7.8
    High

    CVE-2018-11526

    Last Modified: 25 Jun 2018

    The plugin "WordPress Comments Import & Export" for WordPress (v2.0.4 and before) is vulnerable to CSV Injection.

    Source:Bhushan B. Patil
    Published:19 Jun 2018
    7.8
    High

    CVE-2018-11525

    Last Modified: 25 Jun 2018

    The plugin "Advanced Order Export For WooCommerce" for WordPress (v1.5.4 and before) is vulnerable to CSV Injection.

    Source:Bhushan B. Patil
    Published:19 Jun 2018
    9.8
    Critical

    CVE-2018-11523

    Last Modified: 29 May 2018

    upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files.

    Source:M3@Pandas
    Published:29 May 2018
    6.1
    Medium

    CVE-2018-11522

    Last Modified: 30 May 2018

    Yosoro 1.0.4 has stored XSS.

    Source:Carlo Pelliccioni
    Published:1 Jun 2018
    5.3
    Medium

    CVE-2018-11517

    Last Modified: 21 Nov 2024

    mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.

    Published:28 May 2018
    4.8
    Medium

    CVE-2018-11512

    Last Modified: 2 Aug 2018

    Stored cross-site scripting (XSS) vulnerability in the "Website's name" field found in the "Settings" page under the "General" menu in Creatiwity wityCMS 0.6.1 allows remote attackers to inject arbitrary web script or HTML via a crafted website name by doing an authenticated POST HTTP request to admin/settings/general.

    Source:Nathu Nandwani
    Published:28 May 2018
    9.8
    Critical

    CVE-2018-11511

    Last Modified: 20 Nov 2018

    The tree list functionality in the photo gallery application in ASUSTOR ADM 3.1.0.RFQ3 has a SQL injection vulnerability that affects the 'album_id' or 'scope' parameter via a photo-gallery/api/album/tree_lists/ URI.

    Source:Kyle Lovett
    Published:16 Aug 2018
    9.8
    Critical

    CVE-2018-11510

    Last Modified: 20 Nov 2018

    The ASUSTOR ADM 3.1.0.RFQ3 NAS portal suffers from an unauthenticated remote code execution vulnerability in the portal/apis/aggrecate_js.cgi file by embedding OS commands in the 'script' parameter.

    Source:Kyle Lovett
    Published:28 Jun 2018
    9.8
    Critical

    CVE-2018-11509

    Last Modified: 20 Nov 2018

    ASUSTOR ADM 3.1.0.RFQ3 uses the same default root:admin username and password as it does for the NAS itself for applications that are installed from the online repository. This may allow an attacker to login and upload a webshell.

    Source:Kyle Lovett
    Published:16 Aug 2018
    5.5
    Medium

    CVE-2018-11508

    Last Modified: 21 Jan 2019

    The compat_get_timex function in kernel/compat.c in the Linux kernel before 4.16.9 allows local users to obtain sensitive information from kernel memory via adjtimex.

    Source:wally0813
    Published:11 May 2018
    7.5
    High

    CVE-2018-11505

    Last Modified: 27 May 2018

    The Werewolf Online application 0.8.8 for Android allows attackers to discover the Firebase token by reading logcat output.

    Source:ManhNho
    Published:26 May 2018
    6.5
    Medium

    CVE-2018-11502

    Last Modified: 27 Aug 2018

    An issue was discovered in the Moderator Log Notes plugin 1.1 for MyBB. It allows moderators to save notes and display them in a list in the modCP. An attacker can remotely delete all mod notes and mod note logs in the modCP and ACP via CSRF.

    Source:0xB9
    Published:24 Aug 2018
    7.5
    High

    CVE-2018-11492

    Last Modified: 17 Apr 2019

    ASUS HG100 devices allow denial of service via an IPv4 packet flood.

