7.5
    High

    CVE-2018-8229

    Last Modified: 12 Jul 2018

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-8227.

    Source:Google Security Research
    Published:14 Jun 2018
    7
    High

    CVE-2018-8214

    Last Modified: 20 Jun 2018

    An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8208.

    Source:Google Security Research
    Published:14 Jun 2018
    7
    High

    CVE-2018-8208

    Last Modified: 20 Jun 2018

    An elevation of privilege vulnerability exists in Windows when Desktop Bridge does not properly manage the virtual registry, aka "Windows Desktop Bridge Elevation of Privilege Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8214.

    Source:Google Security Research
    Published:14 Jun 2018
    7.5
    High

    CVE-2018-8174

    Last Modified: 24 May 2018

    A remote code execution vulnerability exists in the way that the VBScript engine handles objects in memory, aka "Windows VBScript Engine Remote Code Execution Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers.

    Source:smgorelik
    Published:9 May 2018
    7.8
    High

    CVE-2018-8172

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists in Visual Studio software when the software does not check the source markup of a file for an unbuilt project, aka "Visual Studio Remote Code Execution Vulnerability." This affects Microsoft Visual Studio, Expression Blend 4.

    Published:11 Jul 2018
    7.5
    High

    CVE-2018-8145

    Last Modified: 12 Jul 2018

    An information disclosure vulnerability exists when Chakra improperly discloses the contents of its memory, which could provide an attacker with information to further compromise the user's computer or data, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects ChakraCore, Internet Explorer 11, Microsoft Edge, Internet Explorer 10. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8133, CVE-2018-8177.

    Source:Google Security Research
    Published:9 May 2018
    7.5
    High

    CVE-2018-8139

    Last Modified: 12 Jul 2018

    A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Microsoft Edge, aka "Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0945, CVE-2018-0946, CVE-2018-0951, CVE-2018-0953, CVE-2018-0954, CVE-2018-0955, CVE-2018-1022, CVE-2018-8114, CVE-2018-8122, CVE-2018-8128, CVE-2018-8137.

    Source:Google Security Research
    Published:9 May 2018
    7
    High

    CVE-2018-8134

    Last Modified: 16 May 2018

    An elevation of privilege vulnerability exists in the way that the Windows Kernel API enforces permissions, aka "Windows Elevation of Privilege Vulnerability." This affects Windows Server 2012 R2, Windows RT 8.1, Windows Server 2016, Windows 8.1, Windows 10, Windows 10 Servers.

    Source:Google Security Research
    Published:9 May 2018
    7.5
    High

    CVE-2018-8133

    Last Modified: 31 May 2018

    A remote code execution vulnerability exists in the way that the Chakra scripting engine handles objects in memory in Microsoft Edge, aka "Chakra Scripting Engine Memory Corruption Vulnerability." This affects Microsoft Edge, ChakraCore. This CVE ID is unique from CVE-2018-0943, CVE-2018-8130, CVE-2018-8145, CVE-2018-8177.

    Source:Google Security Research
    Published:9 May 2018
    7
    High

    CVE-2018-8120

    Last Modified: 22 Oct 2018

    An elevation of privilege vulnerability exists in Windows when the Win32k component fails to properly handle objects in memory, aka "Win32k Elevation of Privilege Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8124, CVE-2018-8164, CVE-2018-8166.

    Source:Metasploit
    Published:9 May 2018
    8.6
    High

    CVE-2018-8115

    Last Modified: 21 Nov 2024

    A remote code execution vulnerability exists when the Windows Host Compute Service Shim (hcsshim) library fails to properly validate input while importing a container image, aka "Windows Host Compute Service Shim Remote Code Execution Vulnerability." This affects Windows Host Compute.

    Published:2 May 2018
    6.1
    Medium

    CVE-2018-8108

    Last Modified: 21 Nov 2024

    The select component in bui through 2018-03-13 has XSS because it performs an escape operation on already-escaped text, as demonstrated by workGroupList text.

    Published:14 Mar 2018
    9.8
    Critical

    CVE-2018-8097

    Last Modified: 21 Nov 2024

    io/mongo/parser.py in Eve (aka pyeve) before 0.7.5 allows remote attackers to execute arbitrary code via Code Injection in the where parameter.

    Published:14 Mar 2018
    9.8
    Critical

    CVE-2018-8096

    Last Modified: 2 Aug 2018

    Datalust Seq before 4.2.605 is vulnerable to Authentication Bypass (with the attacker obtaining admin access) via '"Name":"isauthenticationenabled","Value":false' in an api/settings/setting-isauthenticationenabled PUT request.

