9.8
    Critical

    CVE-2018-5975

    Last Modified: 16 Feb 2018

    SQL Injection exists in the Smart Shoutbox 3.0.0 component for Joomla! via the shoutauthor parameter to the archive URI.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5974

    Last Modified: 16 Feb 2018

    SQL Injection exists in the SimpleCalendar 3.1.9 component for Joomla! via the catid array parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5973

    Last Modified: 24 Jan 2018

    SQL Injection exists in Professional Local Directory Script 1.0 via the sellers_subcategories.php IndustryID parameter, or the suppliers.php IndustryID or CategoryID parameter.

    Source:Ihsan Sencan
    Published:25 Jan 2018
    9.8
    Critical

    CVE-2018-5972

    Last Modified: 23 Jan 2018

    SQL Injection exists in Classified Ads CMS Quickad 4.0 via the keywords, placeid, cat, or subcat parameter to the listing URI.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    9.8
    Critical

    CVE-2018-5971

    Last Modified: 16 Feb 2018

    SQL Injection exists in the MediaLibrary Free 4.0.12 component for Joomla! via the id parameter or the mid array parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    9.8
    Critical

    CVE-2018-5970

    Last Modified: 16 Feb 2018

    SQL Injection exists in the JGive 2.0.9 component for Joomla! via the filter_org_ind_type or campaign_countries parameter.

    Source:Ihsan Sencan
    Published:17 Feb 2018
    8.8
    High

    CVE-2018-5969

    Last Modified: 23 Jan 2018

    Cross Site Request Forgery (CSRF) exists in Photography CMS 1.0 via clients/resources/ajax/ajax_new_admin.php, as demonstrated by adding an admin account.

    Source:Ihsan Sencan
    Published:24 Jan 2018
    8.1
    High

    CVE-2018-5968

    Last Modified: 21 Nov 2024

    FasterXML jackson-databind through 2.8.11 and 2.9.x through 2.9.3 allows unauthenticated remote code execution because of an incomplete fix for the CVE-2017-7525 and CVE-2017-17485 deserialization flaws. This is exploitable via two different gadgets that bypass a blacklist.

    Published:18 Jan 2018
    9.8
    Critical

    CVE-2018-5955

    Last Modified: 15 Feb 2018

    An issue was discovered in GitStack through 2.3.10. User controlled input is not sufficiently filtered, allowing an unauthenticated attacker to add a user to the server via the username and password fields to the rest/user/ URI.

    Source:SecuriTeam
    Published:21 Jan 2018
    7.5
    High

    CVE-2018-5954

    Last Modified: 21 Jan 2018

    phpFreeChat 1.7 and earlier allows remote attackers to cause a denial of service by sending a large number of connect commands.

    Source:A. Pakbaz
    Published:25 Jan 2018
    7.5
    High

    CVE-2018-5951

    Last Modified: 21 Nov 2024

    An issue was discovered in Mikrotik RouterOS. Crafting a packet that has a size of 1 byte and sending it to an IPv6 address of a RouterOS box with IP Protocol 97 will cause RouterOS to reboot imminently. All versions of RouterOS that supports EoIPv6 are vulnerable to this attack.

    Published:2 Mar 2020
    7
    High

    CVE-2018-5873

    Last Modified: 21 Nov 2024

    An issue was discovered in the __ns_get_path function in fs/nsfs.c in the Linux kernel before 4.11. Due to a race condition when accessing files, a Use After Free condition can occur. This also affects all Android releases from CAF using the Linux kernel (Android for MSM, Firefox OS for MSM, QRD Android) before security patch level 2018-07-05.

    Published:19 Apr 2017
    5.5
    Medium

    CVE-2018-5803

    Last Modified: 21 Nov 2024

    In the Linux Kernel before version 4.15.8, 4.14.25, 4.9.87, 4.4.121, 4.1.51, and 3.2.102, an error in the "_sctp_make_chunk()" function (net/sctp/sm_make_chunk.c) when handling SCTP packets length can be exploited to cause a kernel crash.

