Unknown

    CVE-2018-16341

    https://github.com/mpgn/CVE-2018-16341

    6.5
    Medium

    CVE-2018-16323

    Last Modified: 20 Nov 2018

    ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into a process that includes sensitive information, that information sometimes can be leaked via the image data.

    Source:ttffdd
    Published:24 Jul 2018
    7.8
    High

    CVE-2018-16302

    Last Modified: 2 Oct 2018

    MediaComm Zip-n-Go before 4.95 has a Buffer Overflow via a crafted file.

    Source:Hashim Jawad
    Published:1 Sept 2018
    7.5
    High

    CVE-2018-16299

    Last Modified: 25 Sept 2018

    The Localize My Post plugin 1.0 for WordPress allows Directory Traversal via the ajax/include.php file parameter.

    Source:Manuel García Cárdenas
    Published:24 Sept 2018
    8.6
    High

    CVE-2018-16288

    Last Modified: 19 Sept 2018

    LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.

    Source:Alejandro Fanjul
    Published:14 Sept 2018
    9.8
    Critical

    CVE-2018-16283

    Last Modified: 25 Sept 2018

    The Wechat Broadcast plugin 1.2.0 and earlier for WordPress allows Directory Traversal via the Image.php url parameter.

    Source:Manuel García Cárdenas
    Published:24 Sept 2018
    3.3
    Low

    CVE-2018-16252

    Last Modified: 3 Sept 2018

    FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.

    Source:hyp3rlinx
    Published:5 Sept 2018
    9.8
    Critical

    CVE-2018-16167

    Last Modified: 1 Jun 2021

    LogonTracer 1.2.0 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors.

    Source:g0ldm45k
    Published:9 Jan 2019
    7.8
    High

    CVE-2018-16156

    Last Modified: 8 Jan 2021

    In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported function named ChangeUninstallString. The default install does not contain this library and therefore if any DLL with that name exists in any directory listed in the PATH variable, it can be used to escalate to SYSTEM level privilege.

    Source:1F98D
    Published:17 May 2019
    6.1
    Medium

    CVE-2018-16134

    Last Modified: 3 Sept 2018

    Cybrotech CyBroHttpServer 1.0.3 allows XSS via a URI.

    Source:Emre ÖVÜNÇ
    Published:29 Aug 2018
    5.3
    Medium

    CVE-2018-16133

    Last Modified: 3 Sept 2018

    Cybrotech CyBroHttpServer 1.0.3 allows Directory Traversal via a ../ in the URI.

    Source:Emre ÖVÜNÇ
    Published:29 Aug 2018
    7.2
    High

    CVE-2018-16119

    Last Modified: 21 Nov 2024

    Stack-based buffer overflow in the httpd server of TP-Link WR1043nd (Firmware Version 3) allows remote attackers to execute arbitrary code via a malicious MediaServer request to /userRpm/MediaServerFoldersCfgRpm.htm.

    Published:20 Jun 2019
    8.8
    High

    CVE-2018-16083

    Last Modified: 21 Sept 2018

    An out of bounds read in forward error correction code in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page.

    Source:Google Security Research
    Published:4 Sept 2018
    8.8
    High

    CVE-2018-16071

    Last Modified: 21 Sept 2018

    A use after free in WebRTC in Google Chrome prior to 69.0.3497.81 allowed a remote attacker to potentially exploit heap corruption via a crafted video file.

    Source:Google Security Research
    Published:4 Sept 2018
    6.1
    Medium

    CVE-2018-16061

    Last Modified: 19 Oct 2021

    Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.

    Source:Hamit CİBO
    Published:15 Oct 2021
    7.5
    High

    CVE-2018-16060

    Last Modified: 19 Oct 2021

    Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.

    Source:Hamit CİBO
    Published:15 Oct 2021
    5.3
    Medium

    CVE-2018-16059

    Last Modified: 10 Sept 2018

    Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.

    Source:Hamit CİBO
    Published:7 Sept 2018
    7.8
    High

    CVE-2018-15982

    Last Modified: 24 Dec 2018

    Flash Player versions 31.0.0.153 and earlier, and 31.0.0.108 and earlier have a use after free vulnerability. Successful exploitation could lead to arbitrary code execution.

    Source:smgorelik
    Published:5 Dec 2018
    5.5
    Medium

    CVE-2018-15968

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader versions 2018.011.20063 and earlier, 2017.011.30102 and earlier, and 2015.006.30452 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Published:12 Oct 2018
    9.8
    Critical

    CVE-2018-15961

    Last Modified: 11 Dec 2018

    Adobe ColdFusion versions July 12 release (2018.0.0.310739), Update 6 and earlier, and Update 14 and earlier have an unrestricted file upload vulnerability. Successful exploitation could lead to arbitrary code execution.