    Source:Daniel Chactoura
    Published:14 Mar 2018
    7.8
    High

    CVE-2018-8090

    Last Modified: 21 Nov 2024

    Quick Heal Total Security 64 bit 17.00 (QHTS64.exe), (QHTSFT64.exe) - Version 10.0.1.38; Quick Heal Total Security 32 bit 17.00 (QHTS32.exe), (QHTSFT32.exe) - Version 10.0.1.38; Quick Heal Internet Security 64 bit 17.00 (QHIS64.exe), (QHISFT64.exe) - Version 10.0.0.37; Quick Heal Internet Security 32 bit 17.00 (QHIS32.exe), (QHISFT32.exe) - Version 10.0.0.37; Quick Heal AntiVirus Pro 64 bit 17.00 (QHAV64.exe), (QHAVFT64.exe) - Version 10.0.0.37; and Quick Heal AntiVirus Pro 32 bit 17.00 (QHAV32.exe), (QHAVFT32.exe) - Version 10.0.0.37 allow DLL Hijacking because of Insecure Library Loading.

    Published:25 Jul 2018
    5.4
    Medium

    CVE-2018-8078

    Last Modified: 21 Nov 2024

    YzmCMS 3.7 has Stored XSS via the title parameter to advertisement/adver/edit.html.

    Published:13 Mar 2018
    7.5
    High

    CVE-2018-8065

    Last Modified: 31 May 2023

    An issue was discovered in the web server in Flexense SyncBreeze Enterprise 10.6.24. There is a user mode write access violation on the syncbrs.exe memory region that can be triggered by rapidly sending a variety of HTTP requests with long HTTP header values or long URIs.

    Source:Ege Balci
    Published:12 Mar 2018
    5.4
    Medium

    CVE-2018-8062

    Last Modified: 21 Nov 2024

    A cross-site scripting (XSS) vulnerability on Comtrend AR-5387un devices with A731-410JAZ-C04_R02.A2pD035g.d23i firmware allows remote attackers to inject arbitrary web script or HTML via the Service Description parameter while creating a WAN service.

    Published:23 Oct 2020
    5.5
    Medium

    CVE-2018-8060

    Last Modified: 21 Nov 2024

    HWiNFO AMD64 Kernel driver version 8.98 and lower allows an unprivileged user to send an IOCTL to the device driver. If input and/or output buffer pointers are NULL or if these buffers' data are invalid, a NULL/invalid pointer access occurs, resulting in a Windows kernel panic aka Blue Screen. This affects IOCTLs higher than 0x85FE2600 with the HWiNFO32 symbolic device name.

    Published:10 May 2018
    9.8
    Critical

    CVE-2018-8057

    Last Modified: 17 Apr 2018

    A SQL Injection vulnerability exists in Western Bridge Cobub Razor 0.8.0 via the channel_name or platform parameter in a /index.php?/manage/channel/addchannel request, related to /application/controllers/manage/channel.php.

    Source:Kyhvedn
    Published:11 Mar 2018
    7.5
    High

    CVE-2018-8056

    Last Modified: 28 Mar 2019

    Physical path Leakage exists in Western Bridge Cobub Razor 0.8.0 via an invalid channel_name parameter to /index.php?/manage/channel/addchannel or a direct request to /export.php.

    Source:Kyhvedn
    Published:11 Mar 2018
    8.8
    High

    CVE-2018-8045

    Last Modified: 21 Nov 2024

    In Joomla! 3.5.0 through 3.8.5, the lack of type casting of a variable in a SQL statement leads to a SQL injection vulnerability in the User Notes list view.

    Published:14 Mar 2018
    5.3
    Medium

    CVE-2018-8041

    Last Modified: 21 Nov 2024

    Apache Camel's Mail 2.20.0 through 2.20.3, 2.21.0 through 2.21.1 and 2.22.0 is vulnerable to path traversal.

    Published:9 Jun 2018
    8.1
    High

    CVE-2018-8039

    Last Modified: 21 Nov 2024

    It is possible to configure Apache CXF to use the com.sun.net.ssl implementation via 'System.setProperty("java.protocol.handler.pkgs", "com.sun.net.ssl.internal.www.protocol");'. When this system property is set, CXF uses some reflection to try to make the HostnameVerifier work with the old com.sun.net.ssl.HostnameVerifier interface. However, the default HostnameVerifier implementation in CXF does not implement the method in this interface, and an exception is thrown. However, in Apache CXF prior to 3.2.5 and 3.1.16 the exception is caught in the reflection code and not properly propagated. What this means is that if you are using the com.sun.net.ssl stack with CXF, an error with TLS hostname verification will not be thrown, leaving a CXF client subject to man-in-the-middle attacks.

