9.8
    Critical

    CVE-2018-14485

    Last Modified: 9 Jan 2019

    BlogEngine.NET 3.3 allows XXE attacks via the POST body to metaweblog.axd.

    Source:Netsparker
    Published:7 May 2019
    7.5
    High

    CVE-2018-14469

    Last Modified: 21 Nov 2024

    The IKEv1 parser in tcpdump before 4.9.3 has a buffer over-read in print-isakmp.c:ikev1_n_print().

    Published:2 Oct 2019
    9.8
    Critical

    CVE-2018-14442

    Last Modified: 21 Nov 2024

    Foxit Reader before 9.2 and PhantomPDF before 9.2 have a Use-After-Free that leads to Remote Code Execution, aka V-88f4smlocs.

    Published:20 Jul 2018
    9.8
    Critical

    CVE-2018-14418

    Last Modified: 23 Jul 2018

    In Msvod Cms v10, SQL Injection exists via an images/lists?cid= URI.

    Source:Hzllaga
    Published:19 Jul 2018
    9.8
    Critical

    CVE-2018-14417

    Last Modified: 27 Jul 2018

    A command injection vulnerability was found in the web administration console in SoftNAS Cloud before 4.0.3. In particular, the snserv script did not sanitize the 'recentVersion' parameter from the snserv endpoint, allowing an unauthenticated attacker to execute arbitrary commands with root permissions.

    Source:Core Security
    Published:3 Aug 2018
    6.1
    Medium

    CVE-2018-14392

    Last Modified: 19 Jul 2018

    The New Threads plugin before 1.2 for MyBB has XSS.

    Source:0xB9
    Published:19 Jul 2018
    7.5
    High

    CVE-2018-14336

    Last Modified: 20 Jul 2018

    TP-Link WR840N devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses.

    Source:Aniket Dinda
    Published:19 Jul 2018
    6.5
    Medium

    CVE-2018-14335

    Last Modified: 31 Jul 2018

    An issue was discovered in H2 1.4.197. Insecure handling of permissions in the backup function allows attackers to read sensitive files (outside of their permissions) via a symlink to a fake database file.

    Source:owodelta
    Published:23 Jul 2018
    9.8
    Critical

    CVE-2018-14328

    Last Modified: 27 Jul 2018

    Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for /dashboard/addplan, /dashboard/paywithcard/charge, /dashboard/withdrawal, or /privacy&terms, as demonstrated by reading database username, database password, database_name, and IP address fields, related to CVE-2018-12908.

    Source:Dhamotharan
    Published:23 Jul 2018
    7.8
    High

    CVE-2018-14327

    Last Modified: 27 Sept 2018

    The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Control) for the "Web Connecton\EE40" and "Web Connecton\EE40\BackgroundService" directories, which allows local users to gain privileges, as demonstrated by inserting a Trojan horse ServiceManager.exe file into the "Web Connecton\EE40\BackgroundService" directory.

    Source:Osanda Malith Jayathissa
    Published:26 Sept 2018
    9.8
    Critical

    CVE-2018-14324

    Last Modified: 21 Nov 2024

    The demo feature in Oracle GlassFish Open Source Edition 5.0 has TCP port 7676 open by default with a password of admin for the admin account. This allows remote attackers to obtain potentially sensitive information, perform database operations, or manipulate the demo via a JMX RMI session, aka a "jmx_rmi remote monitoring and control problem." NOTE: this is not an Oracle supported product.

    Published:16 Jul 2018
    7.5
    High

    CVE-2018-14083

    Last Modified: 21 Nov 2024

    LICA miniCMTS E8K(u/i/...) devices allow remote attackers to obtain sensitive information via a direct POST request for the inc/user.ini file, leading to discovery of a password hash.

    Published:25 Jul 2018
    9.8
    Critical

    CVE-2018-14064

    Last Modified: 16 Jul 2018

    The uc-http service 1.0.0 on VelotiSmart WiFi B-380 camera devices allows Directory Traversal, as demonstrated by /../../etc/passwd on TCP port 80.

    Source:Miguel Mendez Z
    Published:15 Jul 2018
    5.4
    Medium

    CVE-2018-14059

    Last Modified: 16 Aug 2018

    Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset Metadata, Quantity Value, and Static Routes functions.

