.3.11, 11.4 before 11.4.8, and 11.5 before 11.5.1, are vulnerable to an SSRF vulnerability in webhooks.

    Source:Norbert Hofmann
    Published:10 Jul 2019
    8.8
    High

    CVE-2018-19550

    Last Modified: 17 May 2019

    Interspire Email Marketer through 6.1.6 allows arbitrary file upload via a surveys_submit.php "create survey and submit survey" operation, which can cause a .php file to be accessible under a admin/temp/surveys/ URI.

    Source:numan türle
    Published:26 Nov 2018
    7.2
    High

    CVE-2018-19537

    Last Modified: 21 Nov 2024

    TP-Link Archer C5 devices through V2_160201_US allow remote command execution via shell metacharacters on the wan_dyn_hostname line of a configuration file that is encrypted with the 478DA50BF9E3D2CF key and uploaded through the web GUI by using the web admin account. The default password of admin may be used in some cases.

    Published:26 Nov 2018
    9.8
    Critical

    CVE-2018-19524

    Last Modified: 12 Feb 2019

    An issue was discovered on Shenzhen Skyworth DT741 Converged Intelligent Terminal (G/EPON+IPTV) SDOTBGN1, DT721-cb SDOTBGN1, and DT741-cb SDOTBGN1 devices. A long password to the Web_passwd function allows remote attackers to cause a denial of service (segmentation fault) or achieve unauthenticated remote code execution because of control of registers S0 through S4 and T4 through T7.

    Source:Kaustubh G. Padwad
    Published:17 Mar 2019
    7.5
    High

    CVE-2018-19518

    Last Modified: 29 Nov 2018

    University of Washington IMAP Toolkit 2007f on UNIX, as used in imap_open() in PHP and other products, launches an rsh command (by means of the imap_rimap function in c-client/imap4r1.c and the tcp_aopen function in osdep/unix/tcp_unix.c) without preventing argument injection, which might allow remote attackers to execute arbitrary OS commands if the IMAP server name is untrusted input (e.g., entered by a user of a web application) and if rsh has been replaced by a program with different argument semantics. For example, if rsh is a link to ssh (as seen on Debian and Ubuntu systems), then the attack can use an IMAP server name containing a "-oProxyCommand" argument.

    Source:Metasploit
    Published:19 Nov 2018
    7.5
    High

    CVE-2018-19487

    Last Modified: 21 Nov 2024

    The WP-jobhunt plugin before version 2.4 for WordPress does not control AJAX requests sent to the cs_employer_ajax_profile() function through the admin-ajax.php file, which allows remote unauthenticated attackers to enumerate information about users.

    Published:17 Mar 2019
    9.8
    Critical

    CVE-2018-19466

    Last Modified: 21 Nov 2024

    A vulnerability was found in Portainer before 1.20.0. Portainer stores LDAP credentials, corresponding to a master password, in cleartext and allows their retrieval via API calls.

    Published:27 Mar 2019
    7.8
    High

    CVE-2018-19459

    Last Modified: 26 Nov 2018

    Adult Filter 1.0 has a Buffer Overflow via a crafted Black Domain List file.

    Source:AkkuS
    Published:22 Nov 2018
    7.5
    High

    CVE-2018-19458

    Last Modified: 26 Nov 2018

    In PHP Proxy 3.0.3, any user can read files from the server without authentication due to an index.php?q=file:/// LFI URI, a different vulnerability than CVE-2018-19246.

    Source:AkkuS
    Published:22 Nov 2018
    7.2
    High

    CVE-2018-19423

    Last Modified: 26 May 2021

    Codiad 2.8.4 allows remote authenticated administrators to execute arbitrary code by uploading an executable file.

    Source:Ron Jost
    Published:21 Nov 2018
    7.2
    High

    CVE-2018-19422

    Last Modified: 29 Oct 2021

    /panel/uploads in Subrion CMS 4.2.1 allows remote attackers to execute arbitrary PHP code via a .pht or .phar file, because the .htaccess file omits these.

