5.4
    Medium

    CVE-2018-9236

    Last Modified: 10 Apr 2018

    iScripts EasyCreate 3.2.1 has Stored Cross-Site Scripting in the "Site title" field.

    Source:ManhNho
    Published:4 Apr 2018
    6.1
    Medium

    CVE-2018-9235

    Last Modified: 11 Apr 2018

    iScripts SonicBB 1.0 has Reflected Cross-Site Scripting via the query parameter to search.php.

    Source:ManhNho
    Published:4 Apr 2018
    7.8
    High

    CVE-2018-9233

    Last Modified: 19 Apr 2018

    Sophos Endpoint Protection 10.7 uses an unsalted SHA-1 hash for password storage in %PROGRAMDATA%\Sophos\Sophos Anti-Virus\Config\machine.xml, which makes it easier for attackers to determine a cleartext password, and subsequently choose unsafe malware settings, via rainbow tables or other approaches.

    Source:hyp3rlinx
    Published:5 Apr 2018
    9.8
    Critical

    CVE-2018-9208

    Last Modified: 21 Nov 2024

    Unauthenticated arbitrary file upload vulnerability in jQuery Picture Cut <= v1.1Beta

    Published:5 Nov 2018
    9.8
    Critical

    CVE-2018-9207

    Last Modified: 21 Nov 2024

    Arbitrary file upload in jQuery Upload File <= 4.0.2

    Published:19 Nov 2018
    9.8
    Critical

    CVE-2018-9206

    Last Modified: 6 Nov 2018

    Unauthenticated arbitrary file upload vulnerability in Blueimp jQuery-File-Upload <= v9.22.0

    Source:Metasploit
    Published:11 Oct 2018
    7.5
    High

    CVE-2018-9205

    Last Modified: 23 Apr 2018

    Vulnerability in avatar_uploader v7.x-1.0-beta8 , The code in view.php doesn't verify users or sanitize the file path.

    Source:Larry W. Cashdollar
    Published:4 Apr 2018
    5.4
    Medium

    CVE-2018-9183

    Last Modified: 5 Apr 2018

    The Joom Sky JS Jobs extension before 1.2.1 for Joomla! has XSS.

    Source:Sureshbabu Narvaneni
    Published:2 Apr 2018
    6.1
    Medium

    CVE-2018-9173

    Last Modified: 5 Apr 2018

    Cross-site scripting (XSS) vulnerability in admin/template/js/uploadify/uploadify.swf in GetSimple CMS 3.3.13 allows remote attackers to inject arbitrary web script or HTML, as demonstrated by the movieName parameter.

    Source:Sureshbabu Narvaneni
    Published:2 Apr 2018
    5.4
    Medium

    CVE-2018-9172

    Last Modified: 11 Apr 2018

    The Iptanus WordPress File Upload plugin before 4.3.3 for WordPress mishandles shortcode attributes.

    Source:ManhNho
    Published:1 Apr 2018
    5.4
    Medium

    CVE-2018-9163

    Last Modified: 22 May 2018

    A stored Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Recovery Manager Plus before 5.3 (Build 5350) allows remote authenticated users (with Add New Technician permissions) to inject arbitrary web script or HTML via the loginName field to technicianAction.do.

    Source:Ahmet Gurel
    Published:2 Apr 2018
    9.8
    Critical

    CVE-2018-9160

    Last Modified: 26 Apr 2018

    SickRage before v2018.03.09-1 includes cleartext credentials in HTTP responses.

    Source:Sven Fassbender
    Published:31 Mar 2018
    5.3
    Medium

    CVE-2018-9159

    Last Modified: 21 Nov 2024

    In Spark before 2.7.2, a remote attacker can read unintended static files via various representations of absolute or relative pathnames, as demonstrated by file: URLs and directory traversal sequences. NOTE: this product is unrelated to Ignite Realtime Spark.

    Published:6 Mar 2018
    5.4
    Medium

    CVE-2018-9155

    Last Modified: 11 May 2018

    Cross-site scripting (XSS) vulnerability in Open-AudIT Professional 2.1.1 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the Admin->Logs section (with a logs?logs.type= URI) and the Manage->Attributes section (via the "Name (display)" field to the attributes/create URI).

    Source:Tejesh Kolisetty
    Published:12 Apr 2018
    6.8
    Medium

    CVE-2018-9137

    Last Modified: 24 Apr 2018

    Open-AudIT before 2.2 has CSV Injection.