    Published:9 Feb 2018
    9.8
    Critical

    CVE-2018-5782

    Last Modified: 16 Jan 2019

    A vulnerability in the conferencing component of Mitel Connect ONSITE, versions R1711-PREM and earlier, and Mitel ST 14.2, release GA28 and earlier, could allow an unauthenticated attacker to inject PHP code using specially crafted requests to the vsethost.php page. Successful exploit could allow an attacker to execute arbitrary PHP code within the context of the application.

    Source:twosevenzero
    Published:14 Mar 2018
    9.8
    Critical

    CVE-2018-5767

    Last Modified: 6 Mar 2018

    An issue was discovered on Tenda AC15 V15.03.1.16_multi devices. A remote, unauthenticated attacker can gain remote code execution on the device with a crafted password parameter for the COOKIE header.

    Source:Tim Carrington
    Published:15 Feb 2018
    7.5
    High

    CVE-2018-5764

    Last Modified: 21 Nov 2024

    The parse_arguments function in options.c in rsyncd in rsync before 3.1.3 does not prevent multiple --protect-args uses, which allows remote attackers to bypass an argument-sanitization protection mechanism.

    Published:17 Jan 2018
    5.5
    Medium

    CVE-2018-5759

    Last Modified: 28 Jan 2018

    jsparse.c in Artifex MuJS through 1.0.2 does not properly maintain the AST depth for binary expressions, which allows remote attackers to cause a denial of service (excessive recursion) via a crafted file.

    Source:Andrea Sindoni
    Published:24 Jan 2018
    4.3
    Medium

    CVE-2018-5756

    Last Modified: 12 Jun 2018

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 does not properly check for folder-to-object association, which allows remote authenticated users to delete arbitrary tasks via the task id in a delete action to api/tasks.

    Source:Open-Xchange
    Published:15 Jun 2018
    5.5
    Medium

    CVE-2018-5755

    Last Modified: 12 Jun 2018

    Absolute path traversal vulnerability in the readerengine component in Open-Xchange OX App Suite before 7.6.3-rev3, 7.8.x before 7.8.2-rev4, 7.8.3 before 7.8.3-rev5, and 7.8.4 before 7.8.4-rev4 allows remote attackers to read arbitrary files via a full pathname in a formula in a spreadsheet.

    Source:Open-Xchange
    Published:15 Jun 2018
    5.4
    Medium

    CVE-2018-5754

    Last Modified: 12 Jun 2018

    Cross-site scripting (XSS) vulnerability in the office-web component in Open-Xchange OX App Suite before 7.8.3-rev12 and 7.8.4 before 7.8.4-rev9 allows remote attackers to inject arbitrary web script or HTML via a crafted presentation file, related to copying content to the clipboard.

    Source:Open-Xchange
    Published:15 Jun 2018
    6.5
    Medium

    CVE-2018-5753

    Last Modified: 12 Jun 2018

    The frontend component in Open-Xchange OX App Suite before 7.6.3-rev31, 7.8.x before 7.8.2-rev31, 7.8.3 before 7.8.3-rev41, and 7.8.4 before 7.8.4-rev20 allows remote attackers to spoof the origin of e-mails via unicode characters in the "personal part" of a (1) From or (2) Sender address.

    Source:Open-Xchange
    Published:15 Jun 2018
    8.8
    High

    CVE-2018-5752

    Last Modified: 12 Jun 2018

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote attackers to conduct server-side request forgery (SSRF) attacks via vectors involving non-decimal representations of IP addresses and special IPv6 related addresses.

    Source:Open-Xchange
    Published:15 Jun 2018
    6.5
    Medium

    CVE-2018-5751

    Last Modified: 12 Jun 2018

    The backend component in Open-Xchange OX App Suite before 7.6.3-rev36, 7.8.x before 7.8.2-rev39, 7.8.3 before 7.8.3-rev44, and 7.8.4 before 7.8.4-rev22 allows remote authenticated users to obtain sensitive information about external guest users via vectors related to the "groups" and "users" APIs.