    Source:Fellipe Oliveira
    Published:21 Nov 2018
    9.8
    Critical

    CVE-2018-19410

    Last Modified: 7 Nov 2025

    PRTG Network Monitor before 18.2.40.1683 allows remote unauthenticated attackers to create users with read-write privileges (including administrator). A remote unauthenticated user can craft an HTTP request and override attributes of the 'include' directive in /public/login.htm and perform a Local File Inclusion attack, by including /api/addusers and executing it. By providing the 'id' and 'users' parameters, an unauthenticated attacker can create a user with read-write privileges (including administrator).

    Published:21 Nov 2018
    7
    High

    CVE-2018-19374

    Last Modified: 16 Apr 2019

    Zoho ManageEngine ADManager Plus 6.6 Build 6657 allows local users to gain privileges (after a reboot) by placing a Trojan horse file into the permissive bin directory.

    Source:Digital Interruption
    Published:30 Apr 2019
    6.5
    Medium

    CVE-2018-19371

    Last Modified: 18 Dec 2018

    The SaveUserSettings service in Content Manager in SDL Web 8.5.0 has an XXE Vulnerability that allows reading sensitive files from the system.

    Source:Ahmed Elhady Mohamed
    Published:2 Jan 2019
    9.8
    Critical

    CVE-2018-19362

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the jboss-common-core class from polymorphic deserialization.

    Published:18 Nov 2018
    9.8
    Critical

    CVE-2018-19361

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the openjpa class from polymorphic deserialization.

    Published:18 Nov 2018
    9.8
    Critical

    CVE-2018-19360

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.8 might allow attackers to have unspecified impact by leveraging failure to block the axis2-transport-jms class from polymorphic deserialization.

    Published:18 Nov 2018
    9.8
    Critical

    CVE-2018-19323

    Last Modified: 7 Nov 2025

    The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes functionality to read and write Machine Specific Registers (MSRs).

    Published:21 Dec 2018
    7.8
    High

    CVE-2018-19321

    Last Modified: 7 Nov 2025

    The GPCIDrv and GDrv low-level drivers in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

    Published:21 Dec 2018
    7.8
    High

    CVE-2018-19320

    Last Modified: 7 Nov 2025

    The GDrv low-level driver in GIGABYTE APP Center v1.05.21 and earlier, AORUS GRAPHICS ENGINE before 1.57, XTREME GAMING ENGINE before 1.26, and OC GURU II v2.08 exposes ring0 memcpy-like functionality that could allow a local attacker to take complete control of the affected system.

    Published:21 Dec 2018
    6.1
    Medium

    CVE-2018-19287

    Last Modified: 20 Nov 2018

    XSS in the Ninja Forms plugin before 3.3.18 for WordPress allows Remote Attackers to execute JavaScript via the includes/Admin/Menus/Submissions.php (aka submissions page) begin_date, end_date, or form_id parameter.

    Source:MTK
    Published:15 Nov 2018
    8.8
    High

    CVE-2018-19277

    Last Modified: 24 Dec 2018

    securityScan() in PHPOffice PhpSpreadsheet through 1.5.0 allows a bypass of protection mechanisms for XXE via UTF-7 encoding in a .xlsx file

    Source:Alex Leahu
    Published:14 Nov 2018
    9.8
    Critical

    CVE-2018-19276

    Last Modified: 5 Feb 2019

    OpenMRS before 2.24.0 is affected by an Insecure Object Deserialization vulnerability that allows an unauthenticated user to execute arbitrary commands on the targeted system via crafted XML data in a request body.

    Source:Bishop Fox
    Published:17 Mar 2019
    7.5
    High

    CVE-2018-19246

    Last Modified: 15 Nov 2018

    PHP-Proxy 5.1.0 allows remote attackers to read local files if the default "pre-installed version" (intended for users who lack shell access to their web server) is used. This occurs because the aeb067ca0aa9a3193dce3a7264c90187 app_key value from the default config.php is in place, and this value can be easily used to calculate the authorization data needed for local file inclusion.