    Source:Sureshbabu Narvaneni
    Published:19 Apr 2018
    Low

    CVE-2018-9131

    Last Modified: 11 May 2018

    DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none

    Source:bzyo
    Published:24 Apr 2018
    7.8
    High

    CVE-2018-9128

    Last Modified: 21 Mar 2019

    DVD X Player Standard 5.5.3.9 has a Buffer Overflow via a crafted .plf file, a related issue to CVE-2007-3068.

    Source:Paolo Perego
    Published:1 Apr 2018
    9.8
    Critical

    CVE-2018-9126

    Last Modified: 6 Apr 2018

    The DNNArticle module 11 for DNN (formerly DotNetNuke) allows remote attackers to read the web.config file, and consequently discover database credentials, via the /GetCSS.ashx/?CP=%2fweb.config URI.

    Source:Esmaeil Rahimian
    Published:4 Apr 2018
    7.5
    High

    CVE-2018-9118

    Last Modified: 27 Jul 2018

    exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.

    Source:Colette Chamberland
    Published:12 Apr 2018
    5.3
    Medium

    CVE-2018-9115

    Last Modified: 30 Mar 2018

    Systematic SitaWare 6.4 SP2 does not validate input from other sources sufficiently. e.g., information utilizing the NVG interface. An attacker can freeze the Situational Layer, which means that the Situational Picture is no longer updated. Unfortunately, the user cannot notice until he tries to work with that layer.

    Source:2u53
    Published:4 Apr 2018
    8.8
    High

    CVE-2018-9107

    Last Modified: 30 Mar 2018

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcyMailing extension before 5.9.6 for Joomla! via a value that is mishandled in a CSV export.

    Source:Sureshbabu Narvaneni
    Published:28 Mar 2018
    8.8
    High

    CVE-2018-9106

    Last Modified: 30 Mar 2018

    CSV Injection (aka Excel Macro Injection or Formula Injection) exists in the export feature in the Acyba AcySMS extension before 3.5.1 for Joomla! via a value that is mishandled in a CSV export.

    Source:Sureshbabu Narvaneni
    Published:28 Mar 2018
    8.8
    High

    CVE-2018-9092

    Last Modified: 30 Mar 2018

    There is a CSRF vulnerability in mc-admin/conf.php in MiniCMS 1.10 that can change the administrator account password.

    Source:zixian
    Published:27 Mar 2018
    8.1
    High

    CVE-2018-9075

    Last Modified: 21 Nov 2024

    For some Iomega, Lenovo, LenovoEMC NAS devices versions 4.1.402.34662 and earlier, when joining a PersonalCloud setup, an attacker can craft a command injection payload using backtick "``" characters in the client:password parameter. As a result, arbitrary commands may be executed as the root user. The attack requires a value __c and iomega parameter.

    Published:28 Sept 2018
    9.8
    Critical

    CVE-2018-9059

    Last Modified: 24 Apr 2018

    Stack-based buffer overflow in Easy File Sharing (EFS) Web Server 7.2 allows remote attackers to execute arbitrary code via a malicious login request to forum.ghp. NOTE: this may overlap CVE-2014-3791.

    Source:Hashim Jawad
    Published:20 Apr 2018
    6.5
    Medium

    CVE-2018-9038

    Last Modified: 24 Apr 2018

    Monstra CMS 3.0.4 allows remote attackers to delete files via an admin/index.php?id=filesmanager&delete_dir=./&path=uploads/ request.

    Source:Wenming Jiang
    Published:10 Apr 2018
    9.6
    Critical

    CVE-2018-9035

    Last Modified: 30 Mar 2018

    CSV Injection vulnerability in ExportToCsvUtf8.php of the Contact Form 7 to Database Extension plugin 2.10.32 for WordPress allows remote attackers to inject spreadsheet formulas into CSV files via the contact form.

    Source:Stefan Broeder
    Published:4 Apr 2018
    5.4
    Medium

    CVE-2018-9034

    Last Modified: 30 Mar 2018

    Cross-site scripting (XSS) vulnerability in lib/interface.php of the Relevanssi plugin 4.0.4 for WordPress allows remote attackers to inject arbitrary JavaScript or HTML via the tab GET parameter.

    Source:Stefan Broeder
    Published:4 Apr 2018
    9.8
    Critical

    CVE-2018-9032

    Last Modified: 30 Mar 2018

    An authentication bypass vulnerability on D-Link DIR-850L Wireless AC1200 Dual Band Gigabit Cloud Router (Hardware Version : A1, B1; Firmware Version : 1.02-2.06) devices potentially allows attackers to bypass SharePort Web Access Portal by directly visiting /category_view.php or /folder_view.php.