    Source:Open-Xchange
    Published:15 Jun 2018
    7.5
    High

    CVE-2018-5740

    Last Modified: 21 Nov 2024

    "deny-answer-aliases" is a little-used feature intended to help recursive server operators protect end users against DNS rebinding attacks, a potential method of circumventing the security model used by client browsers. However, a defect in this feature makes it easy, when the feature is in use, to experience an assertion failure in name.c. Affects BIND 9.7.0->9.8.8, 9.9.0->9.9.13, 9.10.0->9.10.8, 9.11.0->9.11.4, 9.12.0->9.12.2, 9.13.0->9.13.2.

    Published:8 Aug 2018
    9.8
    Critical

    CVE-2018-5726

    Last Modified: 17 Jan 2018

    MASTER IPCAMERA01 3.3.4.2103 devices allow remote attackers to obtain sensitive information via a crafted HTTP request, as demonstrated by the username, password, and configuration settings.

    Source:Raffaele Sabato
    Published:16 Jan 2018
    7.5
    High

    CVE-2018-5725

    Last Modified: 17 Jan 2018

    MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Change, as demonstrated by the port number of the web server.

    Source:Raffaele Sabato
    Published:16 Jan 2018
    9.8
    Critical

    CVE-2018-5724

    Last Modified: 17 Jan 2018

    MASTER IPCAMERA01 3.3.4.2103 devices allow Unauthenticated Configuration Download and Upload, as demonstrated by restore.cgi.

    Source:Raffaele Sabato
    Published:16 Jan 2018
    9.8
    Critical

    CVE-2018-5723

    Last Modified: 17 Jan 2018

    MASTER IPCAMERA01 3.3.4.2103 devices have a hardcoded password of cat1029 for the root account.

    Source:Raffaele Sabato
    Published:16 Jan 2018
    8.8
    High

    CVE-2018-5720

    Last Modified: 26 Jan 2018

    An issue was discovered on DODOCOOL DC38 3-in-1 N300 Mini Wireless Range Extend RTN2-AW.GD.R3465.1.20161103 devices. A Cross-site request forgery (CSRF) vulnerability allows remote attackers to hijack the authentication of users for requests that modify all the settings. This vulnerability can lead to changing an existing user's username and password, changing the Wi-Fi password, etc.

    Source:Raffaele Sabato
    Published:29 Jan 2018
    6.1
    Medium

    CVE-2018-5715

    Last Modified: 17 Jan 2018

    phprint.php in SugarCRM 3.5.1 has XSS via a parameter name in the query string (aka a $key variable).

    Source:Guilherme Assmann
    Published:16 Jan 2018
    5.5
    Medium

    CVE-2018-5711

    Last Modified: 21 Nov 2024

    gd_gif_in.c in the GD Graphics Library (aka libgd), as used in PHP before 5.6.33, 7.0.x before 7.0.27, 7.1.x before 7.1.13, and 7.2.x before 7.2.1, has an integer signedness error that leads to an infinite loop via a crafted GIF file, as demonstrated by a call to the imagecreatefromgif or imagecreatefromstring PHP function. This is related to GetCode_ and gdImageCreateFromGifCtx.

    Published:25 Nov 2017
    8
    High

    CVE-2018-5708

    Last Modified: 2 Apr 2018

    An issue was discovered on D-Link DIR-601 B1 2.02NA devices. Being on the same local network as, but being unauthenticated to, the administrator's panel, a user can obtain the admin username and cleartext password in the response (specifically, the configuration file restore_default), which is displayed in XML.

    Source:Kevin Randall
    Published:30 Mar 2018
    6.1
    Medium

    CVE-2018-5705

    Last Modified: 17 Jan 2018

    Reservo Image Hosting 1.6 is vulnerable to XSS attacks. The affected function is its search engine (the t parameter to the /search URI). Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.

