8.8
    High

    CVE-2018-13032

    Last Modified: 26 Mar 2019

    ECESSA ShieldLink SL175EHQ 10.7.4 devices have CSRF to add superuser accounts via the cgi-bin/pl_web.cgi/util_configlogin_act URI.

    Source:LiquidWorm
    Published:1 Jul 2018
    5.4
    Medium

    CVE-2018-12981

    Last Modified: 13 Jul 2018

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability can be exploited by authenticated and unauthenticated users by sending special crafted requests to the web server allowing injecting code within the WBM. The code will be rendered and/or executed in the browser of the user's browser.

    Source:SEC Consult
    Published:12 Jul 2018
    8.8
    High

    CVE-2018-12980

    Last Modified: 13 Jul 2018

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. The vulnerability allows an authenticated user to upload arbitrary files to the file system with the permissions of the web server.

    Source:SEC Consult
    Published:12 Jul 2018
    6.5
    Medium

    CVE-2018-12979

    Last Modified: 13 Jul 2018

    An issue was discovered on WAGO e!DISPLAY 762-3000 through 762-3003 devices with firmware before FW 02. Weak permissions allow an authenticated user to overwrite critical files by abusing the unrestricted file upload in the WBM.

    Source:SEC Consult
    Published:12 Jul 2018
    8.6
    High

    CVE-2018-12938

    Last Modified: 9 Nov 2018

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2017-17833. Reason: This candidate is a duplicate of CVE-2017-17833. Notes: All CVE users should reference CVE-2017-17833 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage

    Source:Magnus Klaaborg Stubman
    Published:28 Jun 2018
    7.2
    High

    CVE-2018-12912

    Last Modified: 18 Sept 2018

    An issue wan discovered in admin\controllers\database.php in HongCMS 3.0.0. There is a SQL Injection vulnerability via an admin/index.php/database/operate?dbaction=emptytable&tablename= URI.

    Source:Hzllaga
    Published:27 Jun 2018
    9.8
    Critical

    CVE-2018-12908

    Last Modified: 4 Jul 2018

    Brynamics "Online Trade - Online trading and cryptocurrency investment system" allows remote attackers to obtain sensitive information via a direct request for the /dashboard/deposit URI, as demonstrated by discovering database credentials.

    Source:L0RD
    Published:27 Jun 2018
    4.9
    Medium

    CVE-2018-12904

    Last Modified: 27 Jun 2018

    In arch/x86/kvm/vmx.c in the Linux kernel before 4.17.2, when nested virtualization is used, local attackers could cause L1 KVM guests to VMEXIT, potentially allowing privilege escalations and denial of service attacks due to lack of checking of CPL.

    Source:Google Security Research
    Published:12 Jun 2018
    7.8
    High

    CVE-2018-12897

    Last Modified: 16 Jul 2019

    SolarWinds DameWare Mini Remote Control before 12.1 has a Buffer Overflow.

    Source:Xavi Beltran
    Published:7 Sept 2018
    8.8
    High

    CVE-2018-12895

    Last Modified: 21 Nov 2024

    WordPress through 4.9.6 allows Author users to execute arbitrary code by leveraging directory traversal in the wp-admin/post.php thumb parameter, which is passed to the PHP unlink function and can delete the wp-config.php file. This is related to missing filename validation in the wp-includes/post.php wp_delete_attachment function. The attacker must have capabilities for files and posts that are normally available only to the Author, Editor, and Administrator roles. The attack methodology is to delete wp-config.php and then launch a new installation process to increase the attacker's privileges.

    Published:26 Jun 2018
    7.5
    High

    CVE-2018-12827

    Last Modified: 27 Aug 2018

    Adobe Flash Player 30.0.0.134 and earlier have an out-of-bounds read vulnerability. Successful exploitation could lead to information disclosure.

