8.1
    High

    CVE-2018-15576

    Last Modified: 21 Aug 2018

    An issue was discovered in EasyLogin Pro through 1.3.0. Encryptor.php contains an unserialize call that can be exploited for remote code execution in the decrypt function, if the attacker knows the key.

    Source:mr_me
    Published:24 Aug 2018
    5.5
    Medium

    CVE-2018-15536

    Last Modified: 27 Aug 2018

    /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 does not properly validate file paths in archives, allowing for the extraction of crafted archives to overwrite arbitrary files via an extract action, aka Directory Traversal.

    Source:Simon Uvarov
    Published:24 Aug 2018
    7.5
    High

    CVE-2018-15535

    Last Modified: 27 Aug 2018

    /filemanager/ajax_calls.php in tecrail Responsive FileManager before 9.13.4 uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize get_file sequences such as ".." that can resolve to a location that is outside of that directory, aka Directory Traversal.

    Source:Simon Uvarov
    Published:24 Aug 2018
    9.8
    Critical

    CVE-2018-15534

    Last Modified: 22 Aug 2018

    Geutebrueck re_porter 16 before 7.8.974.20 has a possibility of unauthenticated access to sensitive information including usernames and hashes via a direct request for /statistics/gscsetup.xml on TCP port 12003.

    Source:Kamil Suska
    Published:21 Aug 2018
    6.1
    Medium

    CVE-2018-15533

    Last Modified: 22 Aug 2018

    A reflected cross-site scripting vulnerability exists in Geutebrueck re_porter 16 before 7.8.974.20 by appending a query string to /modifychannel/exec or /images/*.png on TCP port 12005.

    Source:Kamil Suska
    Published:21 Aug 2018
    4.7
    Medium

    CVE-2018-15499

    Last Modified: 21 Nov 2024

    GEAR Software products that include GEARAspiWDM.sys, 2.2.5.0, allow local users to cause a denial of service (Race Condition and BSoD on Windows) by not checking that user-mode memory is available right before writing to it. A check is only performed at the beginning of a long subroutine.

    Published:24 Aug 2018
    5.9
    Medium

    CVE-2018-15473

    Last Modified: 1 Oct 2018

    OpenSSH through 7.7 is prone to a user enumeration vulnerability due to not delaying bailout for an invalid authenticating user until after the packet containing the request has been fully parsed, related to auth2-gss.c, auth2-hostbased.c, and auth2-pubkey.c.

    Source:Justin Gardner
    Published:16 Aug 2018
    7.8
    High

    CVE-2018-15442

    Last Modified: 25 Oct 2018

    A vulnerability in the update service of Cisco Webex Meetings Desktop App for Windows could allow an authenticated, local attacker to execute arbitrary commands as a privileged user. The vulnerability is due to insufficient validation of user-supplied parameters. An attacker could exploit this vulnerability by invoking the update service command with a crafted argument. An exploit could allow the attacker to run arbitrary commands with SYSTEM user privileges. While the CVSS Attack Vector metric denotes the requirement for an attacker to have local access, administrators should be aware that in Active Directory deployments, the vulnerability could be exploited remotely by leveraging the operating system remote management tools.

    Source:Metasploit
    Published:24 Oct 2018
    5.5
    Medium

    CVE-2018-15437

    Last Modified: 13 Nov 2018

    A vulnerability in the system scanning component of Cisco Immunet and Cisco Advanced Malware Protection (AMP) for Endpoints running on Microsoft Windows could allow a local attacker to disable the scanning functionality of the product. This could allow executable files to be launched on the system without being analyzed for threats. The vulnerability is due to improper process resource handling. An attacker could exploit this vulnerability by gaining local access to a system running Microsoft Windows and protected by Cisco Immunet or Cisco AMP for Endpoints and executing a malicious file. A successful exploit could allow the attacker to prevent the scanning services from functioning properly and ultimately prevent the system from being protected from further intrusion.

