8.8
    High

    CVE-2018-10260

    Last Modified: 26 Apr 2018

    A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.

    Source:8bitsec
    Published:1 May 2018
    5.4
    Medium

    CVE-2018-10259

    Last Modified: 25 Apr 2018

    An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.

    Source:8bitsec
    Published:1 May 2018
    8.8
    High

    CVE-2018-10258

    Last Modified: 26 Apr 2018

    A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

    Source:8bitsec
    Published:1 May 2018
    8.8
    High

    CVE-2018-10257

    Last Modified: 26 Apr 2018

    A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

    Source:8bitsec
    Published:1 May 2018
    8.8
    High

    CVE-2018-10256

    Last Modified: 26 Apr 2018

    A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.

    Source:8bitsec
    Published:1 May 2018
    8.8
    High

    CVE-2018-10255

    Last Modified: 26 Apr 2018

    A CSV Injection vulnerability was discovered in clustercoding Blog Master Pro v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to possible code execution.

    Source:8bitsec
    Published:1 May 2018
    7.5
    High

    CVE-2018-10253

    Last Modified: 23 Apr 2018

    Paessler PRTG Network Monitor before 18.1.39.1648 mishandles stack memory during unspecified API calls.

    Source:luriel
    Published:21 Apr 2018
    7.5
    High

    CVE-2018-10201

    Last Modified: 11 May 2018

    An issue was discovered in NcMonitorServer.exe in NC Monitor Server in NComputing vSpace Pro 10 and 11. It is possible to read arbitrary files outside the root directory of the web server. This vulnerability could be exploited remotely by a crafted URL without credentials, with .../ or ...\ or ..../ or ....\ as a directory-traversal pattern to TCP port 8667.

    Source:Javier Bernardo
    Published:20 Apr 2018
    8.8
    High

    CVE-2018-10188

    Last Modified: 23 Apr 2018

    phpMyAdmin 4.8.0 before 4.8.0-1 has CSRF, allowing an attacker to execute arbitrary SQL statements, related to js/db_operations.js, js/tbl_operations.js, libraries/classes/Operations.php, and sql.php.

    Source:revengsh
    Published:19 Apr 2018
    8.8
    High

    CVE-2018-10123

    Last Modified: 20 May 2018

    p910nd on Inteno IOPSYS 2.0 through 4.2.0 allows remote attackers to read, or append data to, arbitrary files via requests on TCP port 9100.

    Source:neonsea
    Published:16 May 2018
    4.8
    Medium

    CVE-2018-10118

    Last Modified: 24 Sept 2018

    Monstra CMS 3.0.4 has Stored XSS via the Name field on the Create New Page screen under the admin/index.php?id=pages URI, related to plugins/box/pages/pages.admin.php.

    Source:DEEPIN2
    Published:15 Apr 2018
    4.8
    Medium

    CVE-2018-10110

    Last Modified: 17 Apr 2018

    D-Link DIR-615 T1 devices allow XSS via the Add User feature.

    Source:Sayan Chatterjee
    Published:18 Apr 2018
    4.8
    Medium

    CVE-2018-10109

    Last Modified: 23 Apr 2018

    Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.

    Source:Wenming Jiang
    Published:14 Apr 2018
    6.1
    Medium

    CVE-2018-10097

    Last Modified: 21 Nov 2024

    XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.

    Published:13 Apr 2018
    9.8
    Critical

    CVE-2018-10094

    Last Modified: 13 Jul 2018

    SQL injection vulnerability in Dolibarr before 7.0.2 allows remote attackers to execute arbitrary SQL commands via vectors involving integer parameters without quotes.

    Source:Sysdream
    Published:22 May 2018
    8.8
    High

    CVE-2018-10093

    Last Modified: 14 Jan 2019

    AudioCodes IP phone 420HD devices using firmware version 2.2.12.126 allow Remote Code Execution.

    Source:Sysdream
    Published:17 Mar 2019
    9.8
    Critical

    CVE-2018-10088

    Last Modified: 26 Jun 2018

    Buffer overflow in XiongMai uc-httpd 1.0.0 has unspecified impact and attack vectors, a different vulnerability than CVE-2017-16725.

    Source:Andrew Watson
    Published:8 Jun 2018
    7.8
    High

    CVE-2018-10079

    Last Modified: 18 Apr 2018

    Geist WatchDog Console 3.2.2 uses a weak ACL for the C:\ProgramData\WatchDog Console directory, which allows local users to modify configuration data by updating (1) config.xml or (2) servers.xml.