    Source:YinT Wang
    Published:10 Aug 2018
    7.8
    High

    CVE-2018-11479

    Last Modified: 7 Feb 2020

    The VPN component in Windscribe 1.81 uses the OpenVPN client for connections. Also, it creates a WindScribeService.exe system process that establishes a \\.\pipe\WindscribeService named pipe endpoint that allows the Windscribe VPN process to connect and execute an OpenVPN process or other processes (like taskkill, etc.). There is no validation of the program name before constructing the lpCommandLine argument for a CreateProcess call. An attacker can run any malicious process with SYSTEM privileges through this named pipe.

    Source:Metasploit
    Published:25 May 2018
    6.1
    Medium

    CVE-2018-11450

    Last Modified: 21 Nov 2024

    A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3 and newer are not affected.

    Published:9 Jul 2018
    8.8
    High

    CVE-2018-11445

    Last Modified: 15 Jun 2018

    A CSRF issue was discovered on the User Add/System Settings Page (system-settings-user-new2.php) in EasyService Billing 1.0. A User can be added with the Admin role.

    Source:Divya Jain
    Published:25 May 2018
    9.8
    Critical

    CVE-2018-11444

    Last Modified: 26 May 2018

    A SQL Injection issue was observed in the parameter "q" in jobcard-ongoing.php in EasyService Billing 1.0.

    Source:Divya Jain
    Published:25 May 2018
    6.1
    Medium

    CVE-2018-11443

    Last Modified: 26 May 2018

    The parameter q is affected by Cross-site Scripting in jobcard-ongoing.php in EasyService Billing 1.0.

    Source:Divya Jain
    Published:25 May 2018
    8.8
    High

    CVE-2018-11442

    Last Modified: 15 Jun 2018

    A CSRF issue was discovered in EasyService Billing 1.0, which was triggered via a quotation-new3-new2.php?add=true&id= URI, as demonstrated by adding a new quotation.

    Source:Divya Jain
    Published:25 May 2018
    6.1
    Medium

    CVE-2018-11415

    Last Modified: 25 May 2018

    SAP Internet Transaction Server (ITS) 6200.X.X has Reflected Cross Site Scripting (XSS) via certain wgate URIs. NOTE: the vendor has reportedly indicated that there will not be any further releases of this product.

    Source:J. Carrillo Lencina
    Published:24 May 2018
    5.9
    Medium

    CVE-2018-11412

    Last Modified: 5 Jun 2018

    In the Linux kernel 4.13 through 4.16.11, ext4_read_inline_data() in fs/ext4/inline.c performs a memcpy with an untrusted length value in certain circumstances involving a crafted filesystem that stores the system.data extended attribute value in a dedicated inode.

    Source:Google Security Research
    Published:22 May 2018
    5.3
    Medium

    CVE-2018-11409

    Last Modified: 8 Jun 2018

    Splunk through 7.0.1 allows information disclosure by appending __raw/services/server/info/server-info?output_mode=json to a query, as demonstrated by discovering a license key.

    Source:KoF2002
    Published:8 Jun 2018
    6.1
    Medium

    CVE-2018-11404

    Last Modified: 28 May 2018

    DomainMod v4.09.03 has XSS via the assets/edit/ssl-provider-account.php sslpaid parameter.

    Source:longer
    Published:24 May 2018
    5.4
    Medium

    CVE-2018-11403

    Last Modified: 28 May 2018

    DomainMod v4.09.03 has XSS via the assets/edit/account-owner.php oid parameter.

    Source:longer
    Published:24 May 2018
    6.1
    Medium

    CVE-2018-11339

    Last Modified: 22 May 2018

    An XSS issue was discovered in Frappe ERPNext v11.x.x-develop b1036e5 via a comment.

    Source:Veerababu Penugonda
    Published:22 May 2018
    4.8
    Medium

    CVE-2018-11332

    Last Modified: 27 May 2018

    Stored cross-site scripting (XSS) vulnerability in the "Site Name" field found in the "site" tab under configurations in ClipperCMS 1.3.3 allows remote attackers to inject arbitrary web script or HTML via a crafted site name to the manager/processors/save_settings.processor.php file.