    Source:Gem George
    Published:27 Mar 2018
    9.8
    Critical

    CVE-2018-9022

    Last Modified: 5 Dec 2019

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary code or commands by poisoning a configuration file.

    Source:Peter Lapp
    Published:18 Jun 2018
    9.8
    Critical

    CVE-2018-9021

    Last Modified: 5 Dec 2019

    An authentication bypass vulnerability in CA Privileged Access Manager 2.8.2 and earlier allows remote attackers to execute arbitrary commands with specially crafted requests.

    Source:Peter Lapp
    Published:18 Jun 2018
    7.2
    High

    CVE-2018-9010

    Last Modified: 26 Mar 2018

    Intelbras TELEFONE IP TIP200/200 LITE 60.0.75.29 devices allow remote authenticated admins to read arbitrary files via the /cgi-bin/cgiServer.exx page parameter, aka absolute path traversal. In some cases, authentication can be achieved via the admin account with its default admin password.

    Source:anhax0r
    Published:25 Mar 2018
    8.8
    High

    CVE-2018-8979

    Last Modified: 30 Mar 2018

    Open-AudIT Professional 2.1 has CSRF, as demonstrated by modifying a user account or inserting XSS sequences via the credentials URI.

    Source:Nilesh Sapariya
    Published:25 Mar 2018
    7.4
    High

    CVE-2018-8970

    Last Modified: 21 Nov 2024

    The int_x509_param_set_hosts function in lib/libcrypto/x509/x509_vpm.c in LibreSSL 2.7.0 before 2.7.1 does not support a certain special case of a zero name length, which causes silent omission of hostname verification, and consequently allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. NOTE: the LibreSSL documentation indicates that this special case is supported, but the BoringSSL documentation does not.

    Published:24 Mar 2018
    7.5
    High

    CVE-2018-8947

    Last Modified: 26 Mar 2018

    rap2hpoutre Laravel Log Viewer before v0.13.0 relies on Base64 encoding for l, dl, and del requests, which makes it easier for remote attackers to bypass intended access restrictions, as demonstrated by reading arbitrary files via a dl request.

    Source:Haboob Team
    Published:25 Mar 2018
    8.8
    High

    CVE-2018-8941

    Last Modified: 21 Nov 2024

    Diagnostics functionality on D-Link DSL-3782 devices with firmware EU v. 1.01 has a buffer overflow, allowing authenticated remote attackers to execute arbitrary code via a long Addr value to the 'set Diagnostics_Entry' function in an HTTP request, related to /userfs/bin/tcapi.

    Published:3 Apr 2018
    8.8
    High

    CVE-2018-8908

    Last Modified: 2 Apr 2018

    An issue was discovered in /admin/?/user/add in Frog CMS 0.9.5. The application's add user functionality suffers from CSRF. A malicious user can craft an HTML page and use it to trick a victim into clicking on it; once executed, a malicious user will be created with admin privileges. This happens due to lack of an anti-CSRF token in state modification requests.

    Source:Samrat Das
    Published:31 Mar 2018
    5.4
    Medium

    CVE-2018-8903

    Last Modified: 28 Mar 2018

    Open-AudIT Professional 2.1 allows XSS via the Name or Description field on the Credentials screen.

    Source:Nilesh Sapariya
    Published:22 Mar 2018
    9.8
    Critical

    CVE-2018-8898

    Last Modified: 20 May 2018

    A flaw in the authentication mechanism in the Login Panel of router D-Link DSL-3782 (A1_WI_20170303 || SWVer="V100R001B012" FWVer="3.10.0.24" FirmVer="TT_77616E6771696F6E67") allows unauthenticated attackers to perform arbitrary modification (read, write) to passwords and configurations meanwhile an administrator is logged into the web panel.

    Source:Giulio Comi
    Published:23 May 2018
    7.8
    High

    CVE-2018-8897

    Last Modified: 13 Jul 2018

    A statement in the System Programming Guide of the Intel 64 and IA-32 Architectures Software Developer's Manual (SDM) was mishandled in the development of some or all operating-system kernels, resulting in unexpected behavior for #DB exceptions that are deferred by MOV SS or POP SS, as demonstrated by (for example) privilege escalation in Windows, macOS, some Xen configurations, or FreeBSD, or a Linux kernel crash. The MOV to SS and POP SS instructions inhibit interrupts (including NMIs), data breakpoints, and single step trap exceptions until the instruction boundary following the next instruction (SDM Vol. 3A; section 6.8.3). (The inhibited data breakpoints are those on memory accessed by the MOV to SS or POP to SS instruction itself.) Note that debug exceptions are not inhibited by the interrupt enable (EFLAGS.IF) system flag (SDM Vol. 3A; section 2.3). If the instruction following the MOV to SS or POP to SS instruction is an instruction like SYSCALL, SYSENTER, INT 3, etc. that transfers control to the operating system at CPL < 3, the debug exception is delivered after the transfer to CPL < 3 is complete. OS kernels may not expect this order of events and may therefore experience unexpected behavior when it occurs.

