Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2009-5153 1 Microfocus 1 Netware 2018-12-20 7.5 HIGH 9.8 CRITICAL
In Novell NetWare before 6.5 SP8, a stack buffer overflow in processing of CALLIT RPC calls in the NFS Portmapper daemon in PKERNEL.NLM allowed remote unauthenticated attackers to execute code, because a length field was incorrectly trusted.
CVE-2018-13350 1 Terra-master 1 Terramaster Operating System 2018-12-19 7.5 HIGH 9.8 CRITICAL
SQL injection in logtable.php in TerraMaster TOS version 3.1.03 allows attackers to execute SQL queries via the "Event" parameter.
CVE-2018-14957 1 Isweb 1 Isweb 2018-12-19 7.5 HIGH 9.8 CRITICAL
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the application because credentials are present in that config.php file).
CVE-2018-19530 1 Httl Project 1 Httl 2018-12-19 7.5 HIGH 9.8 CRITICAL
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses XStream unsafely when configured with an xml.codec=httl.spi.codecs.XstreamCodec setting.
CVE-2018-19531 1 Httl Project 1 Httl 2018-12-19 7.5 HIGH 9.8 CRITICAL
HTTL (aka Hyper-Text Template Language) through 1.0.11 allows remote command execution because the decodeXml function uses java.beans.XMLEncoder unsafely when configured without an xml.codec= setting.
CVE-2018-19528 1 Tp-link 2 Tl-wr886n, Tl-wr886n Firmware 2018-12-19 10.0 HIGH 9.8 CRITICAL
TP-Link TL-WR886N 7.0 1.1.0 devices allow remote attackers to cause a denial of service (Tlb Load Exception) via crafted DNS packets to port 53/udp.
CVE-2018-19468 1 Hucart 1 Hucart 2018-12-19 7.5 HIGH 9.8 CRITICAL
HuCart 5.7.4 has SQL injection in get_ip() in system/class/helper_class.php via the X-Forwarded-For HTTP header to the user/index.php?load=login&act=act_login URI.
CVE-2018-19557 1 Arcms Project 1 Arcms 2018-12-19 7.5 HIGH 9.8 CRITICAL
An issue was discovered in arcms through 2018-03-19. No authentication is required for index/main, user/useradd, or img/images.
CVE-2018-19558 1 Arcms Project 1 Arcms 2018-12-19 7.5 HIGH 9.8 CRITICAL
An issue was discovered in arcms through 2018-03-19. SQL injection exists via the json/newslist limit parameter because of ctl/main/Json.php, ctl/main/service/Data.php, and comp/Db/Mysql.php.
CVE-2018-18861 1 Pcman Ftp Server Project 1 Pcman Ftp Server 2018-12-18 7.5 HIGH 9.8 CRITICAL
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
CVE-2018-19559 1 Cuppacms 1 Cuppacms 2018-12-18 7.5 HIGH 9.8 CRITICAL
CuppaCMS before 2018-11-12 has SQL Injection in administrator/classes/ajax/functions.php via the reference_id parameter.
CVE-2018-18822 1 Grapixel 1 New Media 2018-12-18 7.5 HIGH 9.8 CRITICAL
Grapixel New Media v2.0 allows SQL Injection via the pages.aspx pageref parameter.
CVE-2016-10731 1 Projectsend 1 Projectsend 2018-12-18 7.5 HIGH 9.8 CRITICAL
ProjectSend (formerly cFTP) r582 allows SQL injection via manage-files.php with the request parameter status, manage-files.php with the request parameter files, clients.php with the request parameter selected_clients, clients.php with the request parameter status, process-zip-download.php with the request parameter file, or home-log.php with the request parameter action.
CVE-2018-9207 1 Hayageek 1 Jquery Upload File 2018-12-18 7.5 HIGH 9.8 CRITICAL
Arbitrary file upload in jQuery Upload File <= 4.0.2
CVE-2018-18801 1 Bsen Ordering Software Project 1 Bsen Ordering Software 2018-12-18 7.5 HIGH 9.8 CRITICAL
The BSEN Ordering software 1.0 has SQL Injection via student/index.php?view=view&id=[SQL] or index.php?q=single-item&id=[SQL].
CVE-2018-18793 1 School Event Management System Project 1 School Event Management System 2018-12-18 7.5 HIGH 9.8 CRITICAL
School Event Management System 1.0 allows Arbitrary File Upload via event/controller.php?action=photos.
CVE-2018-18796 1 Library Management System Project 1 Library Management System 2018-12-18 7.5 HIGH 9.8 CRITICAL
Library Management System 1.0 has SQL Injection via the "Search for Books" screen.
CVE-2018-18795 1 School Event Management System Project 1 School Event Management System 2018-12-18 7.5 HIGH 9.8 CRITICAL
School Event Management System 1.0 has SQL Injection via the student/index.php or event/index.php id parameter.