    Source:Ameer Pornillos
    Published:13 Nov 2018
    9.8
    Critical

    CVE-2018-19207

    Last Modified: 21 Nov 2024

    The Van Ons WP GDPR Compliance (aka wp-gdpr-compliance) plugin before 1.4.3 for WordPress allows remote attackers to execute arbitrary code because $wpdb->prepare() input is mishandled, as exploited in the wild in November 2018.

    Published:12 Nov 2018
    8.8
    High

    CVE-2018-19138

    Last Modified: 2 Jan 2019

    WSTMart 2.0.7 has CSRF via the index.php/admin/staffs/add.html URI.

    Source:linfeng
    Published:9 Nov 2018
    6.1
    Medium

    CVE-2018-19136

    Last Modified: 11 Dec 2018

    DomainMOD through 4.11.01 has XSS via the assets/edit/registrar-account.php raid parameter.

    Source:Dawood Ansar
    Published:9 Nov 2018
    8.8
    High

    CVE-2018-19135

    Last Modified: 13 Nov 2018

    ClipperCMS 1.3.3 does not have CSRF protection on its kcfinder file upload (enabled by default). This can be used by an attacker to perform actions for an admin (or any user with the file upload capability). With this vulnerability, one can automatically upload files (by default, it allows html, pdf, xml, zip, and many other file types). A file can be accessed publicly under the "/assets/files" directory.

    Source:Ameer Pornillos
    Published:11 Nov 2018
    6.1
    Medium

    CVE-2018-19131

    Last Modified: 21 Nov 2024

    Squid before 4.4 has XSS via a crafted X.509 certificate during HTTP(S) error page generation for certificate errors.

    Published:31 Oct 2018
    9.8
    Critical

    CVE-2018-19127

    Last Modified: 21 Nov 2024

    A code injection vulnerability in /type.php in PHPCMS 2008 allows attackers to write arbitrary content to a website cache file with a controllable filename, leading to arbitrary code execution. The PHP code is sent via the template parameter, and is written to a data/cache_template/*.tpl.php file along with a "<?php function " substring.

    Published:9 Nov 2018
    9.8
    Critical

    CVE-2018-19126

    Last Modified: 12 Dec 2018

    PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.

    Source:Fariskhi Vidyan
    Published:9 Nov 2018
    7.5
    High

    CVE-2018-19125

    Last Modified: 12 Dec 2018

    PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to delete an image directory.

    Source:Fariskhi Vidyan
    Published:9 Nov 2018
    7.3
    High

    CVE-2018-19113

    Last Modified: 13 Jun 2019

    The Pronestor PNHM (aka Health Monitoring or HealthMonitor) add-in before 8.1.13.0 for Outlook has "BUILTIN\Users:(I)(F)" permissions for the "%PROGRAMFILES(X86)%\proNestor\Outlook add-in for Pronestor\PronestorHealthMonitor.exe" file, which allows local users to gain privileges via a Trojan horse PronestorHealthMonitor.exe file.

    Source:PovlTekstTV
    Published:1 Apr 2019
    7.5
    High

    CVE-2018-19052

    Last Modified: 21 Nov 2024

    An issue was discovered in mod_alias_physical_handler in mod_alias.c in lighttpd before 1.4.50. There is potential ../ path traversal of a single directory above an alias target, with a specific mod_alias configuration where the matched alias lacks a trailing '/' character, but the alias target filesystem path does have a trailing '/' character.

    Published:7 Nov 2018
    5.3
    Medium

    CVE-2018-19043

    Last Modified: 13 Nov 2018

    The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file renaming (specifying a "from" and "to" filename) via a ../ directory traversal in the dir parameter of an mrelocator_rename action to the wp-admin/admin-ajax.php URI.

    Source:Pasquale Turi
    Published:31 Jan 2019
    5.3
    Medium

    CVE-2018-19042

    Last Modified: 13 Nov 2018

    The Media File Manager plugin 1.4.2 for WordPress allows arbitrary file movement via a ../ directory traversal in the dir_from and dir_to parameters of an mrelocator_move action to the wp-admin/admin-ajax.php URI.

    Source:Pasquale Turi
    Published:31 Jan 2019