    Source:bzyo
    Published:20 Apr 2018
    4.8
    Medium

    CVE-2018-10078

    Last Modified: 18 Apr 2018

    Cross-site scripting (XSS) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to inject arbitrary web script or HTML via a server description.

    Source:bzyo
    Published:20 Apr 2018
    4.9
    Medium

    CVE-2018-10077

    Last Modified: 18 Apr 2018

    XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data.

    Source:bzyo
    Published:20 Apr 2018
    7.5
    High

    CVE-2018-10070

    Last Modified: 13 Apr 2018

    A vulnerability in MikroTik Version 6.41.4 could allow an unauthenticated remote attacker to exhaust all available CPU and all available RAM by sending a crafted FTP request on port 21 that begins with many '\0' characters, preventing the affected router from accepting new FTP connections. The router will reboot after 10 minutes, logging a "router was rebooted without proper shutdown" message.

    Source:FarazPajohan
    Published:16 Apr 2018
    6.1
    Medium

    CVE-2018-10068

    Last Modified: 17 Apr 2018

    The jDownloads extension before 3.2.59 for Joomla! has XSS.

    Source:Sureshbabu Narvaneni
    Published:12 Apr 2018
    7.8
    High

    CVE-2018-10063

    Last Modified: 16 Apr 2018

    The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.

    Source:Sairam Jetty
    Published:12 Apr 2018
    8.8
    High

    CVE-2018-10018

    Last Modified: 13 Jul 2018

    The GDASPAMLib.AntiSpam ActiveX control ASK\GDASpam.dll in G DATA Total Security 25.4.0.3 has a buffer overflow via a long IsBlackListed argument.

    Source:Filipe Xavier Oliveira
    Published:13 Jul 2018
    9.8
    Critical

    CVE-2018-9995

    Last Modified: 3 May 2018

    TBK DVR4104 and DVR4216 devices, as well as Novo, CeNova, QSee, Pulnix, XVR 5 in 1, Securus, Night OWL, DVR Login, HVR Login, and MDVR Login, which run re-branded versions of the original TBK DVR4104 and DVR4216 series, allow remote attackers to bypass authentication via a "Cookie: uid=admin" header, as demonstrated by a device.rsp?opt=user&cmd=list request that provides credentials within JSON data in a response.

    Source:ezelf
    Published:10 Apr 2018
    8.8
    High

    CVE-2018-9958

    Last Modified: 27 Aug 2018

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.1.1049. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Text Annotations. When setting the point attribute, the process does not properly validate the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5620.

    Source:Metasploit
    Published:17 May 2018
    8.8
    High

    CVE-2018-9951

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CPDF_Object objects. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code under the context of the current process. Was ZDI-CAN-5414.

    Published:17 May 2018
    6.5
    Medium

    CVE-2018-9950

    Last Modified: 21 Nov 2024

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of PDF documents. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated object. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5413.

    Published:17 May 2018
    6.5
    Medium

    CVE-2018-9948

    Last Modified: 27 Aug 2018

    This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of Foxit Reader 9.0.0.29935. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of typed arrays. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-5380.

    Source:Metasploit
    Published:17 May 2018
    8.8
    High

    CVE-2018-9926

    Last Modified: 17 Nov 2018

    An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can add an admin account via index.php?m=core&f=power&v=add.

    Source:taoge
    Published:10 Apr 2018
    6.1
    Medium

    CVE-2018-9857

    Last Modified: 18 Apr 2018

    PHP Scripts Mall Match Clone Script 1.0.4 has XSS via the search field to searchbyid.php (aka the "View Search By Id" screen).

    Source:ManhNho
    Published:9 Apr 2018
    6.1
    Medium

    CVE-2018-9844

    Last Modified: 11 Apr 2018

    The Iptanus WordPress File Upload plugin before 4.3.4 for WordPress mishandles Settings attributes, leading to XSS.

    Source:ManhNho
    Published:7 Apr 2018
    9.8
    Critical

    CVE-2018-9843

    Last Modified: 9 Apr 2018

    The REST API in CyberArk Password Vault Web Access before 9.9.5 and 10.x before 10.1 allows remote attackers to execute arbitrary code via a serialized .NET object in an Authorization HTTP header.

    Source:RedTeam Pentesting
    Published:12 Apr 2018
    5.3
    Medium

    CVE-2018-9842

    Last Modified: 9 Apr 2018

    CyberArk Password Vault before 9.7 allows remote attackers to obtain sensitive information from process memory by replaying a logon message.