    Source:hyp3rlinx
    Published:8 Nov 2018
    9.8
    Critical

    CVE-2018-15379

    Last Modified: 17 Mar 2019

    A vulnerability in which the HTTP web server for Cisco Prime Infrastructure (PI) has unrestricted directory permissions could allow an unauthenticated, remote attacker to upload an arbitrary file. This file could allow the attacker to execute commands at the privilege level of the user prime. This user does not have administrative or root privileges. The vulnerability is due to an incorrect permission setting for important system directories. An attacker could exploit this vulnerability by uploading a malicious file by using TFTP, which can be accessed via the web-interface GUI. A successful exploit could allow the attacker to run commands on the targeted application without authentication.

    Source:SecuriTeam
    Published:5 Oct 2018
    5.4
    Medium

    CVE-2018-15365

    Last Modified: 21 Nov 2024

    A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable installations. An attacker must be an authenticated user in order to exploit the vulnerability.

    Published:28 Sept 2018
    6.5
    Medium

    CVE-2018-15181

    Last Modified: 15 Aug 2018

    JioFi 4G Hotspot M2S devices allow attackers to cause a denial of service (secure configuration outage) via an XSS payload in the SSID name and Security Key fields.

    Source:Vikas Chaudhary
    Published:9 Aug 2018
    7.5
    High

    CVE-2018-15172

    Last Modified: 17 Aug 2018

    TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.

    Source:Aniket Dinda
    Published:15 Aug 2018
    9.1
    Critical

    CVE-2018-15152

    Last Modified: 28 Oct 2021

    Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_popup_user.php, (3) portal/get_allergies.php, (4) portal/get_amendments.php, (5) portal/get_lab_results.php, (6) portal/get_medications.php, (7) portal/get_patient_documents.php, (8) portal/get_problems.php, (9) portal/get_profile.php, (10) portal/portal_payment.php, (11) portal/messaging/messages.php, (12) portal/messaging/secure_chat.php, (13) portal/report/pat_ledger.php, (14) portal/report/portal_custom_report.php, or (15) portal/report/portal_patient_report.php without authenticating as a patient.

    Source:Ron Jost
    Published:15 Aug 2018
    8.8
    High

    CVE-2018-15142

    Last Modified: 11 Sept 2018

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to execute arbitrary PHP code by writing a file with a PHP extension via the "docid" and "content" parameters and accessing it in the traversed directory.

    Source:Joshua Fam
    Published:13 Aug 2018
    6.5
    Medium

    CVE-2018-15141

    Last Modified: 11 Sept 2018

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to delete arbitrary files via the "docid" parameter when the mode is set to delete.

    Source:Joshua Fam
    Published:13 Aug 2018
    6.5
    Medium

    CVE-2018-15140

    Last Modified: 11 Sept 2018

    Directory traversal in portal/import_template.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker authenticated in the patient portal to read arbitrary files via the "docid" parameter when the mode is set to get.

    Source:Joshua Fam
    Published:13 Aug 2018
    8.8
    High

    CVE-2018-15139

    Last Modified: 14 Jun 2021

    Unrestricted file upload in interface/super/manage_site_files.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary PHP code by uploading a file with a PHP extension via the images upload form and accessing it in the images directory.

    Source:Ron Jost
    Published:13 Aug 2018
    9.8
    Critical

    CVE-2018-15137

    Last Modified: 8 Aug 2018

    CeLa Link CLR-M20 devices allow unauthorized users to upload any file (e.g., asp, aspx, cfm, html, jhtml, jsp, or shtml), which causes remote code execution as well. Because of the WebDAV feature, it is possible to upload arbitrary files by utilizing the PUT method.

    Source:Safak Aslan
    Published:8 Aug 2018
    8.1
    High

    CVE-2018-15133

    Last Modified: 16 Jul 2019

    In Laravel Framework through 5.5.40 and 5.6.x through 5.6.29, remote code execution might occur as a result of an unserialize call on a potentially untrusted X-XSRF-TOKEN value. This involves the decrypt method in Illuminate/Encryption/Encrypter.php and PendingBroadcast in gadgetchains/Laravel/RCE/3/chain.php in phpggc. The attacker must know the application key, which normally would never occur, but could happen if the attacker previously had privileged access or successfully accomplished a previous attack.

