6.1
    Medium

    CVE-2018-19041

    Last Modified: 13 Nov 2018

    The Media File Manager plugin 1.4.2 for WordPress allows XSS via the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

    Source:Pasquale Turi
    Published:31 Jan 2019
    5.3
    Medium

    CVE-2018-19040

    Last Modified: 13 Nov 2018

    The Media File Manager plugin 1.4.2 for WordPress allows directory listing via a ../ directory traversal in the dir parameter of an mrelocator_getdir action to the wp-admin/admin-ajax.php URI.

    Source:Pasquale Turi
    Published:31 Jan 2019
    8.8
    High

    CVE-2018-18982

    Last Modified: 16 Mar 2019

    NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execution.

    Source:Metasploit
    Published:27 Nov 2018
    9.8
    Critical

    CVE-2018-18957

    Last Modified: 7 Nov 2018

    An issue has been found in libIEC61850 v1.3. It is a stack-based buffer overflow in prepareGooseBuffer in goose/goose_publisher.c.

    Source:Dhiraj Mishra
    Published:5 Nov 2018
    7
    High

    CVE-2018-18955

    Last Modified: 16 Nov 2018

    In the Linux kernel 4.15.x through 4.19.x before 4.19.2, map_write() in kernel/user_namespace.c allows privilege escalation because it mishandles nested user namespaces with more than 5 UID or GID ranges. A user who has CAP_SYS_ADMIN in an affected user namespace can bypass access controls on resources outside the namespace, as demonstrated by reading /etc/shadow. This occurs because an ID transformation takes place properly for the namespaced-to-kernel direction but not for the kernel-to-namespaced direction.

    Source:Google Security Research
    Published:15 Nov 2018
    9.8
    Critical

    CVE-2018-18925

    Last Modified: 21 Nov 2024

    Gogs 0.11.66 allows remote code execution because it does not properly validate session IDs, as demonstrated by a ".." session-file forgery in the file session provider in file.go. This is related to session ID handling in the go-macaron/session code for Macaron.

    Published:4 Nov 2018
    8.8
    High

    CVE-2018-18924

    Last Modified: 6 Nov 2018

    The image-upload feature in ProjeQtOr 7.2.5 allows remote attackers to execute arbitrary code by uploading a .shtml file with "#exec cmd" because rejected files remain on the server, with predictable filenames, after a "This file is not a valid image" error message.

    Source:AkkuS
    Published:4 Nov 2018
    9.8
    Critical

    CVE-2018-18923

    Last Modified: 26 Nov 2018

    AbiSoft Ticketly 1.0 is affected by multiple SQL Injection vulnerabilities through the parameters name, category_id and description in action/addproject.php; kind_id, priority_id, project_id, status_id and title in action/addticket.php; and kind_id and status_id in reports.php.

    Source:Javier Olmedo
    Published:13 Dec 2018
    9.8
    Critical

    CVE-2018-18912

    Last Modified: 21 Nov 2024

    An issue was discovered in Easy File Sharing (EFS) Web Server 7.2. A stack-based buffer overflow vulnerability occurs when a malicious POST request has been made to forum.ghp upon creating a new topic in the forums, which allows remote attackers to execute arbitrary code.

    Published:13 May 2019
    5.3
    Medium

    CVE-2018-18893

    Last Modified: 21 Nov 2024

    Jinjava before 2.4.6 does not block the getClass method, related to com/hubspot/jinjava/el/ext/JinjavaBeanELResolver.java.

    Published:3 Jan 2019
    8.1
    High

    CVE-2018-18865

    Last Modified: 5 Nov 2018

    The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure.

    Source:Jakub Palaczynski
    Published:20 Nov 2018
    7.8
    High

    CVE-2018-18860

    Last Modified: 14 Nov 2018

    A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-permissive configuration settings and a SUID binary, an attacker is able to execute arbitrary binaries as root.

    Source:Bernd Leitner
    Published:30 Nov 2018
    7.8
    High

    CVE-2018-18859

    Last Modified: 5 Nov 2018

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the value of the "tun_path" or "tap_path" pathname in a kextload() call.

    Source:Bernd Leitner
    Published:20 Nov 2018
    7.8
    High

    CVE-2018-18858

    Last Modified: 5 Nov 2018

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "tun_path" or "tap_path" pathname within a shell command.