    Source:Can Bölük
    Published:8 May 2018
    7.5
    High

    CVE-2018-8880

    Last Modified: 18 Apr 2018

    Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure.

    Source:SadFud
    Published:23 Apr 2018
    6.1
    Medium

    CVE-2018-8831

    Last Modified: 18 Apr 2018

    A Persistent XSS vulnerability exists in Kodi (formerly XBMC) through 17.6 that allows the execution of arbitrary HTML/script code in the context of the victim user's browser via a playlist.

    Source:Manuel García Cárdenas
    Published:18 Apr 2018
    7.5
    High

    CVE-2018-8820

    Last Modified: 21 Nov 2024

    An issue was discovered in Square 9 GlobalForms 6.2.x. A Time Based SQL injection vulnerability in the "match" parameter allows remote authenticated attackers to execute arbitrary SQL commands. It is possible to upgrade access to full server compromise via xp_cmdshell. In some cases, the authentication requirement for the attack can be met by sending the default admin credentials.

    Published:28 Mar 2018
    8.8
    High

    CVE-2018-8817

    Last Modified: 2 Apr 2018

    Wampserver before 3.1.3 has CSRF in add_vhost.php.

    Source:Vipin Chaudhary
    Published:25 Mar 2018
    4.6
    Medium

    CVE-2018-8815

    Last Modified: 2 Apr 2018

    Cross-site scripting (XSS) vulnerability in the gallery function in Alkacon OpenCMS 10.5.3 allows remote attackers to inject arbitrary web script or HTML via a malicious SVG image.

    Source:Sureshbabu Narvaneni
    Published:20 Mar 2018
    6.5
    Medium

    CVE-2018-8814

    Last Modified: 11 Apr 2018

    Cross-site request forgery (CSRF) vulnerability in WolfCMS 0.8.3.1 allows remote attackers to hijack the authentication of users for requests that modify plugin/[pluginname]/settings by crafting a malicious request.

    Source:Sureshbabu Narvaneni
    Published:4 Apr 2018
    4.8
    Medium

    CVE-2018-8813

    Last Modified: 9 Apr 2018

    Open redirect vulnerability in the login[redirect] parameter login functionality in WolfCMS 0.8.3.1 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a malformed URL.

    Source:Sureshbabu Narvaneni
    Published:4 Apr 2018
    8.8
    High

    CVE-2018-8811

    Last Modified: 2 Apr 2018

    Cross-site request forgery (CSRF) vulnerability in system/workplace/admin/accounts/user_role.jsp in OpenCMS 10.5.3 allows remote attackers to hijack the authentication of administrative users for requests that perform privilege escalation. Note: It is argued that OpenCMS allows only registered users to upload different kind of content artifacts (SVG, .doc, .docx). The uploaded content is stored in the CMS content repository "as is". In case of scripts inside an SVG, this may or may not be "malicious", there is no way of knowing if the uploaded SVG contains the script for a reason. To exploit the "issue", a user must have an account in the CMS as a content manager

    Source:Sureshbabu Narvaneni
    Published:20 Mar 2018
    6.1
    Medium

    CVE-2018-8772

    Last Modified: 18 Apr 2018

    Coship RT3052 4.0.0.48 devices allow XSS via a crafted SSID field on the "Wireless Setting - Basic" screen.

    Source:Sayan Chatterjee
    Published:10 Apr 2018
    5.3
    Medium

    CVE-2018-8770

    Last Modified: 28 Mar 2019

    Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via generate.php, controllers/getConfigTest.php, controllers/getUpdateTest.php, controllers/postclientdataTest.php, controllers/posterrorTest.php, controllers/posteventTest.php, controllers/posttagTest.php, controllers/postusinglogTest.php, fixtures/Controller_fixt.php, fixtures/Controller_fixt2.php, fixtures/view_fixt2.php, libs/ipTest.php, or models/commonDbfix.php in tests/.

    Source:Kyhvedn
    Published:18 Mar 2018