    Source:RedTeam Pentesting
    Published:12 Apr 2018
    Unknown

    CVE-2018-9546

    https://github.com/IOActive/AOSP-DownloadProviderHeadersDumper

    7
    High

    CVE-2018-9539

    Last Modified: 21 Nov 2024

    In the ClearKey CAS descrambler, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android. Versions: Android-8.0 Android-8.1 Android-9. Android ID: A-113027383

    Published:14 Nov 2018
    7.8
    High

    CVE-2018-9515

    Last Modified: 8 Oct 2018

    In sdcardfs_create and sdcardfs_mkdir of inode.c, there is a possible memory corruption due to improper locking. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android kernel Android ID: A-111641492 References: N/A

    Source:Google Security Research
    Published:2 Oct 2018
    5.5
    Medium

    CVE-2018-9493

    Last Modified: 21 Nov 2024

    In the content provider of the download manager, there is a possible SQL injection due to improper input validation. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android-9.0 Android ID: A-111085900

    Published:2 Oct 2018
    7.8
    High

    CVE-2018-9488

    Last Modified: 11 Sept 2018

    In the SELinux permissions of crash_dump.te, there is a permissions bypass due to a missing restriction. This could lead to a local escalation of privilege, with System privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-8.0 Android-8.1 Android-9.0 Android ID: A-110107376.

    Source:Google Security Research
    Published:6 Nov 2018
    7.7
    High

    CVE-2018-9468

    Last Modified: 18 Dec 2024

    In query of DownloadManager.java, there is a possible read/write of arbitrary files due to a permissions bypass. This could lead to local information disclosure and file rewriting with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:20 Nov 2024
    6.8
    Medium

    CVE-2018-9445

    Last Modified: 13 Aug 2018

    In readMetadata of Utils.cpp, there is a possible path traversal bug due to a confused deputy. This could lead to local escalation of privilege when mounting a USB device with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80436257.

    Source:Google Security Research
    Published:6 Nov 2018
    8.8
    High

    CVE-2018-9411

    Last Modified: 22 Nov 2024

    In decrypt of ClearKeyCasPlugin.cpp there is a possible out-of-bounds write due to a missing bounds check. This could lead to remote arbitrary code execution with no additional execution privileges needed. User interaction is needed for exploitation.

    Published:19 Nov 2024
    7.8
    High

    CVE-2018-9375

    Last Modified: 3 Jul 2025

    In multiple functions of UserDictionaryProvider.java, there is a possible way to add and delete words in the user dictionary due to a confused deputy. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:17 Jan 2025
    7.8
    High

    CVE-2018-9338

    Last Modified: 22 Nov 2024

    In ResStringPool::setTo of ResourceTypes.cpp, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published:19 Nov 2024
    9.1
    Critical

    CVE-2018-9302

    Last Modified: 2 May 2018

    SSRF (Server Side Request Forgery) in /assets/lib/fuc.js.php in Cockpit 0.4.4 through 0.5.5 allows remote attackers to read arbitrary files or send TCP traffic to intranet hosts via the url parameter. NOTE: this vulnerability exists because of an incomplete fix for CVE-2017-14611, which was about version 0.13.0, which (surprisingly) is an earlier version than 0.4.4.

    Source:Qian Wu_ Bo Wang_ Jiawang Zhang
    Published:2 May 2018
    7.2
    High

    CVE-2018-9276

    Last Modified: 16 Mar 2019

    An issue was discovered in PRTG Network Monitor before 18.2.39. An attacker who has access to the PRTG System Administrator web console with administrative privileges can exploit an OS command injection vulnerability (both on the server and on devices) by sending malformed parameters in sensor or notification management scenarios.

    Source:M4LV0
    Published:2 Jul 2018
    9.8
    Critical

    CVE-2018-9248

    Last Modified: 6 Apr 2018

    FiberHome VDSL2 Modem HG 150-UB devices allow authentication bypass via a "Cookie: Name=0admin" header.

    Source:Noman Riffat
    Published:4 Apr 2018
    9.8
    Critical

    CVE-2018-9245

    Last Modified: 24 Apr 2018

    The Ericsson-LG iPECS NMS A.1Ac login portal has a SQL injection vulnerability in the User ID and password fields that allows users to bypass the login page and execute remote code on the operating system.

    Source:Berk Cem Göksel
    Published:22 Apr 2018
    6.1
    Medium

    CVE-2018-9238

    Last Modified: 9 Apr 2018

    proberv.php in Yahei-PHP Proberv 0.4.7 has XSS via the funName parameter.

    Source:ManhNho
    Published:4 Apr 2018
    5.4
    Medium

    CVE-2018-9237

    Last Modified: 10 Apr 2018

    iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site Description" field.

    Source:ManhNho
    Published:4 Apr 2018