9.8
    Critical

    CVE-2018-17383

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Collection Factory 4.1.9 component for Joomla! via the filter_order or filter_order_Dir parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17382

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Jobs Factory 2.0.4 component for Joomla! via the filter_letter parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17380

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Article Factory Manager 4.3.9 component for Joomla! via the start_date, m_start_date, or m_end_date parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17379

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Raffle Factory 3.5.2 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17378

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Penny Auction Factory 2.0.4 component for Joomla! via the filter_order_Dir or filter_order parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17377

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Questions 1.4.3 component for Joomla! via the term, userid, users, or groups parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17376

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Reverse Auction Factory 4.3.8 component for Joomla! via the filter_order_Dir, cat, or filter_letter parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-17375

    Last Modified: 25 Sept 2018

    SQL Injection exists in the Music Collection 3.0.3 component for Joomla! via the id parameter.

    Source:Ihsan Sencan
    Published:28 Sept 2018
    6.1
    Medium

    CVE-2018-17313

    Last Modified: 3 Oct 2018

    On the RICOH MP C307 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

    Source:Ismail Tasdelen
    Published:26 Sept 2018
    6.1
    Medium

    CVE-2018-17310

    Last Modified: 3 Oct 2018

    On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.

    Source:Ismail Tasdelen
    Published:26 Sept 2018
    7.5
    High

    CVE-2018-17297

    Last Modified: 21 Nov 2024

    The unzip function in ZipUtil.java in Hutool before 4.1.12 allows remote attackers to overwrite arbitrary files via directory traversal sequences in a filename within a ZIP archive.

    Published:21 Sept 2018
    Low

    CVE-2018-17255

    Last Modified: 24 Sept 2018

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2020-14014. Reason: This candidate is a reservation duplicate of CVE-2020-14014. Notes: All CVE users should reference CVE-2020-14014 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Renzi
    Published:20 Sept 2018
    9.8
    Critical

    CVE-2018-17254

    Last Modified: 8 Mar 2021

    The JCK Editor component 6.4.4 for Joomla! allows SQL Injection via the jtreelink/dialogs/links.php parent parameter.

    Source:Nicholas Ferreira
    Published:20 Sept 2018
    9.8
    Critical

    CVE-2018-17246

    Last Modified: 21 Nov 2024

    Kibana versions before 6.4.3 and 5.6.13 contain an arbitrary file inclusion flaw in the Console plugin. An attacker with access to the Kibana Console API could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.

    Published:6 Nov 2018
    7.5
    High

    CVE-2018-17240

    Last Modified: 21 Nov 2024

    There is a memory dump vulnerability on Netwave IP camera devices at //proc/kcore that allows an unauthenticated attacker to exfiltrate sensitive information from the network configuration (e.g., username and password).

    Published:10 Jun 2022
    6.5
    Medium

    CVE-2018-17229

    Last Modified: 21 Nov 2024

    Exiv2::d2Data in types.cpp in Exiv2 v0.26 allows remote attackers to cause a denial of service (heap-based buffer overflow) via a crafted image file.

    Published:17 Sept 2018
    9.8
    Critical

    CVE-2018-17207

    Last Modified: 2 Feb 2026

    An issue was discovered in Snap Creek Duplicator before 1.2.42. By accessing leftover installer files (installer.php and installer-backup.php), an attacker can inject PHP code into wp-config.php during the database setup step, achieving arbitrary code execution.

    Published:19 Sept 2018
    7.4
    High

    CVE-2018-17187

    Last Modified: 21 Nov 2024

    The Apache Qpid Proton-J transport includes an optional wrapper layer to perform TLS, enabled by use of the 'transport.ssl(...)' methods. Unless a verification mode was explicitly configured, client and server modes previously defaulted as documented to not verifying a peer certificate, with options to configure this explicitly or select a certificate verification mode with or without hostname verification being performed. The latter hostname verifying mode was not implemented in Apache Qpid Proton-J versions 0.3 to 0.29.0, with attempts to use it resulting in an exception. This left only the option to verify the certificate is trusted, leaving such a client vulnerable to Man In The Middle (MITM) attack. Uses of the Proton-J protocol engine which do not utilise the optional transport TLS wrapper are not impacted, e.g. usage within Qpid JMS. Uses of Proton-J utilising the optional transport TLS wrapper layer that wish to enable hostname verification must be upgraded to version 0.30.0 or later and utilise the VerifyMode#VERIFY_PEER_NAME configuration, which is now the default for client mode usage unless configured otherwise.

    Published:12 Nov 2018
    7.8
    High

    CVE-2018-17182

    Last Modified: 28 Sept 2018

    An issue was discovered in the Linux kernel through 4.18.8. The vmacache_flush_all function in mm/vmacache.c mishandles sequence number overflows. An attacker can trigger a use-after-free (and possibly gain privileges) via certain thread creation, map, unmap, invalidation, and dereference operations.