    Source:Google Security Research
    Published:14 Aug 2018
    9.8
    Critical

    CVE-2018-12798

    Last Modified: 21 Nov 2024

    Adobe Acrobat and Reader 2018.011.20040 and earlier, 2017.011.30080 and earlier, and 2015.006.30418 and earlier versions have a Heap Overflow vulnerability. Successful exploitation could lead to arbitrary code execution in the context of the current user.

    Published:20 Jul 2018
    8.8
    High

    CVE-2018-12739

    Last Modified: 28 Jun 2018

    In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.

    Source:bay0net
    Published:5 Jul 2018
    8
    High

    CVE-2018-12710

    Last Modified: 30 Aug 2018

    An issue was discovered on D-Link DIR-601 2.02NA devices. Being local to the network and having only "User" account (which is a low privilege account) access, an attacker can intercept the response from a POST request to obtain "Admin" rights due to the admin password being displayed in XML.

    Source:Kevin Randall
    Published:29 Aug 2018
    9.8
    Critical

    CVE-2018-12706

    Last Modified: 25 Jun 2018

    DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.

    Source:Adipta Basu
    Published:24 Jun 2018
    6.1
    Medium

    CVE-2018-12705

    Last Modified: 25 Jun 2018

    DIGISOL DG-BR4000NG devices have XSS via the SSID (it is validated only on the client side).

    Source:Adipta Basu
    Published:24 Jun 2018
    6.1
    Medium

    CVE-2018-12653

    Last Modified: 12 Nov 2019

    A Reflected Cross Site Scripting (XSS) vulnerability exists in Adrenalin HRMS 5.4.0. An attacker can input malicious JavaScript code in /RPT/SSRSDynamicEditReports.aspx via 'ReportId' parameter.

    Source:Cy83rl0gger
    Published:25 Mar 2019
    6.1
    Medium

    CVE-2018-12650

    Last Modified: 12 Nov 2019

    Adrenalin HRMS version 5.4.0 contains a Reflected Cross Site Scripting (XSS) vulnerability in the ApplicationtEmployeeSearch page via 'prntDDLCntrlName' and 'prntFrmName'.

    Source:Cy83rl0gger
    Published:24 Oct 2018
    7.2
    High

    CVE-2018-12636

    Last Modified: 25 Jun 2018

    The iThemes Security (better-wp-security) plugin before 7.0.3 for WordPress allows SQL Injection (by attackers with Admin privileges) via the logs page.

    Source:Çlirim Emini
    Published:22 Jun 2018
    9.8
    Critical

    CVE-2018-12634

    Last Modified: 12 Sept 2018

    CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.

    Source:SadFud
    Published:22 Jun 2018
    6.3
    Medium

    CVE-2018-12633

    Last Modified: 21 Nov 2024

    An issue was discovered in the Linux kernel through 4.17.2. vbg_misc_device_ioctl() in drivers/virt/vboxguest/vboxguest_linux.c reads the same user data twice with copy_from_user. The header part of the user data is double-fetched, and a malicious user thread can tamper with the critical variables (hdr.size_in and hdr.size_out) in the header between the two fetches because of a race condition, leading to severe kernel errors, such as buffer over-accesses. This bug can cause a local denial of service and information leakage.

    Published:8 May 2018
    7.5
    High

    CVE-2018-12617

    Last Modified: 22 Jun 2018

    qmp_guest_file_read in qga/commands-posix.c and qga/commands-win32.c in qemu-ga (aka QEMU Guest Agent) in QEMU 2.12.50 has an integer overflow causing a g_malloc0() call to trigger a segmentation fault when trying to allocate a large memory chunk. The vulnerability can be exploited by sending a crafted QMP command (including guest-file-read with a large count value) to the agent via the listening socket.

