7.5
    High

    CVE-2018-10822

    Last Modified: 24 Oct 2018

    Directory traversal vulnerability in the web interface on D-Link DWR-116 through 1.06, DIR-140L through 1.02, DIR-640L through 1.02, DWR-512 through 2.02, DWR-712 through 2.02, DWR-912 through 2.02, DWR-921 through 2.02, and DWR-111 through 1.01 devices allows remote attackers to read arbitrary files via a /.. or // after "GET /uir" in an HTTP request. NOTE: this vulnerability exists because of an incorrect fix for CVE-2017-6190.

    Source:Blazej Adamczyk
    Published:17 Oct 2018
    4.8
    Medium

    CVE-2018-10821

    Last Modified: 21 Nov 2024

    Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search panel.

    Published:14 Jun 2018
    7.8
    High

    CVE-2018-10814

    Last Modified: 12 Sept 2018

    Synametrics SynaMan 4.0 build 1488 uses cleartext password storage for SMTP credentials.

    Source:bzyo
    Published:14 Sept 2018
    7.8
    High

    CVE-2018-10809

    Last Modified: 7 Mar 2019

    In 2345 Security Guard 3.7, the driver file (2345NetFirewall.sys) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating input values from IOCtl 0x00222040. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-8873.

    Source:anhkgg
    Published:8 May 2018
    4.8
    Medium

    CVE-2018-10763

    Last Modified: 17 Mar 2019

    Multiple cross-site scripting (XSS) vulnerabilities in Synametrics SynaMan 4.0 build 1488 via the (1) Main heading or (2) Sub heading fields in the Partial Branding configuration page.

    Source:bzyo
    Published:14 Sept 2018
    9.8
    Critical

    CVE-2018-10757

    Last Modified: 6 May 2018

    CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.

    Source:Youssef Mami
    Published:5 May 2018
    4.8
    Medium

    CVE-2018-10752

    Last Modified: 21 Aug 2018

    The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.

    Source:ManhNho
    Published:5 May 2018
    5.3
    Medium

    CVE-2018-10751

    Last Modified: 23 May 2018

    A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in memory allocation for this string. The Samsung ID is SVE-2018-11463.

    Source:Google Security Research
    Published:29 May 2018
    5.3
    Medium

    CVE-2018-10732

    Last Modified: 21 Nov 2024

    The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.

    Published:28 May 2018
    10
    Critical

    CVE-2018-10718

    Last Modified: 9 Jul 2018

    Stack-based buffer overflow in Activision Infinity Ward Call of Duty Modern Warfare 2 before 2018-04-26 allows remote attackers to execute arbitrary code via crafted packets.

    Source:Maurice Heumann
    Published:3 May 2018
    Unknown

    CVE-2018-10715

    https://github.com/alt3kx/CVE-2018-10715

    7.8
    High

    CVE-2018-10712

    Last Modified: 29 Oct 2018

    The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

    Source:SecureAuth
    Published:30 Oct 2018
    7.8
    High

    CVE-2018-10711

    Last Modified: 29 Oct 2018

    The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.

    Source:SecureAuth
    Published:30 Oct 2018
    7.1
    High

    CVE-2018-10710

    Last Modified: 29 Oct 2018

    The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.

    Source:SecureAuth
    Published:30 Oct 2018
    7.8
    High

    CVE-2018-10709

    Last Modified: 29 Oct 2018

    The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. This could be leveraged in a number of ways to ultimately run code with elevated privileges.

    Source:SecureAuth
    Published:30 Oct 2018
    9.8
    Critical

    CVE-2018-10662

    Last Modified: 1 Aug 2018

    An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.

    Source:Metasploit
    Published:26 Jun 2018
    9.8
    Critical

    CVE-2018-10661

    Last Modified: 1 Aug 2018

    An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.

    Source:Metasploit
    Published:26 Jun 2018
    9.8
    Critical

    CVE-2018-10660

    Last Modified: 1 Aug 2018

    An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.

    Source:Metasploit
    Published:26 Jun 2018
    7.8
    High

    CVE-2018-10655

    Last Modified: 6 May 2018

    DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).

    Source:hyp3rlinx
    Published:10 May 2018
    9.8
    Critical

    CVE-2018-10653

    Last Modified: 28 Jan 2020

    There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.

    Source:Jonas Lejon
    Published:23 May 2018
    7.8
    High

    CVE-2018-10619

    Last Modified: 13 Jun 2018

    An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation.