    Source:Bernd Leitner
    Published:20 Nov 2018
    7.8
    High

    CVE-2018-18857

    Last Modified: 5 Nov 2018

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "command_line" parameter as a shell command.

    Source:Bernd Leitner
    Published:20 Nov 2018
    7.8
    High

    CVE-2018-18856

    Last Modified: 5 Nov 2018

    Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execute arbitrary OS commands as root or load a potentially malicious kernel extension because com.smr.liquidvpn.OVPNHelper uses the system function to execute the "openvpncmd" parameter as a shell command.

    Source:Bernd Leitner
    Published:20 Nov 2018
    8.8
    High

    CVE-2018-18852

    Last Modified: 21 Nov 2024

    Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited in the wild in October 2018.

    Published:18 Jun 2019
    8.1
    High

    CVE-2018-18820

    Last Modified: 21 Nov 2024

    A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource including a crafted header, leading to denial of service and potentially remote code execution.

    Published:5 Nov 2018
    9.8
    Critical

    CVE-2018-18805

    Last Modified: 29 Oct 2018

    Point Of Sales 1.0 allows SQL injection via the login screen, related to LoginForm1.vb.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18804

    Last Modified: 29 Oct 2018

    Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18803

    Last Modified: 29 Oct 2018

    Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18801

    Last Modified: 29 Oct 2018

    The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18800

    Last Modified: 29 Oct 2018

    The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.

    Source:Ihsan Sencan
    Published:14 May 2019
    8.8
    High

    CVE-2018-18799

    Last Modified: 29 Oct 2018

    School Attendance Monitoring System 1.0 has CSRF via event/controller.php?action=photos.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18798

    Last Modified: 29 Oct 2018

    Attendance Monitoring System 1.0 has SQL Injection via the 'id' parameter to student/index.php?view=view, event/index.php?view=view, and user/index.php?view=view.

    Source:Ihsan Sencan
    Published:17 Mar 2019
    8.8
    High

    CVE-2018-18797

    Last Modified: 29 Oct 2018

    School Attendance Monitoring System 1.0 has CSRF via /user/user/edit.php.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18795

    Last Modified: 29 Oct 2018

    School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    8.8
    High

    CVE-2018-18794

    Last Modified: 29 Oct 2018

    School Event Management System 1.0 allows CSRF via user/controller.php?action=edit.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18793

    Last Modified: 29 Oct 2018

    School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    6.5
    Medium

    CVE-2018-18778

    Last Modified: 21 Nov 2024

    ACME mini_httpd before 1.30 lets remote users read arbitrary files.

    Published:29 Oct 2018
    4.3
    Medium

    CVE-2018-18777

    Last Modified: 30 Oct 2018

    Directory traversal vulnerability in Microstrategy Web, version 7, in "/WebMstr7/servlet/mstrWeb" (in the parameter subpage) allows remote authenticated users to bypass intended SecurityManager restrictions and list a parent directory via a /.. (slash dot dot) in a pathname used by a web application. NOTE: this is a deprecated product.

    Source:Rafael Pedrero
    Published:1 Nov 2018
    6.1
    Medium

    CVE-2018-18776

    Last Modified: 30 Oct 2018

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the admin/admin.asp ShowAll parameter. NOTE: this is a deprecated product.

    Source:Rafael Pedrero
    Published:1 Nov 2018
    6.1
    Medium

    CVE-2018-18775

    Last Modified: 30 Oct 2018

    Microstrategy Web, version 7, does not sufficiently encode user-controlled inputs, resulting in a Cross-Site Scripting (XSS) vulnerability via the Login.asp Msg parameter. NOTE: this is a deprecated product.

    Source:Rafael Pedrero
    Published:1 Nov 2018
    6.1
    Medium

    CVE-2018-18774

    Last Modified: 13 Nov 2018

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows XSS via the admin/index.php module parameter.

    Source:InfinitumIT
    Published:20 Nov 2018
    8.8
    High

    CVE-2018-18773

    Last Modified: 13 Nov 2018

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=rootpwd, as demonstrated by changing the root password.

    Source:InfinitumIT
    Published:20 Nov 2018
    8.8
    High

    CVE-2018-18772

    Last Modified: 13 Nov 2018

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel through 0.9.8.740 allows CSRF via admin/index.php?module=send_ssh, as demonstrated by executing an arbitrary OS command.