    Source:Dennis Veninga
    Published:24 Jan 2018
    8.8
    High

    CVE-2018-5702

    Last Modified: 17 Jan 2018

    Transmission through 2.92 relies on X-Transmission-Session-Id (which is not a forbidden header for Fetch) for access control, which allows remote attackers to execute arbitrary RPC commands, and consequently write to arbitrary files, via POST requests to /transmission/rpc in conjunction with a DNS rebinding attack.

    Source:Google Security Research
    Published:15 Jan 2018
    9.8
    Critical

    CVE-2018-5701

    Last Modified: 25 Mar 2023

    In Iolo System Shield AntiVirus and AntiSpyware 5.0.0.136, the amp.sys driver file contains an Arbitrary Write vulnerability due to not validating input values from IOCtl 0x00226003.

    Source:Brandon Marshall
    Published:31 Jan 2018
    6.1
    Medium

    CVE-2018-5688

    Last Modified: 15 Jan 2018

    ILIAS before 5.2.4 has XSS via the cmd parameter to the displayHeader function in setup/classes/class.ilSetupGUI.php in the Setup component.

    Source:Florian Kunushevci
    Published:14 Jan 2018
    7.2
    High

    CVE-2018-5511

    Last Modified: 25 Mar 2019

    On F5 BIG-IP 13.1.0-13.1.0.3 or 13.0.0, when authenticated administrative users execute commands in the Traffic Management User Interface (TMUI), also referred to as the BIG-IP Configuration utility, restrictions on allowed commands may not be enforced.

    Source:Google Security Research
    Published:13 Apr 2018
    6.1
    Medium

    CVE-2018-5479

    Last Modified: 15 Jan 2018

    FoxSash ImgHosting 1.5 (according to footer information) is vulnerable to XSS attacks. The affected function is its search engine via the search parameter to the default URI. Since there is an user/admin login interface, it's possible for attackers to steal sessions of users and thus admin(s). By sending users an infected URL, code will be executed.

    Source:Dennis Veninga
    Published:15 Jan 2018
    8.8
    High

    CVE-2018-5430

    Last Modified: 15 May 2018

    The Spring web flows of TIBCO Software Inc.'s TIBCO JasperReports Server, TIBCO JasperReports Server Community Edition, TIBCO JasperReports Server for ActiveMatrix BPM, TIBCO Jaspersoft for AWS with Multi-Tenancy, and TIBCO Jaspersoft Reporting and Analytics for AWS contain a vulnerability which may allow any authenticated user read-only access to the contents of the web application, including key configuration files. Affected releases include TIBCO Software Inc.'s TIBCO JasperReports Server: versions up to and including 6.2.4; 6.3.0; 6.3.2; 6.3.3;6.4.0; 6.4.2, TIBCO JasperReports Server Community Edition: versions up to and including 6.4.2, TIBCO JasperReports Server for ActiveMatrix BPM: versions up to and including 6.4.2, TIBCO Jaspersoft for AWS with Multi-Tenancy: versions up to and including 6.4.2, TIBCO Jaspersoft Reporting and Analytics for AWS: versions up to and including 6.4.2.

    Source:Hector Monsegur
    Published:17 Apr 2018
    7.8
    High

    CVE-2018-5410

    Last Modified: 13 Feb 2019

    Dokan, versions between 1.0.0.5000 and 1.2.0.1000, are vulnerable to a stack-based buffer overflow in the dokan1.sys driver. An attacker can create a device handle to the system driver and send arbitrary input that will trigger the vulnerability. This vulnerability was introduced in the 1.0.0.5000 version update.

    Source:Parvez Anwar
    Published:7 Jan 2019
    4.7
    Medium

    CVE-2018-5407

    Last Modified: 5 Nov 2018

    Simultaneous Multi-threading (SMT) in processors can enable local users to exploit software vulnerable to timing attacks via a side-channel timing attack on 'port contention'.