    Source:SEC Consult
    Published:24 Aug 2018
    6.5
    Medium

    CVE-2018-14058

    Last Modified: 16 Aug 2018

    Pimcore before 5.3.0 allows SQL Injection via the REST web service API.

    Source:SEC Consult
    Published:17 Aug 2018
    8.8
    High

    CVE-2018-14057

    Last Modified: 16 Aug 2018

    Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / Roles" function.

    Source:SEC Consult
    Published:17 Aug 2018
    6.1
    Medium

    CVE-2018-14042

    Last Modified: 21 Nov 2024

    In Bootstrap before 4.1.2, XSS is possible in the data-container property of tooltip.

    Published:29 May 2018
    6.1
    Medium

    CVE-2018-14041

    Last Modified: 21 Nov 2024

    In Bootstrap before 4.1.2, XSS is possible in the data-target property of scrollspy.

    Published:29 May 2018
    6.1
    Medium

    CVE-2018-14040

    Last Modified: 21 Nov 2024

    In Bootstrap before 4.1.2, XSS is possible in the collapse data-parent attribute.

    Published:29 May 2018
    8.8
    High

    CVE-2018-14029

    Last Modified: 2 Aug 2018

    CSRF vulnerability in admin/user/edit in Creatiwity wityCMS 0.6.2 allows an attacker to take over a user account, as demonstrated by modifying the account's email field.

    Source:Porhai Eung
    Published:13 Jul 2018
    9.8
    Critical

    CVE-2018-14009

    Last Modified: 23 Mar 2021

    Codiad through 2.8.4 allows Remote Code Execution, a different vulnerability than CVE-2017-11366 and CVE-2017-15689.

    Source:WangYihang
    Published:12 Jul 2018
    8.8
    High

    CVE-2018-13989

    Last Modified: 13 Jul 2018

    Grundig Smart Inter@ctive TV 3.0 devices allow CSRF attacks via a POST request to TCP port 8085 containing a predictable ID value, as demonstrated by a /sendrcpackage?keyid=-2544&keysymbol=-4081 request to shut off the device.

    Source:t4rkd3vilz
    Published:11 Jul 2018
    9.8
    Critical

    CVE-2018-13981

    Last Modified: 13 Jul 2018

    The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated remote code execution due to a default component that permits arbitrary upload of PHP files, because the formmailer widget blocks .php files but not .php5 or .phtml files. This is related to /assets/php/formmailer/SendEmail.php and /assets/php/formmailer/functions.php.

    Source:SEC Consult
    Published:16 Jul 2018
    5.5
    Medium

    CVE-2018-13980

    Last Modified: 13 Jul 2018

    The websites that were built from Zeta Producer Desktop CMS before 14.2.1 are vulnerable to unauthenticated file disclosure if the plugin "filebrowser" is installed, because of assets/php/filebrowser/filebrowser.main.php?file=../ directory traversal.

    Source:SEC Consult
    Published:16 Jul 2018
    7.5
    High

    CVE-2018-13864

    Last Modified: 21 Nov 2024

    A directory traversal vulnerability has been found in the Assets controller in Play Framework 2.6.12 through 2.6.15 (fixed in 2.6.16) when running on Windows. It allows a remote attacker to download arbitrary files from the target server via specially crafted HTTP requests.

    Published:17 Jul 2018
    9.8
    Critical

    CVE-2018-13862

    Last Modified: 23 Jul 2018

    Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&attr=protectAccess&newValue=0" (a successful attack will allow attackers to login without authorization).

    Source:vulnc0d3
    Published:17 Jul 2018
    9.8
    Critical

    CVE-2018-13859

    Last Modified: 27 Jul 2018

    MusicCenter / Trivum Multiroom Setup Tool V8.76 - SNR 8604.26 - C4 Professional before V9.34 build 13381 - 12.07.18, allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&attr=protectAccess&newValue=0" (a successful attack will allow attackers to login without authorization).

    Source:vulnc0d3
    Published:17 Jul 2018
    6.1
    Medium

    CVE-2018-13849

    Last Modified: 11 Jul 2018

    edit_requests.php in yTakkar Instagram-clone through 2018-04-23 has XSS via an onmouseover payload because of an inadequate XSS protection mechanism based on preg_replace.