    Source:Google Security Research
    Published:13 Sept 2018
    9.8
    Critical

    CVE-2018-17179

    Last Modified: 21 Nov 2024

    An issue was discovered in OpenEMR before 5.0.1 Patch 7. There is SQL Injection in the make_task function in /interface/forms/eye_mag/php/taskman_functions.php via /interface/forms/eye_mag/taskman.php.

    Published:17 May 2019
    9.8
    Critical

    CVE-2018-17173

    Last Modified: 6 May 2019

    LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.

    Source:Alejandro Fanjul
    Published:21 Sept 2018
    7.5
    High

    CVE-2018-17144

    Last Modified: 21 Nov 2024

    Bitcoin Core 0.14.x before 0.14.3, 0.15.x before 0.15.2, and 0.16.x before 0.16.3 and Bitcoin Knots 0.14.x through 0.16.x before 0.16.3 allow a remote denial of service (application crash) exploitable by miners via duplicate input. An attacker can make bitcoind or Bitcoin-Qt crash.

    Published:19 Sept 2018
    5.4
    Medium

    CVE-2018-17128

    Last Modified: 24 Sept 2018

    A Persistent XSS issue was discovered in the Visual Editor in MyBB before 1.8.19 via a Video MyCode.

    Source:Numan OZDEMIR
    Published:17 Sept 2018
    4.3
    Medium

    CVE-2018-17081

    Last Modified: 21 Nov 2024

    e107 2.1.9 allows CSRF via e107_admin/wmessage.php?mode=&action=inline&ajax_used=1&id= for changing the title of an arbitrary page.

    Published:26 Sept 2018
    9.8
    Critical

    CVE-2018-17057

    Last Modified: 2 Apr 2019

    An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.

    Source:q3rv0
    Published:14 Sept 2018
    7.2
    High

    CVE-2018-16987

    Last Modified: 21 Nov 2024

    Squash TM through 1.18.0 presents the cleartext passwords of external services in the administration panel, as demonstrated by a ta-server-password field in the HTML source code.

    Published:13 Sept 2018
    7.5
    High

    CVE-2018-16946

    Last Modified: 12 Sept 2018

    LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via download.php) without authenticating. These backup files contain user credentials and configuration information for the camera device. An attacker is able to discover the backup filename via reading the system logs or report data, or just by brute-forcing the backup filename pattern. It may be possible to authenticate to the admin account with the admin password.

    Source:Ege Balci
    Published:12 Sept 2018
    7.5
    High

    CVE-2018-16890

    Last Modified: 15 Apr 2026

    libcurl versions from 7.36.0 to before 7.64.0 is vulnerable to a heap buffer out-of-bounds read. The function handling incoming NTLM type-2 messages (`lib/vauth/ntlm.c:ntlm_decode_type2_target`) does not validate incoming data correctly and is subject to an integer overflow vulnerability. Using that overflow, a malicious or broken NTLM server could trick libcurl to accept a bad length + offset combination that would lead to a buffer read out-of-bounds.

    Published:6 Feb 2019
    5.9
    Medium

    CVE-2018-16875

    Last Modified: 21 Nov 2024

    The crypto/x509 package of Go before 1.10.6 and 1.11.x before 1.11.3 does not limit the amount of work performed for each chain verification, which might allow attackers to craft pathological inputs leading to a CPU denial of service. Go TLS servers accepting client certificates and TLS clients are affected.

    Published:13 Dec 2018
    7.8
    High

    CVE-2018-16858

    Last Modified: 18 Apr 2019

    It was found that libreoffice before versions 6.0.7 and 6.1.3 was vulnerable to a directory traversal attack which could be used to execute arbitrary macros bundled with a document. An attacker could craft a document, which when opened by LibreOffice, would execute a Python method from a script in any arbitrary file system location, specified relative to the LibreOffice install location.

    Source:Metasploit
    Published:1 Feb 2019
    6.5
    Medium

    CVE-2018-16854

    Last Modified: 21 Nov 2024

    A flaw was found in moodle versions 3.5 to 3.5.2, 3.4 to 3.4.5, 3.3 to 3.3.8, 3.1 to 3.1.14 and earlier. The login form is not protected by a token to prevent login cross-site request forgery. Fixed versions include 3.6, 3.5.3, 3.4.6, 3.3.9 and 3.1.15.

    Published:26 Nov 2018
    7.5
    High

    CVE-2018-16843

    Last Modified: 21 Nov 2024

    nginx before versions 1.15.6 and 1.14.1 has a vulnerability in the implementation of HTTP/2 that can allow for excessive memory consumption. This issue affects nginx compiled with the ngx_http_v2_module (not compiled by default) if the 'http2' option of the 'listen' directive is used in a configuration file.