    Published:29 Jun 2018
    7.5
    High

    CVE-2018-8038

    Last Modified: 21 Nov 2024

    Versions of Apache CXF Fediz prior to 1.4.4 do not fully disable Document Type Declarations (DTDs) when either parsing the Identity Provider response in the application plugins, or in the Identity Provider itself when parsing certain XML-based parameters.

    Published:5 Jul 2018
    7.5
    High

    CVE-2018-8033

    Last Modified: 21 Nov 2024

    In Apache OFBiz 16.11.01 to 16.11.04, the OFBiz HTTP engine (org.apache.ofbiz.service.engine.HttpEngine.java) handles requests for HTTP services via the /webtools/control/httpService endpoint. Both POST and GET requests to the httpService endpoint may contain three parameters: serviceName, serviceMode, and serviceContext. The exploitation occurs by having DOCTYPEs pointing to external references that trigger a payload that returns secret information from the host.

    Published:13 Dec 2018
    6.1
    Medium

    CVE-2018-8032

    Last Modified: 8 May 2025

    Apache Axis 1.x up to and including 1.4 is vulnerable to a cross-site scripting (XSS) attack in the default servlet/services.

    Published:8 Jul 2018
    7.5
    High

    CVE-2018-8030

    Last Modified: 21 Nov 2024

    A Denial of Service vulnerability was found in Apache Qpid Broker-J versions 7.0.0-7.0.4 when AMQP protocols 0-8, 0-9 or 0-91 are used to publish messages with size greater than allowed maximum message size limit (100MB by default). The broker crashes due to the defect. AMQP protocols 0-10 and 1.0 are not affected.

    Published:19 Jun 2018
    9.8
    Critical

    CVE-2018-8021

    Last Modified: 5 Dec 2018

    Versions of Superset prior to 0.23 used an unsafe load method from the pickle library to deserialize data leading to possible remote code execution. Note Superset 0.23 was released prior to any Superset release under the Apache Software Foundation.

    Source:David May
    Published:7 Nov 2018
    6.5
    Medium

    CVE-2018-8004

    Last Modified: 21 Nov 2024

    There are multiple HTTP smuggling and cache poisoning issues when clients making malicious requests interact with Apache Traffic Server (ATS). This affects versions 6.0.0 to 6.2.2 and 7.0.0 to 7.1.3. To resolve this issue users running 6.x should upgrade to 6.2.3 or later versions and 7.x users should upgrade to 7.1.4 or later versions.

    Published:29 Aug 2018
    8.8
    High

    CVE-2018-8002

    Last Modified: 25 Jul 2018

    In PoDoFo 0.9.5, there exists an infinite loop vulnerability in PdfParserObject::ParseFileComplete() in PdfParserObject.cpp which may result in stack overflow. Remote attackers could leverage this vulnerability to cause a denial-of-service or possibly unspecified other impact via a crafted pdf file.

    Source:r4xis
    Published:9 Mar 2018
    5.3
    Medium

    CVE-2018-7935

    Last Modified: 24 Mar 2025

    There is a vulnerability in 21.328.01.00.00 version of the E5573Cs-322. Remote attackers could exploit this vulnerability to make the network where the E5573Cs-322 is running temporarily unavailable.

    Published:10 Feb 2023
    6.5
    Medium

    CVE-2018-7921

    Last Modified: 12 Dec 2018

    Huawei B315s-22 products with software of 21.318.01.00.26 have an information leak vulnerability. Unauthenticated adjacent attackers may exploit this vulnerability to obtain device information.

    Source:Usman Saeed
    Published:12 Sept 2018
    9.8
    Critical

    CVE-2018-7890

    Last Modified: 12 Mar 2018

    A remote code execution issue was discovered in Zoho ManageEngine Applications Manager before 13.6 (build 13640). The publicly accessible testCredential.do endpoint takes multiple user inputs and validates supplied credentials by accessing a specified system. This endpoint calls several internal classes, and then executes a PowerShell script. If the specified system is OfficeSharePointServer, then the username and password parameters to this script are not validated, leading to Command Injection.

    Source:Mehmet Ince
    Published:8 Mar 2018
    7.8
    High

    CVE-2018-7886

    Last Modified: 16 Apr 2018

    An issue was discovered in CloudMe 1.11.0. An unauthenticated local attacker that can connect to the "CloudMe Sync" client application listening on 127.0.0.1 port 8888 can send a malicious payload causing a buffer overflow condition. This will result in code execution, as demonstrated by a TCP reverse shell, or a crash. NOTE: this vulnerability exists because of an incomplete fix for CVE-2018-6892.

