5.4
    Medium

    CVE-2018-6227

    Last Modified: 22 Feb 2018

    A stored cross-site scripting (XSS) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject client-side scripts into vulnerable systems.

    Source:Core Security
    Published:15 Mar 2018
    5.4
    Medium

    CVE-2018-6226

    Last Modified: 22 Feb 2018

    Reflected cross-site scripting (XSS) vulnerabilities in two Trend Micro Email Encryption Gateway 5.5 configuration files could allow an attacker to inject client-side scripts into vulnerable systems.

    Source:Core Security
    Published:15 Mar 2018
    4.3
    Medium

    CVE-2018-6225

    Last Modified: 22 Feb 2018

    An XML external entity injection (XXE) vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an authenticated user to expose a normally protected configuration script.

    Source:Core Security
    Published:15 Mar 2018
    8.8
    High

    CVE-2018-6224

    Last Modified: 22 Feb 2018

    A lack of cross-site request forgery (CSRF) protection vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to submit authenticated requests to a user browsing an attacker-controlled domain.

    Source:Core Security
    Published:15 Mar 2018
    9.8
    Critical

    CVE-2018-6223

    Last Modified: 22 Feb 2018

    A missing authentication for appliance registration vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to manipulate the registration process of the product to reset configuration parameters.

    Source:Core Security
    Published:15 Mar 2018
    7.8
    High

    CVE-2018-6222

    Last Modified: 22 Feb 2018

    Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulated to execute arbitrary commands and attain command execution on a vulnerable system.

    Source:Core Security
    Published:15 Mar 2018
    8.1
    High

    CVE-2018-6221

    Last Modified: 22 Feb 2018

    An unvalidated software update vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow a man-in-the-middle attacker to tamper with an update file and inject their own.

    Source:Core Security
    Published:15 Mar 2018
    9.8
    Critical

    CVE-2018-6220

    Last Modified: 22 Feb 2018

    An arbitrary file write vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to inject arbitrary data, which may lead to gaining code execution on vulnerable systems.

    Source:Core Security
    Published:15 Mar 2018
    6.5
    Medium

    CVE-2018-6219

    Last Modified: 22 Feb 2018

    An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.

    Source:Core Security
    Published:15 Mar 2018
    4.7
    Medium

    CVE-2018-6193

    Last Modified: 28 Feb 2018

    A Cross-Site Scripting (XSS) vulnerability was found in Routers2 2.24, affecting the 'rtr' GET parameter in a page=graph action to cgi-bin/routers2.pl.

    Source:Lorenzo Di Fuccia
    Published:24 Jan 2018
    5.5
    Medium

    CVE-2018-6191

    Last Modified: 28 Jan 2018

    The js_strtod function in jsdtoa.c in Artifex MuJS through 1.0.2 has an integer overflow because of incorrect exponent validation.

    Source:Andrea Sindoni
    Published:24 Jan 2018
    5.4
    Medium

    CVE-2018-6190

    Last Modified: 5 Feb 2018

    Netis WF2419 V3.2.41381 devices allow XSS via the Description field on the MAC Filtering page.

    Source:Sajibe Kanti
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-6180

    Last Modified: 5 Feb 2018

    A flaw in the profile section of Online Voting System 1.0 allows an unauthenticated user to set an arbitrary password for other accounts.

    Source:Giulio Comi
    Published:8 Feb 2018
    6.5
    Medium

    CVE-2018-6130

    Last Modified: 8 Jun 2018

    Incorrect handling of object lifetimes in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Source:Google Security Research
    Published:29 May 2018
    6.5
    Medium

    CVE-2018-6129

    Last Modified: 8 Jun 2018

    Out of bounds array access in WebRTC in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to potentially perform out of bounds memory access via a crafted HTML page.

    Source:Google Security Research
    Published:29 May 2018
    8.8
    High

    CVE-2018-6126

    Last Modified: 27 Jul 2018

    A precision error in Skia in Google Chrome prior to 67.0.3396.62 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page.

    Source:Google Security Research
    Published:29 May 2018
    8.8
    High

    CVE-2018-6092

    Last Modified: 8 Jun 2018

    An integer overflow on 32-bit systems in WebAssembly in Google Chrome prior to 66.0.3359.117 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.

    Source:Google Security Research
    Published:17 Apr 2018
    7.8
    High

    CVE-2018-6084

    Last Modified: 20 Mar 2018

    Insufficiently sanitized distributed objects in Updater in Google Chrome on macOS prior to 66.0.3359.117 allowed a local attacker to execute arbitrary code via an executable file.

    Source:Google Security Research
    Published:17 Apr 2018
    6.5
    Medium

    CVE-2018-6066

    Last Modified: 21 Nov 2024

    Lack of CORS checking by ResourceFetcher/ResourceLoader in Blink in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to leak cross-origin data via a crafted HTML page.

    Published:6 Mar 2018
    8.8
    High

    CVE-2018-6065

    Last Modified: 4 May 2018

    Integer overflow in computing the required allocation size when instantiating a new javascript object in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Google Security Research
    Published:6 Mar 2018
    8.8
    High

    CVE-2018-6064

    Last Modified: 3 Apr 2018

    Type Confusion in the implementation of __defineGetter__ in V8 in Google Chrome prior to 65.0.3325.146 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page.

    Source:Google Security Research
    Published:6 Mar 2018
    9.8
    Critical

    CVE-2018-6024

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Project Log 1.5.3 component for Joomla! via the search parameter.