    Source:LiquidWorm
    Published:7 Jun 2018
    9.8
    Critical

    CVE-2018-10618

    Last Modified: 2 Aug 2018

    Davolink DVW-3200N all version prior to Version 1.00.06. The device generates a weak password hash that is easily cracked, allowing a remote attacker to obtain the password for the device.

    Source:Ankit Anubhav
    Published:1 Aug 2018
    7.5
    High

    CVE-2018-10608

    Last Modified: 16 May 2019

    SEL AcSELerator Architect version 2.2.24.0 and prior can be exploited when the AcSELerator Architect FTP client connects to a malicious FTP server, which may cause denial of service via 100% CPU utilization. Restart of the application is required.

    Source:LiquidWorm
    Published:24 Jul 2018
    9.8
    Critical

    CVE-2018-10594

    Last Modified: 2 Jul 2018

    Delta Industrial Automation COMMGR from Delta Electronics versions 1.08 and prior with accompanying PLC Simulators (DVPSimulator EH2, EH3, ES2, SE, SS2 and AHSIM_5x0, AHSIM_5x1) utilize a fixed-length stack buffer where an unverified length value can be read from the network packets via a specific network port, causing the buffer to be overwritten. This may allow remote code execution, cause the application to crash, or result in a denial-of-service condition in the application server.

    Source:t4rkd3vilz
    Published:26 Jun 2018
    7.5
    High

    CVE-2018-10583

    Last Modified: 2 May 2018

    An information disclosure vulnerability occurs when LibreOffice 6.0.3 and Apache OpenOffice Writer 4.1.5 automatically process and initiate an SMB connection embedded in a malicious file, as demonstrated by xlink:href=file://192.168.0.2/test.jpg within an office:document-content element in a .odt XML document.

    Source:Richard Davy
    Published:1 May 2018
    5.4
    Medium

    CVE-2018-10580

    Last Modified: 10 May 2018

    The "Latest Posts on Profile" plugin 1.1 for MyBB has XSS because there is an added section in a user profile that displays that user's most recent posts without sanitizing the tsubject (aka thread subject) field.

    Source:0xB9
    Published:11 May 2018
    8.8
    High

    CVE-2018-10577

    Last Modified: 14 Sept 2018

    An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15, and AP300 devices with firmware before 2.0.0.10. File upload functionality allows any users authenticated on the web interface to upload files containing code to the web root, allowing these files to be executed as root.

    Source:Stephen Shkardoon
    Published:2 May 2018
    7.8
    High

    CVE-2018-10576

    Last Modified: 14 Sept 2018

    An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a local system account (instead of the dedicated web-only user).

    Source:Stephen Shkardoon
    Published:30 Apr 2018
    9.8
    Critical

    CVE-2018-10575

    Last Modified: 14 Sept 2018

    An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.

    Source:Stephen Shkardoon
    Published:30 Apr 2018
    9.8
    Critical

    CVE-2018-10562

    Last Modified: 3 May 2018

    An issue was discovered on Dasan GPON home routers. Command Injection can occur via the dest_host parameter in a diag_action=ping request to a GponForm/diag_Form URI. Because the router saves ping results in /tmp and transmits them to the user when the user revisits /diag.html, it's quite simple to execute commands and retrieve their output.

    Source:vpnmentor
    Published:4 May 2018
    9.8
    Critical

    CVE-2018-10561

    Last Modified: 3 May 2018

    An issue was discovered on Dasan GPON home routers. It is possible to bypass authentication simply by appending "?images" to any URL of the device that requires authentication, as demonstrated by the /menu.html?images/ or /GponForm/diag_FORM?images/ URI. One can then manage the device.

    Source:vpnmentor
    Published:4 May 2018
    7.5
    High

    CVE-2018-10546

    Last Modified: 21 Nov 2024

    An issue was discovered in PHP before 5.6.36, 7.0.x before 7.0.30, 7.1.x before 7.1.17, and 7.2.x before 7.2.5. An infinite loop exists in ext/iconv/iconv.c because the iconv stream filter does not reject invalid multibyte sequences.

    Published:26 Apr 2018
    7.2
    High

    CVE-2018-10517

    Last Modified: 17 Nov 2018

    In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.

    Source:Lucian Ioan Nitescu
    Published:27 Apr 2018
    4.4
    Medium

    CVE-2018-10507

    Last Modified: 8 Jun 2018

    A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScan Unauthorized Change Prevention inoperable on vulnerable installations. An attacker must already have administrator privileges in order to exploit this vulnerability.