    Source:Vahagn Vardanyan
    Published:25 Sept 2018
    5.4
    Medium

    CVE-2018-15918

    Last Modified: 11 Sept 2018

    An issue was discovered in Jorani 0.6.5. SQL Injection (error-based) allows a user of the application without permissions to read and modify sensitive information from the database used by the application via the startdate or enddate parameter to leaves/validate.

    Source:Javier Olmedo
    Published:5 Sept 2018
    5.4
    Medium

    CVE-2018-15917

    Last Modified: 6 Sept 2018

    Persistent cross-site scripting (XSS) issues in Jorani 0.6.5 allow remote attackers to inject arbitrary web script or HTML via the language parameter to session/language.

    Source:Javier Olmedo
    Published:5 Sept 2018
    7.8
    High

    CVE-2018-15912

    Last Modified: 21 Nov 2024

    An issue was discovered in manjaro-update-system.sh in manjaro-system 20180716-1 on Manjaro Linux. A local attacker can install or remove arbitrary packages and package repositories potentially containing hooks with arbitrary code, which will automatically be run as root, or remove packages vital to the system.

    Published:29 Aug 2018
    8.8
    High

    CVE-2018-15884

    Last Modified: 27 Aug 2018

    RICOH MP C4504ex devices allow HTML Injection via the /web/entry/en/address/adrsSetUserWizard.cgi entryNameIn parameter.

    Source:Ismail Tasdelen
    Published:28 Aug 2018
    8.8
    High

    CVE-2018-15877

    Last Modified: 28 Aug 2018

    The Plainview Activity Monitor plugin before 20180826 for WordPress is vulnerable to OS command injection via shell metacharacters in the ip parameter of a wp-admin/admin.php?page=plainview_activity_monitor&tab=activity_tools request.

    Source:Lydéric Lefebvre
    Published:26 Aug 2018
    8.8
    High

    CVE-2018-15845

    Last Modified: 27 Aug 2018

    There is a CSRF vulnerability that can add an administrator account in Gleez CMS 1.2.0 via admin/users/add.

    Source:GunEggWang
    Published:25 Aug 2018
    8.8
    High

    CVE-2018-15844

    Last Modified: 3 Sept 2018

    An issue was discovered in DamiCMS 6.0.0. There is an CSRF vulnerability that can revise the administrator account's password via /admin.php?s=/Admin/doedit.

    Source:Autism_JH
    Published:25 Aug 2018
    9.8
    Critical

    CVE-2018-15839

    Last Modified: 3 Sept 2018

    D-Link DIR-615 devices have a buffer overflow via a long Authorization HTTP header.

    Source:Aniket Dinda
    Published:28 Aug 2018
    7.5
    High

    CVE-2018-15835

    Last Modified: 21 Nov 2024

    Android 1.0 through 9.0 has Insecure Permissions. The Android bug ID is 77286983.

    Published:30 Nov 2018
    8.8
    High

    CVE-2018-15832

    Last Modified: 21 Nov 2024

    upc.exe in Ubisoft Uplay Desktop Client versions 63.0.5699.0 allows remote attackers to execute arbitrary code. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the processing of URI handlers. The issue results from the lack of proper validation of a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code under the context of the current process.

    Published:20 Sept 2018
    7.5
    High

    CVE-2018-15812

    Last Modified: 16 Apr 2020

    DNN (aka DotNetNuke) 9.2 through 9.2.1 incorrectly converts encryption key source values, resulting in lower than expected entropy.

    Source:Metasploit
    Published:3 Jul 2019
    7.5
    High

    CVE-2018-15811

    Last Modified: 16 Apr 2020

    DNN (aka DotNetNuke) 9.2 through 9.2.1 uses a weak encryption algorithm to protect input parameters.

    Source:Metasploit
    Published:3 Jul 2019
    6.5
    Medium

    CVE-2018-15768

    Last Modified: 14 Nov 2018

    Dell OpenManage Network Manager versions prior to 6.5.0 enabled read/write access to the file system for MySQL users due to insecure default configuration setting for the embedded MySQL database.

    Source:KoreLogic
    Published:30 Nov 2018
    8.8
    High

    CVE-2018-15767

    Last Modified: 14 Nov 2018

    The Dell OpenManage Network Manager virtual appliance versions prior to 6.5.3 contain an improper authorization vulnerability caused by a misconfiguration in the /etc/sudoers file.

    Source:KoreLogic
    Published:30 Nov 2018
    7.5
    High

    CVE-2018-15745

    Last Modified: 6 Sept 2018

    Argus Surveillance DVR 4.0.0.0 devices allow Unauthenticated Directory Traversal, leading to File Disclosure via a ..%2F in the WEBACCOUNT.CGI RESULTPAGE parameter.

    Source:hyp3rlinx
    Published:30 Aug 2018
    6.1
    Medium

    CVE-2018-15740

    Last Modified: 12 Sept 2018

    Zoho ManageEngine ADManager Plus 6.5.7 has XSS on the "Workflow Delegation" "Requester Roles" screen.