    Source:L0RD
    Published:10 Jul 2018
    4.8
    Medium

    CVE-2018-13832

    Last Modified: 20 Jul 2018

    Multiple Persistent cross-site scripting (XSS) issues in the Techotronic all-in-one-favicon (aka All In One Favicon) plugin 4.6 for WordPress allow remote attackers to inject arbitrary web script or HTML via Apple-Text, GIF-Text, ICO-Text, PNG-Text, or JPG-Text.

    Source:Javier Olmedo
    Published:16 Jul 2018
    9.8
    Critical

    CVE-2018-13797

    Last Modified: 21 Nov 2024

    The macaddress module before 0.2.9 for Node.js is prone to an arbitrary command injection flaw, due to allowing unsanitized input to an exec (rather than execFile) call.

    Published:11 Jun 2018
    9.1
    Critical

    CVE-2018-13784

    Last Modified: 18 Jul 2018

    PrestaShop before 1.6.1.20 and 1.7.x before 1.7.3.4 mishandles cookie encryption in Cookie.php, Rinjdael.php, and Blowfish.php.

    Source:Charles Fol
    Published:9 Jul 2018
    5.5
    Medium

    CVE-2018-13458

    Last Modified: 25 Jul 2018

    qh_core in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

    Source:Fakhri Zulkifli
    Published:12 Jul 2018
    5.5
    Medium

    CVE-2018-13457

    Last Modified: 25 Jul 2018

    qh_echo in Nagios Core 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attackers to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

    Source:Fakhri Zulkifli
    Published:12 Jul 2018
    5.5
    Medium

    CVE-2018-13441

    Last Modified: 25 Jul 2018

    qh_help in Nagios Core version 4.4.1 and earlier is prone to a NULL pointer dereference vulnerability, which allows attacker to cause a local denial-of-service condition by sending a crafted payload to the listening UNIX socket.

    Source:Fakhri Zulkifli
    Published:12 Jul 2018
    9.8
    Critical

    CVE-2018-13417

    Last Modified: 3 Aug 2018

    In Vuze Bittorrent Client 5.7.6.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Vuze, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

    Source:Chris Moberly
    Published:13 Aug 2018
    9.8
    Critical

    CVE-2018-13416

    Last Modified: 2 Aug 2018

    In Universal Media Server (UMS) 7.1.0, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running UMS, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

    Source:Chris Moberly
    Published:3 Aug 2018
    9.8
    Critical

    CVE-2018-13415

    Last Modified: 3 Aug 2018

    In Plex Media Server 1.13.2.5154, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnerability to: (1) Access arbitrary files from the filesystem with the same permission as the user account running Plex, (2) Initiate SMB connections to capture a NetNTLM challenge/response and crack to cleartext password, or (3) Initiate SMB connections to relay a NetNTLM challenge/response and achieve Remote Command Execution in Windows domains.

    Source:Chris Moberly
    Published:13 Aug 2018
    9.8
    Critical

    CVE-2018-13410

    Last Modified: 21 Nov 2024

    Info-ZIP Zip 3.0, when the -T and -TT command-line options are used, allows attackers to cause a denial of service (invalid free and application crash) or possibly have unspecified other impact because of an off-by-one error. NOTE: it is unclear whether there are realistic scenarios in which an untrusted party controls the -TT value, given that the entire purpose of -TT is execution of arbitrary commands

    Published:6 Jul 2018
    7.8
    High

    CVE-2018-13405

    Last Modified: 17 Jul 2018

    The inode_init_owner function in fs/inode.c in the Linux kernel through 3.16 allows local users to create files with an unintended group ownership, in a scenario where a directory is SGID to a certain group and is writable by a user who is not a member of that group. Here, the non-member can trigger creation of a plain file whose group ownership is that group. The intended behavior was that the non-member can trigger creation of a directory (but not a plain file) whose group ownership is that group. The non-member can escalate privileges by making the plain file executable and SGID.