    Source:Metasploit
    Published:9 Aug 2018
    5.3
    Medium

    CVE-2018-15131

    Last Modified: 21 Nov 2024

    An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enumeration is possible via inconsistent responses for specific types of authentication requests.

    Published:30 May 2019
    6.5
    Medium

    CVE-2018-15120

    Last Modified: 15 Mar 2021

    libpango in Pango 1.40.8 through 1.42.3, as used in hexchat and other products, allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted text with invalid Unicode sequences.

    Source:Jeffery M
    Published:20 Aug 2018
    9.8
    Critical

    CVE-2018-14933

    Last Modified: 11 Feb 2019

    upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.

    Source:Metasploit
    Published:4 Aug 2018
    7.5
    High

    CVE-2018-14912

    Last Modified: 14 Aug 2018

    cgit_clone_objects in CGit before 1.2.1 has a directory traversal vulnerability when `enable-http-clone=1` is not turned off, as demonstrated by a cgit/cgit.cgi/git/objects/?path=../ request.

    Source:Dhiraj Mishra
    Published:3 Aug 2018
    7.8
    High

    CVE-2018-14894

    Last Modified: 2 May 2019

    CyberArk Endpoint Privilege Manager 10.2.1.603 and earlier allows an attacker (who is able to edit permissions of a file) to bypass intended access restrictions and execute blocked applications.

    Source:Alpcan Onaran
    Published:9 Apr 2019
    6.1
    Medium

    CVE-2018-14888

    Last Modified: 10 Aug 2018

    inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.

    Source:0xB9
    Published:14 Aug 2018
    9.8
    Critical

    CVE-2018-14881

    Last Modified: 3 Dec 2025

    The BGP parser in tcpdump before 4.9.3 has a buffer over-read in print-bgp.c:bgp_capabilities_print() (BGP_CAPCODE_RESTART).

    Published:2 Oct 2019
    7.5
    High

    CVE-2018-14880

    Last Modified: 21 Nov 2024

    The OSPFv3 parser in tcpdump before 4.9.3 has a buffer over-read in print-ospf6.c:ospf6_print_lshdr().

    Published:2 Oct 2019
    7
    High

    CVE-2018-14879

    Last Modified: 3 Dec 2025

    The command-line argument parser in tcpdump before 4.9.3 has a buffer overflow in tcpdump.c:get_next_file().

    Published:2 Oct 2019
    5.4
    Medium

    CVE-2018-14869

    Last Modified: 3 Aug 2018

    PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.

    Source:Sarafraz Khan
    Published:6 Aug 2018
    9.1
    Critical

    CVE-2018-14847

    Last Modified: 10 Oct 2018

    MikroTik RouterOS through 6.42 allows unauthenticated remote attackers to read arbitrary files and remote authenticated attackers to write arbitrary files due to a directory traversal vulnerability in the WinBox interface.

    Source:Jacob Baines
    Published:2 Aug 2018
    6.1
    Medium

    CVE-2018-14840

    Last Modified: 8 Aug 2018

    uploads/.htaccess in Subrion CMS 4.2.1 allows XSS because it does not block .html file uploads (but does block, for example, .htm file uploads).

    Source:Zeel Chavda
    Published:2 Aug 2018
    7.2
    High

    CVE-2018-14772

    Last Modified: 21 Nov 2024

    Pydio 4.2.1 through 8.2.1 has an authenticated remote code execution vulnerability in which an attacker with administrator access to the web application can execute arbitrary code on the underlying system via Command Injection.

    Published:16 Oct 2018
    8.8
    High

    CVE-2018-14729

    Last Modified: 21 Nov 2024

    The database backup feature in upload/source/admincp/admincp_db.php in Discuz! 2.5 and 3.4 allows remote attackers to execute arbitrary PHP code.

    Published:22 May 2019
    9.8
    Critical

    CVE-2018-14728

    Last Modified: 9 Aug 2018

    upload.php in Responsive FileManager 9.13.1 allows SSRF via the url parameter.

