6.1
    Medium

    CVE-2018-18437

    Last Modified: 24 Oct 2018

    In AXIOS ITALIA Axioscloud Sissiweb Registro Elettronico 1.7.0, secret/relogoff.aspx has XSS via the Error_Desc parameter.

    Source:Dino Barlattani
    Published:23 Oct 2018
    7.8
    High

    CVE-2018-18435

    Last Modified: 7 Jan 2019

    KioWare Server version 4.9.6 and older installs by default to "C:\kioware_com" with weak folder permissions granting any user full permission "Everyone: (F)" to the contents of the directory and it's sub-folders. In addition, the program installs a service called "KWSService" which runs as "Localsystem", this will allow any user to escalate privileges to "NT AUTHORITY\SYSTEM" by substituting the service's binary with a malicious one.

    Source:Hashim Jawad
    Published:17 Mar 2019
    7.5
    High

    CVE-2018-18428

    Last Modified: 23 Oct 2018

    TP-Link TL-SC3130 1.6.18P12_121101 devices allow unauthenticated RTSP stream access, as demonstrated by a /jpg/image.jpg URI.

    Source:LiquidWorm
    Published:19 Oct 2018
    5.4
    Medium

    CVE-2018-18419

    Last Modified: 25 Oct 2018

    Stored XSS has been discovered in the upload section of ARDAWAN.COM User Management 1.1, as demonstrated by a .jpg filename to the /account URI.

    Source:Ismail Tasdelen
    Published:19 Oct 2018
    5.4
    Medium

    CVE-2018-18417

    Last Modified: 25 Oct 2018

    In the 3.1 version of Ekushey Project Manager CRM, Stored XSS has been discovered in the input and upload sections, as demonstrated by the name parameter to the index.php/admin/client/create URI.

    Source:Ismail Tasdelen
    Published:19 Oct 2018
    4.8
    Medium

    CVE-2018-18416

    Last Modified: 25 Oct 2018

    LANGO Codeigniter Multilingual Script 1.0 has XSS in the input and upload sections, as demonstrated by the site_name parameter to the admin/settings/update URI.

    Source:Ismail Tasdelen
    Published:19 Oct 2018
    8.8
    High

    CVE-2018-18387

    Last Modified: 21 Nov 2024

    playSMS through 1.4.2 allows Privilege Escalation through Daemon abuse.

    Published:29 Oct 2018
    7.8
    High

    CVE-2018-18368

    Last Modified: 21 Nov 2024

    Symantec Endpoint Protection Manager (SEPM), prior to 14.2 RU1, may be susceptible to a privilege escalation vulnerability, which is a type of issue whereby an attacker may attempt to compromise the software application to gain elevated access to resources that are normally protected from an application or user.

    Published:15 Nov 2019
    7.8
    High

    CVE-2018-18333

    Last Modified: 21 Nov 2024

    A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations.

    Published:5 Feb 2019
    7.5
    High

    CVE-2018-18326

    Last Modified: 16 Apr 2020

    DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-15812.

    Source:Metasploit
    Published:3 Jul 2019
    7.5
    High

    CVE-2018-18325

    Last Modified: 16 Apr 2020

    DNN (aka DotNetNuke) 9.2 through 9.2.2 uses a weak encryption algorithm to protect input parameters. NOTE: this issue exists because of an incomplete fix for CVE-2018-15811.

    Source:Metasploit
    Published:3 Jul 2019
    6.1
    Medium

    CVE-2018-18324

    Last Modified: 15 Oct 2018

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has XSS via the admin/fileManager2.php fm_current_dir parameter, or the admin/index.php module, service_start, service_fullstatus, service_restart, service_stop, or file (within the file_editor) parameter.

    Source:seccops
    Published:15 Oct 2018
    7.5
    High

    CVE-2018-18323

    Last Modified: 15 Oct 2018

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Local File Inclusion via directory traversal with an admin/index.php?module=file_editor&file=/../ URI.

    Source:seccops
    Published:15 Oct 2018
    9.8
    Critical

    CVE-2018-18322

    Last Modified: 15 Oct 2018

    CentOS-WebPanel.com (aka CWP) CentOS Web Panel 0.9.8.480 has Command Injection via shell metacharacters in the admin/index.php service_start, service_restart, service_fullstatus, or service_stop parameter.

    Source:seccops
    Published:15 Oct 2018
    6.1
    Medium

    CVE-2018-18308

    Last Modified: 18 Oct 2018

    In the 4.2.23 version of BigTree, a Stored XSS vulnerability has been discovered in /admin/ajax/file-browser/upload/ (aka the image upload area).