    Source:InfinitumIT
    Published:20 Nov 2018
    9.8
    Critical

    CVE-2018-18763

    Last Modified: 29 Oct 2018

    SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    6.5
    Medium

    CVE-2018-18762

    Last Modified: 29 Oct 2018

    SaltOS 3.1 r8126 contains a database download vulnerability.

    Source:Ihsan Sencan
    Published:17 Mar 2019
    9.8
    Critical

    CVE-2018-18761

    Last Modified: 29 Oct 2018

    SaltOS 3.1 r8126 allows action=login&querystring=&user=[SQL] SQL Injection.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    6.5
    Medium

    CVE-2018-18760

    Last Modified: 29 Oct 2018

    RhinOS 3.0 build 1190 allows CSRF.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    7.5
    High

    CVE-2018-18759

    Last Modified: 29 Oct 2018

    Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    9.8
    Critical

    CVE-2018-18755

    Last Modified: 29 Oct 2018

    K-iwi Framework 1775 has SQL Injection via the admin/user/group/update user_group_id parameter or the admin/user/user/update user_id parameter.

    Source:Ihsan Sencan
    Published:16 Nov 2018
    7.8
    High

    CVE-2018-18714

    Last Modified: 21 Nov 2024

    RegFilter.sys in IOBit Malware Fighter 6.2 and earlier is susceptible to a stack-based buffer overflow when an attacker uses IOCTL 0x8006E010. This can lead to denial of service (DoS) or code execution with root privileges.

    Published:1 Nov 2018
    9.8
    Critical

    CVE-2018-18649

    Last Modified: 21 Nov 2024

    An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.

    Published:29 Nov 2018
    7.8
    High

    CVE-2018-18629

    Last Modified: 24 Dec 2018

    An issue was discovered in the Keybase command-line client before 2.8.0-20181023124437 for Linux. An untrusted search path vulnerability in the keybase-redirector application allows a local, unprivileged user on Linux to gain root privileges via a Trojan horse binary.

    Source:mirchr
    Published:20 Dec 2018
    9.8
    Critical

    CVE-2018-18619

    Last Modified: 14 Nov 2018

    internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an SQL query, allowing remote attackers to execute the sqli attack via a URL in the "page" parameter. NOTE: The product is discontinued.

    Source:Rafael Pedrero
    Published:29 Nov 2018
    8.8
    High

    CVE-2018-18557

    Last Modified: 25 Oct 2018

    LibTIFF 3.9.3, 3.9.4, 3.9.5, 3.9.6, 3.9.7, 4.0.0alpha4, 4.0.0alpha5, 4.0.0alpha6, 4.0.0beta7, 4.0.0, 4.0.1, 4.0.2, 4.0.3, 4.0.4, 4.0.4beta, 4.0.5, 4.0.6, 4.0.7, 4.0.8 and 4.0.9 (with JBIG enabled) decodes arbitrarily-sized JBIG into a buffer, ignoring the buffer size, which leads to a tif_jbig.c JBIGDecode out-of-bounds write.

    Source:Google Security Research
    Published:14 Oct 2018
    6.1
    Medium

    CVE-2018-18548

    Last Modified: 25 Oct 2018

    ajenticp (aka Ajenti Docker control panel) for Ajenti through v1.2.23.13 has XSS via a filename that is mishandled in File Manager.

    Source:Numan OZDEMIR
    Published:24 Oct 2018
    9.8
    Critical

    CVE-2018-18500

    Last Modified: 21 Nov 2024

    A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a potentially exploitable crash. This vulnerability affects Thunderbird < 60.5, Firefox ESR < 60.5, and Firefox < 65.

    Published:29 Jan 2019
    7.5
    High

    CVE-2018-18441

    Last Modified: 21 Nov 2024

    D-Link DCS series Wi-Fi cameras expose sensitive information regarding the device configuration. The affected devices include many of DCS series, such as: DCS-936L, DCS-942L, DCS-8000LH, DCS-942LB1, DCS-5222L, DCS-825L, DCS-2630L, DCS-820L, DCS-855L, DCS-2121, DCS-5222LB1, DCS-5020L, and many more. There are many affected firmware versions starting from 1.00 and above. The configuration file can be accessed remotely through: <Camera-IP>/common/info.cgi, with no authentication. The configuration file include the following fields: model, product, brand, version, build, hw_version, nipca version, device name, location, MAC address, IP address, gateway IP address, wireless status, input/output settings, speaker, and sensor settings.

    Published:20 Dec 2018