    Source:Nathu Nandwani
    Published:24 May 2018
    6.5
    Medium

    CVE-2018-11321

    Last Modified: 21 Nov 2024

    An issue was discovered in com_fields in Joomla! Core before 3.8.8. Inadequate filtering allows users authorised to create custom fields to manipulate the filtering options and inject an unvalidated option.

    Published:22 May 2018
    9.1
    Critical

    CVE-2018-11311

    Last Modified: 25 Jun 2020

    A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.

    Source:Emre ÖVÜNÇ
    Published:20 May 2018
    9.8
    Critical

    CVE-2018-11307

    Last Modified: 21 Nov 2024

    An issue was discovered in FasterXML jackson-databind 2.0.0 through 2.9.5. Use of Jackson default typing along with a gadget class from iBatis allows exfiltration of content. Fixed in 2.7.9.4, 2.8.11.2, and 2.9.6.

    Published:10 May 2018
    6.5
    Medium

    CVE-2018-11242

    Last Modified: 22 May 2018

    An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as demonstrated by data/com.makemytrip/databases and data/com.makemytrip/Cache SQLite database files.

    Source:Divya Jain
    Published:20 May 2018
    7.8
    High

    CVE-2018-11235

    Last Modified: 21 Nov 2024

    In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project can execute an arbitrary script on a machine that runs "git clone --recurse-submodules" because submodule "names" are obtained from this file, and then appended to $GIT_DIR/modules, leading to directory traversal with "../" in a name. Finally, post-checkout hooks from a submodule are executed, bypassing the intended design in which hooks are not obtained from a remote server.

    Published:30 May 2018
    8.8
    High

    CVE-2018-11220

    Last Modified: 27 May 2018

    Bitmain Antminer D3, L3+, and S9 devices allow Remote Command Execution via the system restore function.

    Source:CorryL
    Published:31 May 2018
    9.8
    Critical

    CVE-2018-11138

    Last Modified: 27 Jun 2018

    The '/common/download_agent_installer.php' script in the Quest KACE System Management Appliance 8.0.318 is accessible by anonymous users and can be abused to execute arbitrary commands on the system.

    Source:Metasploit
    Published:31 May 2018
    5.4
    Medium

    CVE-2018-11124

    Last Modified: 18 Jul 2018

    Cross-site scripting (XSS) vulnerability in Attributes functionality in Open-AudIT Community edition before 2.2.2 allows remote attackers to inject arbitrary web script or HTML via a crafted attribute name of an Attribute.

    Source:Ranjeet Jaiswal
    Published:6 Jul 2018
    9.8
    Critical

    CVE-2018-11094

    Last Modified: 17 May 2018

    An issue was discovered on Intelbras NCLOUD 300 1.0 devices. /cgi-bin/ExportSettings.sh, /goform/updateWPS, /goform/RebootSystem, and /goform/vpnBasicSettings do not require authentication. For example, when an HTTP POST request is made to /cgi-bin/ExportSettings.sh, the username, password, and other details are retrieved.

    Source:Pedro Aguiar
    Published:15 May 2018
    7.8
    High

    CVE-2018-11034

    Last Modified: 14 May 2018

    In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCTL 0x8000200D.

    Source:anhkgg
    Published:14 May 2018
    Unknown

    CVE-2018-10993

    https://github.com/nicolastsk/cve-2018-10993

    9.8
    Critical

    CVE-2018-10969

    Last Modified: 12 Jun 2018

    SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.

    Source:Manuel García Cárdenas
    Published:17 Jun 2018
    7.5
    High

    CVE-2018-10956

    Last Modified: 17 Nov 2018

    IPConfigure Orchid Core VMS 2.0.5 allows Directory Traversal.