    Source:Ismail Tasdelen
    Published:16 Oct 2018
    7.5
    High

    CVE-2018-18074

    Last Modified: 21 Nov 2024

    The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to discover credentials by sniffing the network.

    Published:29 Jun 2018
    6.5
    Medium

    CVE-2018-18065

    Last Modified: 17 Mar 2019

    _set_key in agent/helpers/table_container.c in Net-SNMP before 5.8 has a NULL Pointer Exception bug that can be used by an authenticated attacker to remotely cause the instance to crash via a crafted UDP packet, resulting in Denial of Service.

    Source:Magnus Klaaborg Stubman
    Published:6 Oct 2016
    7.8
    High

    CVE-2018-18026

    Last Modified: 21 Nov 2024

    IMFCameraProtect.sys in IObit Malware Fighter 6.2 (and possibly lower versions) is vulnerable to a stack-based buffer overflow. The attacker can use DeviceIoControl to pass a user specified size which can be used to overwrite return addresses. This can lead to a denial of service or code execution attack.

    Published:19 Oct 2018
    6.1
    Medium

    CVE-2018-17997

    Last Modified: 7 Jan 2019

    LayerBB 1.1.1 allows XSS via the titles of conversations (PMs).

    Source:0xB9
    Published:17 Mar 2019
    6.5
    Medium

    CVE-2018-17996

    Last Modified: 14 Feb 2019

    LayerBB before 1.1.3 allows CSRF for adding a user via admin/new_user.php, deleting a user via admin/members.php/delete_user/, and deleting content via mod/delete.php/.

    Source:0xB9
    Published:17 Mar 2019
    7.8
    High

    CVE-2018-17980

    Last Modified: 15 Oct 2018

    NoMachine before 5.3.27 and 6.x before 6.3.6 allows attackers to gain privileges via a Trojan horse wintab32.dll file located in the same directory as a .nxs file, as demonstrated by a scenario where the .nxs file and the DLL are in the current working directory, and the Trojan horse code is executed. (The directory could, in general, be on a local filesystem or a network share.).

    Source:hyp3rlinx
    Published:15 Oct 2018
    8.6
    High

    CVE-2018-17961

    Last Modified: 9 Oct 2018

    Artifex Ghostscript 9.25 and earlier allows attackers to bypass a sandbox protection mechanism via vectors involving errorhandler setup. NOTE: this issue exists because of an incomplete fix for CVE-2018-17183.

    Source:Google Security Research
    Published:10 Oct 2018
    8.8
    High

    CVE-2018-17873

    Last Modified: 21 Nov 2024

    An incorrect access control vulnerability in the FTP configuration of WiFiRanger devices with firmware version 7.0.8rc3 and earlier allows an attacker with adjacent network access to read the SSH Private Key and log in to the root account.

    Published:23 Oct 2018
    6.1
    Medium

    CVE-2018-17832

    Last Modified: 3 Oct 2018

    XSS exists in WUZHI CMS 2.0 via the index.php v or f parameter.

    Source:Renzi
    Published:1 Oct 2018
    Low

    CVE-2018-17793

    Last Modified: 5 Oct 2018

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Source:vr_system
    Published:30 Sept 2018
    6.1
    Medium

    CVE-2018-17784

    Last Modified: 18 Oct 2018

    Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targeted system.

    Source:Purplemet Security
    Published:10 Oct 2018
    7.8
    High

    CVE-2018-17776

    Last Modified: 2 Oct 2018

    PCProtect Anti-Virus v4.8.35 has "Everyone: (F)" permission for %PROGRAMFILES(X86)%\PCProtect, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

    Source:Hashim Jawad
    Published:28 Sept 2018
    7.8
    High

    CVE-2018-17775

    Last Modified: 9 Oct 2018

    Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by replacing an executable file with a Trojan horse.

    Source:Hashim Jawad
    Published:8 Oct 2018
    6.1
    Medium

    CVE-2018-17593

    Last Modified: 3 Oct 2018

    AirTies Air 5453 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Source:Ismail Tasdelen
    Published:2 Oct 2018
    6.1
    Medium

    CVE-2018-17591

    Last Modified: 3 Oct 2018

    AirTies Air 5343v2 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Source:Ismail Tasdelen
    Published:2 Oct 2018
    6.1
    Medium

    CVE-2018-17590

    Last Modified: 3 Oct 2018

    AirTies Air 5442 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Source:Ismail Tasdelen
    Published:2 Oct 2018
    6.1
    Medium

    CVE-2018-17588

    Last Modified: 3 Oct 2018

    AirTies Air 5021 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Source:Ismail Tasdelen
    Published:2 Oct 2018
    6.1
    Medium

    CVE-2018-17587

    Last Modified: 3 Oct 2018

    AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.