    Source:Fakhri Zulkifli
    Published:21 Jun 2018
    8.8
    High

    CVE-2018-12613

    Last Modified: 13 Jul 2018

    An issue was discovered in phpMyAdmin 4.8.x before 4.8.2, in which an attacker can include (view and potentially execute) files on the server. The vulnerability comes from a portion of code where pages are redirected and loaded within phpMyAdmin, and an improper test for whitelisted pages. An attacker must be authenticated, except in the "$cfg['AllowArbitraryServer'] = true" case (where an attacker can specify any host he/she is already in control of, and execute arbitrary code on phpMyAdmin) and the "$cfg['ServerDefault'] = 0" case (which bypasses the login requirement and runs the vulnerable code without any authentication).

    Source:Metasploit
    Published:21 Jun 2018
    7.5
    High

    CVE-2018-12604

    Last Modified: 22 Jun 2018

    GreenCMS 2.3.0603 allows remote attackers to obtain sensitive information via a direct request for Data/Log/year_month_day.log.

    Source:vr_system
    Published:20 Jun 2018
    8.8
    High

    CVE-2018-12603

    Last Modified: 22 Jun 2018

    Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the s parameter, a related issue to CVE-2018-12114.

    Source:bay0net
    Published:25 Jun 2018
    8.8
    High

    CVE-2018-12602

    Last Modified: 22 Jun 2018

    A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.

    Source:bay0net
    Published:25 Jun 2018
    Unknown

    CVE-2018-12598

    https://github.com/alt3kx/CVE-2018-12598

    Unknown

    CVE-2018-12597

    https://github.com/alt3kx/CVE-2018-12597

    9.8
    Critical

    CVE-2018-12596

    Last Modified: 10 Oct 2018

    Episerver Ektron CMS before 9.0 SP3 Site CU 31, 9.1 before SP3 Site CU 45, or 9.2 before SP2 Site CU 22 allows remote attackers to call aspx pages via the "activateuser.aspx" page, even if a page is located under the /WorkArea/ path, which is forbidden (normally available exclusively for local admins).

    Source:alt3kx
    Published:10 Oct 2018
    7.8
    High

    CVE-2018-12589

    Last Modified: 6 Jul 2018

    Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory.

    Source:hyp3rlinx
    Published:28 Jun 2018
    9.8
    Critical

    CVE-2018-12584

    Last Modified: 9 Aug 2018

    The ConnectionBase::preparseNewBytes function in resip/stack/ConnectionBase.cxx in reSIProcate through 1.10.2 allows remote attackers to cause a denial of service (buffer overflow) or possibly execute arbitrary code when TLS communication is enabled.

    Source:Joachim De Zutter
    Published:16 Jul 2018
    9.8
    Critical

    CVE-2018-12544

    Last Modified: 21 Nov 2024

    In version from 3.5.Beta1 to 3.5.3 of Eclipse Vert.x, the OpenAPI XML type validator creates XML parsers without taking appropriate defense against XML attacks. This mechanism is exclusively when the developer uses the Eclipse Vert.x OpenAPI XML type validator to validate a provided schema.

    Published:27 Sept 2018
    9.8
    Critical

    CVE-2018-12542

    Last Modified: 21 Nov 2024

    In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the StaticHandler uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize '\' (forward slashes) sequences that can resolve to a location that is outside of that directory when running on Windows Operating Systems.

    Published:10 Oct 2018
    6.5
    Medium

    CVE-2018-12541

    Last Modified: 21 Nov 2024

    In version from 3.0.0 to 3.5.3 of Eclipse Vert.x, the WebSocket HTTP upgrade implementation buffers the full http request before doing the handshake, holding the entire request body in memory. There should be a reasonnable limit (8192 bytes) above which the WebSocket gets an HTTP response with the 413 status code and the connection gets closed.

    Published:3 Oct 2018
    8.8
    High

    CVE-2018-12540

    Last Modified: 21 Nov 2024

    In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued tokens which are not expired yet.

    Published:12 Jul 2018
    5.3
    Medium

    CVE-2018-12537

    Last Modified: 21 Nov 2024

    In Eclipse Vert.x version 3.0 to 3.5.1, the HttpServer response headers and HttpClient request headers do not filter carriage return and line feed characters from the header value. This allow unfiltered values to inject a new header in the client request or server response.