    Source:GUIA BRAHIM FOUAD
    Published:3 Aug 2018
    10
    Critical

    CVE-2018-14721

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to conduct server-side request forgery (SSRF) attacks by leveraging failure to block the axis2-jaxws class from polymorphic deserialization.

    Published:27 Jul 2018
    9.8
    Critical

    CVE-2018-14720

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow attackers to conduct external XML entity (XXE) attacks by leveraging failure to block unspecified JDK classes from polymorphic deserialization.

    Published:27 Jul 2018
    9.8
    Critical

    CVE-2018-14719

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the blaze-ds-opt and blaze-ds-core classes from polymorphic deserialization.

    Published:27 Jul 2018
    9.8
    Critical

    CVE-2018-14718

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind 2.x before 2.9.7 might allow remote attackers to execute arbitrary code by leveraging failure to block the slf4j-ext class from polymorphic deserialization.

    Published:27 Jul 2018
    7.5
    High

    CVE-2018-14716

    Last Modified: 9 Aug 2018

    A Server Side Template Injection (SSTI) was discovered in the SEOmatic plugin before 3.1.4 for Craft CMS, because requests that don't match any elements incorrectly generate the canonicalUrl, and can lead to execution of Twig code.

    Source:0xB455
    Published:6 Aug 2018
    9.8
    Critical

    CVE-2018-14714

    Last Modified: 21 Nov 2024

    System command injection in appGet.cgi on ASUS RT-AC3200 version 3.0.0.4.382.50010 allows attackers to execute system commands via the "load_script" URL parameter.

    Published:13 May 2019
    9.8
    Critical

    CVE-2018-14699

    Last Modified: 21 Nov 2024

    System command injection in the /DroboAccess/enable_user endpoint in Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to execute system commands via the "username" URL parameter.

    Published:3 Dec 2018
    9.8
    Critical

    CVE-2018-14667

    Last Modified: 3 Nov 2025

    The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized objects via org.ajax4jsf.resource.UserResource$UriData.

    Published:6 Nov 2018
    6.6
    Medium

    CVE-2018-14665

    Last Modified: 11 Dec 2018

    A flaw was found in xorg-x11-server before 1.20.3. An incorrect permission check for -modulepath and -logfile options when starting Xorg. X server allows unprivileged users with the ability to log in to the system via physical console to escalate their privileges and run arbitrary code under root privileges.

    Source:0xdono
    Published:25 Oct 2018
    7.8
    High

    CVE-2018-14634

    Last Modified: 1 Oct 2018

    An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

    Source:Qualys Corporation
    Published:25 Sept 2018
    9.8
    Critical

    CVE-2018-14592

    Last Modified: 24 Sept 2018

    The CWJoomla CW Article Attachments PRO extension before 2.0.7 and CW Article Attachments FREE extension before 1.0.6 for Joomla! allow SQL Injection within download.php.

    Source:Haboob Team
    Published:20 Sept 2018
    8.8
    High

    CVE-2018-14575

    Last Modified: 15 Feb 2019

    Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.

    Source:0xB9
    Published:17 Mar 2019
    7.8
    High

    CVE-2018-14533

    Last Modified: 26 Jul 2018

    read_tmp and write_tmp in Inteno IOPSYS allow attackers to gain privileges after writing to /tmp/etc/smb.conf because /var is a symlink to /tmp.

    Source:neonsea
    Published:31 Jul 2018
    5.4
    Medium

    CVE-2018-14497

    Last Modified: 6 Sept 2018

    Tenda D152 ADSL routers allow XSS via a crafted SSID.

    Source:Sandip Dey
    Published:3 Aug 2018
    6.1
    Medium

    CVE-2018-14493

    Last Modified: 8 Aug 2018

    Cross-site scripting (XSS) vulnerability in the Groups Page in Open-Audit Community 2.2.6 allows remote attackers to inject arbitrary web script or HTML via the group name.

    Source:Ranjeet Jaiswal
    Published:25 Jul 2018