    Source:Ismail Tasdelen
    Published:2 Oct 2018
    8.8
    High

    CVE-2018-17553

    Last Modified: 17 Mar 2019

    An "Unrestricted Upload of File with Dangerous Type" issue with directory traversal in navigate_upload.php in Naviwebs Navigate CMS 2.8 allows authenticated attackers to achieve remote code execution via a POST request with engine=picnik and id=../../../navigate_info.php.

    Source:Metasploit
    Published:3 Oct 2018
    9.8
    Critical

    CVE-2018-17552

    Last Modified: 17 Mar 2019

    SQL Injection in login.php in Naviwebs Navigate CMS 2.8 allows remote attackers to bypass authentication via the navigate-user cookie.

    Source:Metasploit
    Published:3 Oct 2018
    8.8
    High

    CVE-2018-17463

    Last Modified: 9 Mar 2020

    Incorrect side effect annotation in V8 in Google Chrome prior to 70.0.3538.64 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Source:Metasploit
    Published:16 Oct 2018
    9.8
    Critical

    CVE-2018-17456

    Last Modified: 17 Oct 2018

    Git before 2.14.5, 2.15.x before 2.15.3, 2.16.x before 2.16.5, 2.17.x before 2.17.2, 2.18.x before 2.18.1, and 2.19.x before 2.19.1 allows remote code execution during processing of a recursive "git clone" of a superproject if a .gitmodules file has a URL field beginning with a '-' character.

    Source:joernchen
    Published:5 Oct 2018
    6.1
    Medium

    CVE-2018-17443

    Last Modified: 5 Oct 2018

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.

    Source:Core Security
    Published:8 Oct 2018
    8.8
    High

    CVE-2018-17442

    Last Modified: 5 Oct 2018

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. An unrestricted file upload vulnerability in the onUploadLogPic endpoint allows remote authenticated users to execute arbitrary PHP code.

    Source:Core Security
    Published:8 Oct 2018
    6.1
    Medium

    CVE-2018-17441

    Last Modified: 5 Oct 2018

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'username' parameter of the addUser endpoint is vulnerable to stored XSS.

    Source:Core Security
    Published:8 Oct 2018
    9.8
    Critical

    CVE-2018-17440

    Last Modified: 5 Oct 2018

    An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. They expose an FTP server that serves by default on port 9000 and has hardcoded credentials (admin, admin). Taking advantage of this, a remote unauthenticated attacker could execute arbitrary PHP code by uploading any file in the web root directory and then accessing it via a request.

    Source:Core Security
    Published:8 Oct 2018
    9.8
    Critical

    CVE-2018-17431

    Last Modified: 22 Sept 2020

    Web Console in Comodo UTM Firewall before 2.7.0 allows remote attackers to execute arbitrary code without authentication via a crafted URL.

    Source:Milad Fadavvi
    Published:29 Jan 2019
    9.8
    Critical

    CVE-2018-17428

    Last Modified: 4 Oct 2018

    An issue was discovered in OPAC EasyWeb Five 5.7. There is SQL injection via the w2001/index.php?scelta=campi biblio parameter.

    Source:Dino Barlattani
    Published:3 Oct 2018
    7.2
    High

    CVE-2018-17418

    Last Modified: 21 Nov 2024

    Monstra CMS 3.0.4 allows remote attackers to execute arbitrary PHP code via a mixed-case file extension, as demonstrated by the 123.PhP filename, because plugins\box\filesmanager\filesmanager.admin.php mishandles the forbidden_types variable.

    Published:7 Mar 2019
    7.8
    High

    CVE-2018-17408

    Last Modified: 8 Oct 2018

    Stack-based buffer overflows in Zahir Accounting Enterprise Plus 6 through build 10b allow remote attackers to execute arbitrary code via a crafted CSV file that is accessed through the Import CSV File menu.

    Source:Metasploit
    Published:3 Oct 2018
    9.8
    Critical

    CVE-2018-17397

    Last Modified: 25 Sept 2018

    SQL Injection exists in the AlphaIndex Dictionaries 1.0 component for Joomla! via the letter parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17394

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Timetable Schedule 3.6.8 component for Joomla! via the eid parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17391

    Last Modified: 25 Sept 2018

    SQL Injection exists in authors_post.php in Super Cms Blog Pro 1.0 via the author parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17385

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Social Factory 3.8.3 component for Joomla! via the radius[lat], radius[lng], or radius[radius] parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17384

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Swap Factory 2.2.1 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018