    Published:13 Jun 2018
    9.8
    Critical

    CVE-2018-12533

    Last Modified: 21 Nov 2024

    JBoss RichFaces 3.1.0 through 3.3.4 allows unauthenticated remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via a /DATA/ substring in a path with an org.richfaces.renderkit.html.Paint2DResource$ImageData object, aka RF-14310.

    Published:30 May 2018
    5.3
    Medium

    CVE-2018-12525

    Last Modified: 20 Jun 2018

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.

    Source:ManhNho
    Published:18 Jun 2018
    5.3
    Medium

    CVE-2018-12524

    Last Modified: 20 Jun 2018

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.

    Source:ManhNho
    Published:18 Jun 2018
    5.3
    Medium

    CVE-2018-12523

    Last Modified: 20 Jun 2018

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.

    Source:ManhNho
    Published:18 Jun 2018
    5.3
    Medium

    CVE-2018-12522

    Last Modified: 20 Jun 2018

    An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.

    Source:ManhNho
    Published:18 Jun 2018
    8.1
    High

    CVE-2018-12520

    Last Modified: 3 Jul 2018

    An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated for active user sessions. An attacker with foreknowledge of the operating system and standard library in use by the host running the service and the username of the user whose session they're targeting can abuse the deterministic random number generation in order to hijack the user's session, thus escalating their access.

    Source:Ioannis Profetis
    Published:5 Jul 2018
    8.8
    High

    CVE-2018-12519

    Last Modified: 4 Jul 2018

    An issue was discovered in ShopNx through 2017-11-17. The vulnerability allows a remote attacker to upload any malicious file to a Node.js application. An attacker can upload a malicious HTML file that contains a JavaScript payload to steal a user's credentials.

    Source:L0RD
    Published:19 Jun 2018
    9.1
    Critical

    CVE-2018-12465

    Last Modified: 25 Jul 2018

    An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrary OS commands on the SMG server. This can be exploited in conjunction with CVE-2018-12464 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that used GWAVA product name (i.e. GWAVA 6.5).

    Source:Mehmet Ince
    Published:29 Jun 2018
    10
    Critical

    CVE-2018-12464

    Last Modified: 25 Jul 2018

    A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements against the database. This can be exploited to create an administrative account and used in conjunction with CVE-2018-12465 to achieve unauthenticated remote code execution. Affects Micro Focus Secure Messaging Gateway versions prior to 471. It does not affect previous versions of the product that use the GWAVA product name (i.e. GWAVA 6.5).

    Source:Mehmet Ince
    Published:29 Jun 2018
    9.8
    Critical

    CVE-2018-12463

    Last Modified: 16 Jul 2018

    An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.

    Source:alt3kx
    Published:12 Jul 2018
    7.5
    High

    CVE-2018-12453

    Last Modified: 20 Jun 2018

    Type confusion in the xgroupCommand function in t_stream.c in redis-server in Redis before 5.0 allows remote attackers to cause denial-of-service via an XGROUP command in which the key is not a stream.

    Source:Fakhri Zulkifli
    Published:10 Jun 2018
    9.8
    Critical

    CVE-2018-12421

    Last Modified: 21 Nov 2024

    LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishandled and the PHP data type is not constrained to be a string.

    Published:14 Jun 2018
    5.5
    Medium

    CVE-2018-12418

    Last Modified: 21 Nov 2024

    Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.

    Published:30 May 2018
    8.1
    High

    CVE-2018-12386

    Last Modified: 25 Nov 2025

    A vulnerability in register allocation in JavaScript can lead to type confusion, allowing for an arbitrary read and write. This leads to remote code execution inside the sandboxed content process when triggered. This vulnerability affects Firefox ESR < 60.2.2 and Firefox < 62.0.3.

    Published:2 Oct 2018