    Source:Ismail Tasdelen
    Published:28 Aug 2018
    9.8
    Critical

    CVE-2018-15727

    Last Modified: 21 Nov 2024

    Grafana 2.x, 3.x, and 4.x before 4.6.4 and 5.x before 5.2.3 allows authentication bypass because an attacker can generate a valid "remember me" cookie knowing only a username of an LDAP or OAuth user.

    Published:29 Aug 2018
    8.8
    High

    CVE-2018-15716

    Last Modified: 17 Mar 2019

    NUUO NVRMini2 version 3.9.1 is vulnerable to authenticated remote command injection. An attacker can send crafted requests to upgrade_handle.php to execute OS commands as root.

    Source:Artem Metla
    Published:30 Nov 2018
    7.8
    High

    CVE-2018-15710

    Last Modified: 26 Jun 2019

    Nagios XI 5.5.6 allows local authenticated attackers to escalate privileges to root via Autodiscover_new.php.

    Source:Metasploit
    Published:14 Nov 2018
    9.8
    Critical

    CVE-2018-15708

    Last Modified: 26 Jun 2019

    Snoopy 1.0 in Nagios XI 5.5.6 allows remote unauthenticated attackers to execute arbitrary commands via a crafted HTTP request.

    Source:Metasploit
    Published:14 Nov 2018
    5.4
    Medium

    CVE-2018-15707

    Last Modified: 5 Nov 2018

    Advantech WebAccess 8.3.1 and 8.3.2 are vulnerable to cross-site scripting in the Bwmainleft.asp page. An attacker could leverage this vulnerability to disclose credentials amongst other things.

    Source:Chris Lyne
    Published:31 Oct 2018
    6.5
    Medium

    CVE-2018-15705

    Last Modified: 5 Nov 2018

    WADashboard API in Advantech WebAccess 8.3.1 and 8.3.2 allows remote authenticated attackers to write or overwrite any file on the filesystem due to a directory traversal vulnerability in the writeFile API. An attacker can use this vulnerability to remotely execute arbitrary code.

    Source:Chris Lyne
    Published:31 Oct 2018
    9.8
    Critical

    CVE-2018-15691

    Last Modified: 18 Sept 2018

    Insecure deserialization of a specially crafted serialized object, in CA Release Automation 6.5 and earlier, allows attackers to potentially execute arbitrary code.

    Source:Jakub Palaczynski
    Published:30 Aug 2018
    7
    High

    CVE-2018-15687

    Last Modified: 17 Nov 2018

    A race condition in chown_one() of systemd allows an attacker to cause systemd to set arbitrary permissions on arbitrary files. Affected releases are systemd versions up to and including 239.

    Source:Google Security Research
    Published:26 Oct 2018
    7.8
    High

    CVE-2018-15686

    Last Modified: 17 Nov 2018

    A vulnerability in unit_deserialize of systemd allows an attacker to supply arbitrary state across systemd re-execution via NotifyAccess. This can be used to improperly influence systemd execution and possibly lead to root privilege escalation. Affected releases are systemd versions up to and including 239.

    Source:Google Security Research
    Published:26 Oct 2018
    8.1
    High

    CVE-2018-15685

    Last Modified: 27 Aug 2018

    GitHub Electron 1.7.15, 1.8.7, 2.0.7, and 3.0.0-beta.6, in certain scenarios involving IFRAME elements and "nativeWindowOpen: true" or "sandbox: true" options, is affected by a WebPreferences vulnerability that can be leveraged to perform remote code execution.

    Source:Matt Austin
    Published:23 Aug 2018
    7.3
    High

    CVE-2018-15657

    Last Modified: 1 Feb 2019

    An SSRF issue was discovered in 42Gears SureMDM before 2018-11-27 via the /api/DownloadUrlResponse.ashx "url" parameter.

    Source:Digital Interruption
    Published:5 Feb 2019
    6.1
    Medium

    CVE-2018-15608

    Last Modified: 25 Aug 2018

    Zoho ManageEngine ADManager Plus 6.5.7 allows HTML Injection on the "AD Delegation" "Help Desk Technicians" screen.

    Source:Ismail Tasdelen
    Published:28 Aug 2018
    5.3
    Medium

    CVE-2018-15599

    Last Modified: 21 Nov 2024

    The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages are handled, a similar issue to CVE-2018-15473 in an unrelated codebase.

    Published:21 Aug 2018
    6.1
    Medium

    CVE-2018-15596

    Last Modified: 13 Sept 2018

    An issue was discovered in inc/class_feedgeneration.php in MyBB 1.8.17. On the forum RSS Syndication page, one can generate a URL such as http://localhost/syndication.php?fid=&type=atom1.0&limit=15. The thread titles (within title elements of the generated XML documents) aren't sanitized, leading to XSS.

    Source:0xB9
    Published:28 Aug 2018