    Source:Google Security Research
    Published:5 Jul 2018
    9.1
    Critical

    CVE-2018-13382

    Last Modified: 19 Nov 2020

    An Improper Authorization vulnerability in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.0 to 5.6.8 and 5.4.1 to 5.4.10 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to modify the password of an SSL VPN web portal user via specially crafted HTTP requests

    Source:Ricardo Longatto
    Published:4 Jun 2019
    9.1
    Critical

    CVE-2018-13379

    Last Modified: 30 Apr 2021

    An Improper Limitation of a Pathname to a Restricted Directory ("Path Traversal") in Fortinet FortiOS 6.0.0 to 6.0.4, 5.6.3 to 5.6.7 and 5.4.6 to 5.4.12 and FortiProxy 2.0.0, 1.2.0 to 1.2.8, 1.1.0 to 1.1.6, 1.0.0 to 1.0.7 under SSL VPN web portal allows an unauthenticated attacker to download system files via special crafted HTTP resource requests.

    Source:Carlos E. Vieira
    Published:4 Jun 2019
    4.3
    Medium

    CVE-2018-13374

    Last Modified: 30 Apr 2021

    A Improper Access Control in Fortinet FortiOS 6.0.2, 5.6.7 and before, FortiADC 6.1.0, 6.0.0 to 6.0.1, 5.4.0 to 5.4.4 allows attacker to obtain the LDAP server login credentials configured in FortiGate via pointing a LDAP server connectivity test request to a rogue LDAP server instead of the configured one.

    Source:Julio Ureña
    Published:22 Jan 2019
    8.8
    High

    CVE-2018-13341

    Last Modified: 21 Nov 2024

    Crestron TSW-X60 all versions prior to 2.001.0037.001 and MC3 all versions prior to 1.502.0047.00, The passwords for special sudo accounts may be calculated using information accessible to those with regular user privileges. Attackers could decipher these passwords, which may allow them to execute hidden API calls and escape the CTP console sandbox environment with elevated privileges.

    Published:10 Aug 2018
    6.1
    Medium

    CVE-2018-13257

    Last Modified: 21 Nov 2024

    The bb-auth-provider-cas authentication module within Blackboard Learn 2018-07-02 is susceptible to HTTP host header spoofing during Central Authentication Service (CAS) service ticket validation, enabling a phishing attack from the CAS server login page.

    Published:18 Nov 2019
    6.1
    Medium

    CVE-2018-13134

    Last Modified: 12 Dec 2018

    TP-Link Archer C1200 1.13 Build 2018/01/24 rel.52299 EU devices have XSS via the PATH_INFO to the /webpages/data URI.

    Source:Usman Saeed
    Published:4 Jul 2018
    7.5
    High

    CVE-2018-13110

    Last Modified: 5 Jul 2018

    All ADB broadband gateways / routers based on the Epicentro platform are affected by a privilege escalation vulnerability where attackers can gain access to the command line interface (CLI) if previously disabled by the ISP, escalate their privileges, and perform further attacks.

    Source:SEC Consult
    Published:6 Jul 2018
    7.5
    High

    CVE-2018-13109

    Last Modified: 5 Jul 2018

    All ADB broadband gateways / routers based on the Epicentro platform are affected by an authorization bypass vulnerability where attackers are able to access and manipulate settings within the web interface that are forbidden to end users (e.g., by the ISP). An attacker would be able to enable the TELNET server or other settings as well.

    Source:SEC Consult
    Published:6 Jul 2018
    7.8
    High

    CVE-2018-13108

    Last Modified: 5 Jul 2018

    All ADB broadband gateways / routers based on the Epicentro platform are affected by a local root jailbreak vulnerability where attackers are able to gain root access on the device, and extract further information such as sensitive configuration data of the ISP (e.g., VoIP credentials) or attack the internal network of the ISP.

    Source:SEC Consult
    Published:6 Jul 2018
    9.8
    Critical

    CVE-2018-13045

    Last Modified: 19 Dec 2018

    SQL injection vulnerability in the "Bazar" page in Yeswiki Cercopitheque 2018-06-19-1 and earlier allows attackers to execute arbitrary SQL commands via the "id" parameter.

    Source:Mickael BROUTY
    Published:2 Jan 2019
    5.9
    Medium

    CVE-2018-13042

    Last Modified: 15 Jan 2019

    The 1Password application 6.8 for Android is affected by a Denial Of Service vulnerability. By starting the activity com.agilebits.onepassword.filling.openyolo.OpenYoloDeleteActivity or com.agilebits.onepassword.filling.openyolo.OpenYoloRetrieveActivity from an external application (since they are exported), it is possible to crash the 1Password instance.

    Source:Valerio Brussani
    Published:5 Oct 2018