    Source:Billy Brumley
    Published:30 Oct 2018
    8.8
    High

    CVE-2018-5406

    Last Modified: 3 Jun 2019

    The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows a remote attacker to exploit the misconfigured Cross-Origin Resource Sharing (CORS) mechanism. An unauthenticated, remote attacker could exploit this vulnerability to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. A malicious internal user could also gain administrator privileges of this appliance and use it to visit a malicious link that exploits this vulnerability. This could cause the application to perform sensitive actions such as adding a new administrator account or changing the appliance’s settings. An unauthenticated, remote attacker could add an administrator-level account or change the appliance's settings.

    Source:SlidingWindow
    Published:3 Jun 2019
    5.4
    Medium

    CVE-2018-5405

    Last Modified: 3 Jun 2019

    The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated least privileged user with 'User Console Only' rights to potentially inject arbitrary JavaScript code on the tickets page. Script execution could allow a malicious user of the system to steal session cookies of other users including Administrator and take over their session. This can further be exploited to launch other attacks. The software also does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users. The software does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other user. An authenticated user with 'user console only' rights may inject arbitrary JavaScript, which could result in an attacker taking over a session of others, including an Administrator.

    Source:SlidingWindow
    Published:3 Jun 2019
    6.5
    Medium

    CVE-2018-5404

    Last Modified: 3 Jun 2019

    The Quest Kace K1000 Appliance, versions prior to 9.0.270, allows an authenticated, remote attacker with least privileges ('User Console Only' role) to potentially exploit multiple Blind SQL Injection vulnerabilities to retrieve sensitive information from the database or copy the entire database. An authenticated remote attacker could leverage Blind SQL injections to obtain sensitive data.

    Source:SlidingWindow
    Published:3 Jun 2019
    6.1
    Medium

    CVE-2018-5370

    Last Modified: 12 Jan 2018

    BizLogic xnami 1.0 has XSS via the comment parameter in an addComment action to the /media/ajax URI.

    Source:Dennis Veninga
    Published:16 Jan 2018
    8.1
    High

    CVE-2018-5359

    Last Modified: 15 Jan 2018

    The server in Flexense SysGauge 3.6.18 operating on port 9221 can be exploited remotely with the attacker gaining system-level access because of a Buffer Overflow.

    Source:Ahmad Mahfouz
    Published:23 Jan 2018
    8.8
    High

    CVE-2018-5354

    Last Modified: 21 Nov 2024

    The custom GINA/CP module in ANIXIS Password Reset Client before version 3.22 allows remote attackers to execute code and escalate privileges via spoofing. When the client is configured to use HTTP, it does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP.

    Published:29 Sept 2020
    9.8
    Critical

    CVE-2018-5353

    Last Modified: 21 Nov 2024

    The custom GINA/CP module in Zoho ManageEngine ADSelfService Plus before 5.5 build 5517 allows remote attackers to execute code and escalate privileges via spoofing. It does not authenticate the intended server before opening a browser window. An unauthenticated attacker capable of conducting a spoofing attack can redirect the browser to gain execution in the context of the WinLogon.exe process. If Network Level Authentication is not enforced, the vulnerability can be exploited via RDP. Additionally, if the web server has a misconfigured certificate then no spoofing attack is required

    Published:29 Sept 2020
    9.8
    Critical

    CVE-2018-5347

    Last Modified: 16 Jan 2018

    Seagate Media Server in Seagate Personal Cloud has unauthenticated command injection in the uploadTelemetry and getLogs functions in views.py because .psp URLs are handled by the fastcgi.server component and shell metacharacters are mishandled.

    Source:SecuriTeam
    Published:12 Jan 2018
    5.5
    Medium

    CVE-2018-5333

    Last Modified: 23 Jan 2020

    In the Linux kernel through 4.14.13, the rds_cmsg_atomic function in net/rds/rdma.c mishandles cases where page pinning fails or an invalid address is supplied, leading to an rds_atomic_free_op NULL pointer dereference.

    Source:Metasploit
    Published:3 Jan 2018