    Source:Prasenjit Kanti Paul
    Published:15 Mar 2018
    7.5
    High

    CVE-2018-7854

    Last Modified: 21 Nov 2024

    A CWE-248 Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause a denial of Service when sending invalid debug parameters to the controller over Modbus.

    Published:22 May 2019
    7.5
    High

    CVE-2018-7852

    Last Modified: 29 May 2026

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when an invalid private command parameter is sent to the controller over Modbus.

    Published:22 May 2019
    7.5
    High

    CVE-2018-7849

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause a possible Denial of Service due to improper data integrity check when sending files the controller over Modbus.

    Published:22 May 2019
    7.5
    High

    CVE-2018-7848

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading files from the controller over Modbus

    Published:22 May 2019
    9.8
    Critical

    CVE-2018-7846

    Last Modified: 21 Nov 2024

    A CWE-501: Trust Boundary Violation vulnerability on connection to the Controller exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum and Modicon Premium which could cause unauthorized access by conducting a brute force attack on Modbus protocol to the controller.

    Published:22 May 2019
    7.5
    High

    CVE-2018-7845

    Last Modified: 21 Nov 2024

    A CWE-125: Out-of-bounds Read vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of unexpected data from the controller when reading specific memory blocks in the controller over Modbus.

    Published:22 May 2019
    7.5
    High

    CVE-2018-7844

    Last Modified: 21 Nov 2024

    A CWE-200: Information Exposure vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause the disclosure of SNMP information when reading memory blocks from the controller over Modbus.

    Published:22 May 2019
    7.5
    High

    CVE-2018-7843

    Last Modified: 21 Nov 2024

    A CWE-248: Uncaught Exception vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause denial of service when reading memory blocks with an invalid data size or with an invalid data offset in the controller over Modbus.

    Published:22 May 2019
    9.8
    Critical

    CVE-2018-7842

    Last Modified: 21 Nov 2024

    A CWE-290: Authentication Bypass by Spoofing vulnerability exists in all versions of the Modicon M580, Modicon M340, Modicon Quantum, and Modicon Premium which could cause an elevation of privilege by conducting a brute force attack on Modbus parameters sent to the controller.

    Published:22 May 2019
    9.8
    Critical

    CVE-2018-7841

    Last Modified: 14 May 2019

    A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an improper set of characters is entered.

    Source:Julien Ahrens
    Published:22 May 2019
    8.8
    High

    CVE-2018-7777

    Last Modified: 3 Feb 2020

    The vulnerability is due to insufficient handling of update_file request parameter on update_module.php in Schneider Electric U.motion Builder software versions prior to v1.3.4. A remote, authenticated attacker can exploit this vulnerability by sending a crafted request to the target server.

    Source:Cosmin Craciun
    Published:3 Jul 2018
    9.8
    Critical

    CVE-2018-7756

    Last Modified: 12 Mar 2018

    RunExeFile.exe in the installer for DEWESoft X3 SP1 (64-bit) devices does not require authentication for sessions on TCP port 1999, which allows remote attackers to execute arbitrary code or access internal commands, as demonstrated by a RUN command that launches a .EXE file located at an arbitrary external URL, or a "SETFIREWALL Off" command.

    Source:hyp3rlinx
    Published:14 Mar 2018
    9.8
    Critical

    CVE-2018-7750

    Last Modified: 29 Oct 2018

    transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by channel-open. A customized SSH client can simply skip the authentication step.

    Source:Adam Brown
    Published:13 Mar 2018
    4.8
    Medium

    CVE-2018-7747

    Last Modified: 18 Apr 2018

    Multiple cross-site scripting (XSS) vulnerabilities in the Caldera Forms plugin before 1.6.0-rc.1 for WordPress allow remote attackers to inject arbitrary web script or HTML via vectors involving (1) a greeting message, (2) the email transaction log, or (3) an imported form.

    Source:Federico Scalco
    Published:20 Apr 2018
    8.8
    High

    CVE-2018-7746

    Last Modified: 8 Jun 2018

    An issue was discovered in Western Bridge Cobub Razor 0.7.2. Authentication is not required for /index.php?/manage/channel/modifychannel. For example, with a crafted channel name, stored XSS is triggered during a later /index.php?/manage/channel request by an admin.

    Source:ppb
    Published:7 Mar 2018