    Published:6 Nov 2018
    9.8
    Critical

    CVE-2018-16836

    Last Modified: 12 Sept 2018

    Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as demonstrated by a /theme/default/img/%2e%2e/..//etc/passwd URI.

    Source:Marouene Boubakri
    Published:11 Sept 2018
    9.8
    Critical

    CVE-2018-16809

    Last Modified: 21 Nov 2024

    An issue was discovered in Dolibarr through 7.0.0. expensereport/card.php in the expense reports module allows SQL injection via the integer parameters qty and value_unit.

    Published:7 Mar 2019
    9.8
    Critical

    CVE-2018-16763

    Last Modified: 28 Jan 2021

    FUEL CMS 1.4.1 allows PHP Code Evaluation via the pages/select/ filter parameter or the preview/ data parameter. This can lead to Pre-Auth Remote Code Execution.

    Source:0xd0ff9
    Published:9 Sept 2018
    5.4
    Medium

    CVE-2018-16736

    Last Modified: 19 Sept 2018

    In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).

    Source:Fahimeh Rezaei
    Published:9 Sept 2018
    6.5
    Medium

    CVE-2018-16713

    Last Modified: 21 Nov 2024

    IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402084) with a buffer containing user defined content. The driver's subroutine will execute a rdmsr instruction with the user's buffer for input, and provide output from the instruction.

    Published:26 Sept 2018
    6.5
    Medium

    CVE-2018-16712

    Last Modified: 21 Nov 2024

    IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send a specially crafted IOCTL 0x9C406104 to read physical memory.

    Published:26 Sept 2018
    8.8
    High

    CVE-2018-16711

    Last Modified: 21 Nov 2024

    IObit Advanced SystemCare, which includes Monitor_win10_x64.sys or Monitor_win7_x64.sys, 1.2.0.5 (and possibly earlier versions) allows a user to send an IOCTL (0x9C402088) with a buffer containing user defined content. The driver's subroutine will execute a wrmsr instruction with the user's buffer for input.

    Published:26 Sept 2018
    7.5
    High

    CVE-2018-16706

    Last Modified: 21 Nov 2024

    LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.

    Published:14 Sept 2018
    9.8
    Critical

    CVE-2018-16659

    Last Modified: 1 Oct 2018

    An issue was discovered in Rausoft ID.prove 2.95. The login page allows SQL injection via Microsoft SQL Server stacked queries in the Username POST parameter. Hypothetically, an attacker can utilize master..xp_cmdshell for the further privilege elevation.

    Source:Ilya Timchenko
    Published:28 Sept 2018
    7.2
    High

    CVE-2018-16621

    Last Modified: 21 Nov 2024

    Sonatype Nexus Repository Manager before 3.14 allows Java Expression Language Injection.

    Published:15 Nov 2018
    6.5
    Medium

    CVE-2018-16606

    Last Modified: 16 Apr 2025

    In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Organization, and Position) by changing the value of Paper ID (the pid parameter).

    Source:ub3rsick
    Published:6 Sept 2018
    5.5
    Medium

    CVE-2018-16517

    Last Modified: 18 Apr 2019

    asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.

    Source:Fakhri Zulkifli
    Published:5 Sept 2018
    7.8
    High

    CVE-2018-16509

    Last Modified: 10 Sept 2018

    An issue was discovered in Artifex Ghostscript before 9.24. Incorrect "restoration of privilege" checking during handling of /invalidaccess exceptions could be used by attackers able to supply crafted PostScript to execute code using the "pipe" instruction.

    Source:Metasploit
    Published:21 Aug 2018
    9.8
    Critical

    CVE-2018-16492

    Last Modified: 21 Nov 2024

    A prototype pollution vulnerability was found in module extend <2.0.2, ~<3.0.2 that allows an attacker to inject arbitrary properties onto Object.prototype.

    Published:24 Apr 2018
    8.8
    High

    CVE-2018-16431

    Last Modified: 21 Nov 2024

    admin/admin/adminsave.html in YFCMF v3.0 allows CSRF to add an administrator account.

    Published:4 Sept 2018
    9.8
    Critical

    CVE-2018-16385

    Last Modified: 21 Nov 2024

    ThinkPHP before 5.1.23 allows SQL Injection via the public/index/index/test/index query string.

    Published:3 Sept 2018
    4.9
    Medium

    CVE-2018-16373

    Last Modified: 21 Nov 2024

    Frog CMS 0.9.5 has an Upload vulnerability that can create files via /admin/?/plugin/file_manager/save.

    Published:3 Sept 2018
    9.8
    Critical

    CVE-2018-16370

    Last Modified: 21 Nov 2024

    In PESCMS Team 2.2.1, attackers may upload and execute arbitrary PHP code through /Public/?g=Team&m=Setting&a=upgrade by placing a .php file in a ZIP archive.

    Published:3 Sept 2018