    Source:hyp3rlinx
    Published:12 Jun 2018
    7.8
    High

    CVE-2018-10504

    Last Modified: 30 Apr 2018

    The WebDorado "Form Maker by WD" plugin before 1.12.24 for WordPress allows CSV injection.

    Source:Sairam Jetty
    Published:27 Apr 2018
    Unknown

    CVE-2018-10467

    https://github.com/alt3kx/CVE-2018-10467

    9.8
    Critical

    CVE-2018-10388

    Last Modified: 21 Nov 2024

    Format string vulnerability in the logMess function in TFTP Server SP 1.66 and earlier allows remote attackers to perform a denial of service or execute arbitrary code via format string sequences in a TFTP error packet.

    Published:23 Dec 2019
    6.1
    Medium

    CVE-2018-10371

    Last Modified: 4 May 2018

    An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that allows the execution of arbitrary HTML/script code to be executed in a victim's web browser via a page title.

    Source:B0UG
    Published:1 May 2018
    6.1
    Medium

    CVE-2018-10366

    Last Modified: 26 Apr 2018

    An issue was discovered in the Users (aka Front-end user management) plugin 1.4.5 for October CMS. XSS exists in the name field.

    Source:0xB9
    Published:25 Apr 2018
    5.4
    Medium

    CVE-2018-10365

    Last Modified: 26 Apr 2018

    An XSS issue was discovered in the Threads to Link plugin 1.3 for MyBB. When editing a thread, the user is given the option to convert the thread to a link. The thread link input box is not properly sanitized.

    Source:0xB9
    Published:1 May 2018
    4.8
    Medium

    CVE-2018-10321

    Last Modified: 26 Apr 2018

    Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.

    Source:Wenming Jiang
    Published:24 Apr 2018
    5.4
    Medium

    CVE-2018-10314

    Last Modified: 14 May 2018

    Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action parameter in the Discover -> Audit Scripts -> List Scripts -> Download section.

    Source:Tejesh Kolisetty
    Published:10 May 2018
    5.4
    Medium

    CVE-2018-10313

    Last Modified: 13 May 2018

    WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.

    Source:jiguang
    Published:24 Apr 2018
    8.8
    High

    CVE-2018-10312

    Last Modified: 24 Apr 2018

    index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.

    Source:jiguang
    Published:24 Apr 2018
    6.1
    Medium

    CVE-2018-10311

    Last Modified: 13 May 2018

    A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f=index&v=add URI.

    Source:jiguang
    Published:24 Apr 2018
    5.4
    Medium

    CVE-2018-10310

    Last Modified: 24 Apr 2018

    A persistent cross-site scripting vulnerability has been identified in the web interface of the Catapult UK Cookie Consent plugin before 2.3.10 for WordPress that allows the execution of arbitrary HTML/script code in the context of a victim's browser.

    Source:B0UG
    Published:25 Apr 2018
    5.4
    Medium

    CVE-2018-10309

    Last Modified: 1 May 2018

    The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.

    Source:B0UG
    Published:24 Apr 2018
    7.5
    High

    CVE-2018-10299

    Last Modified: 21 Nov 2024

    An integer overflow in the batchTransfer function of a smart contract implementation for Beauty Ecosystem Coin (BEC), the Ethereum ERC20 token used in the Beauty Chain economic system, allows attackers to accomplish an unauthorized increase of digital assets by providing two _receivers arguments in conjunction with a large _value argument, as exploited in the wild in April 2018, aka the "batchOverflow" issue.

    Published:23 Apr 2018
    8.8
    High

    CVE-2018-10286

    Last Modified: 24 Apr 2018

    The Ericsson-LG iPECS NMS A.1Ac web application discloses sensitive information such as the NMS admin credentials and the PostgreSQL database credentials to logged-in users via the responses to certain HTTP POST requests. In order to be able to see the credentials in cleartext, an attacker needs to be authenticated.

    Source:Berk Cem Göksel
    Published:22 Apr 2018
    9.8
    Critical

    CVE-2018-10285

    Last Modified: 24 Apr 2018

    The Ericsson-LG iPECS NMS A.1Ac web application uses incorrect access control mechanisms. Since the app does not use any sort of session ID, an attacker might bypass authentication.

    Source:Berk Cem Göksel
    Published:22 Apr 2018