    Source:Ihsan Sencan
    Published:18 Feb 2018
    8.8
    High

    CVE-2018-6023

    Last Modified: 11 May 2018

    Fastweb FASTgate 0.00.47 devices are vulnerable to CSRF, with impacts including Wi-Fi password changing, Guest Wi-Fi activating, etc.

    Source:Raffaele Sabato
    Published:11 May 2018
    7.5
    High

    CVE-2018-6008

    Last Modified: 28 Jan 2018

    Arbitrary File Download exists in the Jtag Members Directory 5.3.7 component for Joomla! via the download_file parameter.

    Source:Ihsan Sencan
    Published:29 Jan 2018
    8.8
    High

    CVE-2018-6007

    Last Modified: 28 Jan 2018

    CSRF exists in the JS Support Ticket 1.1.0 component for Joomla! and allows attackers to inject HTML or edit a ticket.

    Source:Ihsan Sencan
    Published:29 Jan 2018
    9.8
    Critical

    CVE-2018-6006

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JS Autoz 1.0.9 component for Joomla! via the vtype, pre, or prs parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6005

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Realpin through 1.5.04 component for Joomla! via the pinboard parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6004

    Last Modified: 16 Feb 2018

    SQL Injection exists in the File Download Tracker 3.0 component for Joomla! via the dynfield[phone] or sess parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-6000

    Last Modified: 26 Feb 2018

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. The do_vpnupload_post function in router/httpd/web.c in vpnupload.cgi provides functionality for setting NVRAM configuration values, which allows attackers to set the admin password and launch an SSH daemon (or enable infosvr command mode), and consequently obtain remote administrative access, via a crafted request. This is available to unauthenticated attackers in conjunction with CVE-2018-5999.

    Source:Metasploit
    Published:22 Jan 2018
    9.8
    Critical

    CVE-2018-5999

    Last Modified: 26 Feb 2018

    An issue was discovered in AsusWRT before 3.0.0.4.384_10007. In the handle_request function in router/httpd/httpd.c, processing of POST requests continues even if authentication fails.

    Source:Metasploit
    Published:22 Jan 2018
    9.8
    Critical

    CVE-2018-5997

    Last Modified: 26 Jan 2018

    An issue was discovered in the HTTP Server in RAVPower Filehub 2.000.056. Due to an unrestricted upload feature and a path traversal vulnerability, it is possible to upload a file on a filesystem with root privileges: this will lead to remote code execution as root.

    Source:Daniele Linguaglossa & Stefano Farletti
    Published:25 Jan 2018
    9.8
    Critical

    CVE-2018-5994

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JS Jobs 1.1.9 component for Joomla! via the zipcode parameter in a newest-jobs request, or the ta parameter in a view_resume request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5993

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Aist through 2.0 component for Joomla! via the id parameter in a view=showvacancy request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5992

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Staff Master through 1.0 RC 1 component for Joomla! via the name parameter in a view=staff request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5991

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Form Maker 3.6.12 component for Joomla! via the id, from, or to parameter in a view=stats request, a different vulnerability than CVE-2015-2798.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5990

    Last Modified: 16 Feb 2018

    SQL Injection exists in the AllVideos Reloaded 1.2.x component for Joomla! via the divid parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5989

    Last Modified: 16 Feb 2018

    SQL Injection exists in the ccNewsletter 2.x component for Joomla! via the id parameter in a task=removeSubscriber action, a related issue to CVE-2011-5099.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5988

    Last Modified: 23 Jan 2018

    SQL Injection exists in Flexible Poll 1.2 via the id parameter to mobile_preview.php or index.php.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5987

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Pinterest Clone Social Pinboard 2.0 component for Joomla! via the pin_id or user_id parameter in a task=getlikeinfo action, the ends parameter in a view=gift action, the category parameter in a view=home action, the uid parameter in a view=pindisplay action, the searchVal parameter in a view=search action, or the uid parameter in a view=likes action.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5986

    Last Modified: 23 Jan 2018

    SQL Injection exists in Easy Car Script 2014 via the s_order or s_row parameter to site_search.php.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5985

    Last Modified: 23 Jan 2018

    SQL Injection exists in the LiveCRM SaaS Cloud 1.0 component for Joomla! via an r=site/login&company_id= request.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5984

    Last Modified: 23 Jan 2018

    SQL Injection exists in the Tumder (An Arcade Games Platform) 2.1 component for Joomla! via the PATH_INFO to the category/ URI.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5983

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JquickContact 1.3.2.2.1 component for Joomla! via a task=refresh&sid= request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5982

    Last Modified: 29 Mar 2019

    SQL Injection exists in the Advertisement Board 3.1.0 component for Joomla! via a task=show_rss_categories&catname= request.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5981

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Gallery WD 1.3.6 component for Joomla! via the tag_id parameter or gallery_id parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5980

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Solidres 2.5.1 component for Joomla! via the direction parameter in a hub.search action.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5979

    Last Modified: 23 Jan 2018

    SQL Injection exists in Wchat Fully Responsive PHP AJAX Chat Script 1.5 via the login.php User field.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5978

    Last Modified: 23 Jan 2018

    SQL Injection exists in Facebook Style Php Ajax Chat Zechat 1.5 via the login.php User field.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5977

    Last Modified: 23 Jan 2018

    SQL Injection exists in Affiligator Affiliate Webshop Management System 2.1.0 via a search/?q=&price_type=range&price= request.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    8.8
    High

    CVE-2018-5976

    Last Modified: 23 Jan 2018

    Cross Site Request Forgery (CSRF) exists in RSVP Invitation Online 1.0 via function/account.php, as demonstrated by modifying the admin password.

    Source:Ihsan Sencan
    Published:24 Jan 2018