    Source:Nettitude
    Published:25 Jun 2018
    5.3
    Medium

    CVE-2018-10949

    Last Modified: 21 Nov 2024

    mailboxd in Zimbra Collaboration Suite 8.8 before 8.8.8; 8.7 before 8.7.11.Patch3; and 8.6 allows Account Enumeration by leveraging a Discrepancy between the "HTTP 404 - account is not active" and "HTTP 401 - must authenticate" errors.

    Published:10 May 2018
    8.1
    High

    CVE-2018-10936

    Last Modified: 21 Nov 2024

    A weakness was found in postgresql-jdbc before version 42.2.5. It was possible to provide an SSL Factory and not check the host name if a host name verifier was not provided to the driver. This could lead to a condition where a man-in-the-middle attacker could masquerade as a trusted server by providing a certificate for the wrong host, as long as it was signed by a trusted CA.

    Published:27 Aug 2018
    9.1
    Critical

    CVE-2018-10933

    Last Modified: 19 Oct 2018

    A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unauthorized access.

    Source:Dayanç Soyadlı
    Published:16 Oct 2018
    6.8
    Medium

    CVE-2018-10920

    Last Modified: 21 Nov 2024

    Improper input validation bug in DNS resolver component of Knot Resolver before 2.4.1 allows remote attacker to poison cache.

    Published:2 Aug 2018
    5.3
    Medium

    CVE-2018-10906

    Last Modified: 30 Jul 2018

    In fuse before versions 2.9.8 and 3.x before 3.2.5, fusermount is vulnerable to a restriction bypass when SELinux is active. This allows non-root users to mount a FUSE file system with the 'allow_other' mount option regardless of whether 'user_allow_other' is set in the fuse configuration. An attacker may use this flaw to mount a FUSE file system, accessible by other users, and trick them into accessing files on that file system, possibly causing Denial of Service or other unspecified effects.

    Source:Google Security Research
    Published:24 Jul 2018
    7.8
    High

    CVE-2018-10900

    Last Modified: 8 Sept 2018

    Network Manager VPNC plugin (aka networkmanager-vpnc) before version 1.2.6 is vulnerable to a privilege escalation attack. A new line character can be used to inject a Password helper parameter into the configuration data passed to VPNC, allowing an attacker to execute arbitrary commands as root.

    Source:Metasploit
    Published:26 Jul 2018
    5.5
    Medium

    CVE-2018-10832

    Last Modified: 10 May 2018

    ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.

    Source:Trent Gordon
    Published:11 May 2018
    7.8
    High

    CVE-2018-10830

    Last Modified: 22 Jun 2018

    In 2345 Security Guard 3.7, the driver file (2345BdPcSafe.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x002220e0.

    Source:anhkgg
    Published:9 May 2018
    5.5
    Medium

    CVE-2018-10828

    Last Modified: 10 May 2018

    An issue was discovered in Alps Pointing-device Driver 10.1.101.207. ApMsgFwd.exe allows the current user to map and write to the "ApMsgFwd File Mapping Object" section. ApMsgFwd.exe uses the data written to this section as arguments to functions. This causes a denial of service condition when invalid pointers are written to the mapped section. This driver has been used with Dell, ThinkPad, and VAIO devices.

    Source:Souhail Hammou
    Published:9 May 2018
    9.8
    Critical

    CVE-2018-10824

    Last Modified: 24 Oct 2018

    An issue was discovered on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. The administrative password is stored in plaintext in the /tmp/csman/0 file. An attacker having a directory traversal (or LFI) can easily get full router access.

    Source:Blazej Adamczyk
    Published:17 Oct 2018
    8.8
    High

    CVE-2018-10823

    Last Modified: 24 Oct 2018

    An issue was discovered on D-Link DWR-116 through 1.06, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices. An authenticated attacker may execute arbitrary code by injecting the shell command into the chkisg.htm page Sip parameter. This allows for full control over the device internals.

    Source:Blazej Adamczyk
    Published:17 Oct 2018