CVE-2018-18763 1 Saltos 1 Saltos 2018-12-18 7.5 HIGH 9.8 CRITICAL
SaltOS 3.1 r8126 allows action=ajax&query=numbers&page=usuarios&action2=[SQL] SQL Injection.
CVE-2018-9209 1 Fineuploader 1 Php-traditional-server 2018-12-18 7.5 HIGH 9.8 CRITICAL
Unauthenticated arbitrary file upload vulnerability in FineUploader php-traditional-server <= v1.2.2
CVE-2018-18806 1 School Equipment Monitoring System Project 1 School Equipment Monitoring System 2018-12-17 7.5 HIGH 9.8 CRITICAL
School Equipment Monitoring System 1.0 allows SQL injection via the login screen, related to include/user.vb.
CVE-2018-18804 1 Bakeshop Inventory System Project 1 Bakeshop Inventory System 2018-12-17 7.5 HIGH 9.8 CRITICAL
Bakeshop Inventory System 1.0 has SQL injection via the login screen, related to include/publicfunction.vb.
CVE-2018-18803 1 Curriculum Evaluation System Project 1 Curriculum Evaluation System 2018-12-17 7.5 HIGH 9.8 CRITICAL
Curriculum Evaluation System 1.0 allows SQL Injection via the login screen, related to frmCourse.vb and includes/user.vb.
CVE-2018-0694 1 Soliton 1 Filezen 2018-12-17 10.0 HIGH 9.8 CRITICAL
FileZen V3.0.0 to V4.2.1 allows remote attackers to execute arbitrary OS commands via unspecified vectors.
CVE-2018-17411 1 Informationbuilders 1 Data Quality Suite 2018-12-17 10.0 HIGH 9.8 CRITICAL
An XML External Entity (XXE) vulnerability exists in iWay Data Quality Suite Web Console 10.6.1.ga-2016-11-20.
CVE-2018-0681 1 Neo 2 Debun Imap, Debun Pop 2018-12-17 7.5 HIGH 9.8 CRITICAL
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to login to the Management page and change the configuration.
CVE-2018-0680 1 Neo 2 Debun Imap, Debun Pop 2018-12-17 7.5 HIGH 9.8 CRITICAL
Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) uses hard-coded credentials, which may allow remote attackers to read/send mail or change the configuration.
CVE-2018-0683 1 Neo 2 Debun Imap, Debun Pop 2018-12-17 7.5 HIGH 9.8 CRITICAL
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R4.0 and earlier, Denbun IMAP version V3.3I R4.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via Cookie data.
CVE-2018-0684 1 Neo 2 Debun Imap, Debun Pop 2018-12-17 7.5 HIGH 9.8 CRITICAL
Buffer overflow in Denbun by NEOJAPAN Inc. (Denbun POP version V3.3P R3.0 and earlier, Denbun IMAP version V3.3I R3.0 and earlier) allows remote attackers to execute arbitrary code or cause a denial-of-service (DoS) condition via multipart/form-data format data.
CVE-2018-17881 1 D-link 2 Dir-823g, Dir-823g Firmware 2018-12-17 5.0 MEDIUM 9.8 CRITICAL
On D-Link DIR-823G 2018-09-19 devices, the GoAhead configuration allows /HNAP1 SetPasswdSettings commands without authentication to trigger an admin password change.
CVE-2018-9356 1 Google 1 Android 2018-12-14 10.0 HIGH 9.8 CRITICAL
In bnep_data_ind of bnep_main.c, there is a possible remote code execution due to a double free. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74950468.
CVE-2018-9355 1 Google 1 Android 2018-12-14 10.0 HIGH 9.8 CRITICAL
In bta_dm_sdp_result of bta_dm_act.cc, there is a possible out of bounds stack write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-74016921.
CVE-2018-18476 1 Nedap 1 Mysql-binuuid-rails 2018-12-13 7.5 HIGH 9.8 CRITICAL
mysql-binuuid-rails 1.1.0 and earlier allows SQL Injection because it removes default string escaping for affected database columns.
CVE-2018-18963 1 Degraupublicidade 1 Degraupublicidade 2018-12-13 7.5 HIGH 9.8 CRITICAL
Busca.aspx.cs in Degrau Publicidade e Internet Plataforma de E-commerce allows SQL Injection via the busca/ URI.
CVE-2018-19196 1 Xiaocms 1 Xiaocms 2018-12-13 7.5 HIGH 9.8 CRITICAL
An issue was discovered in XiaoCms 20141229. It allows remote attackers to execute arbitrary code by using the type parameter to bypass the standard admin\controller\uploadfile.php restrictions on uploaded file types (jpg, jpeg, bmp, png, gif), as demonstrated by an admin/index.php?c=uploadfile&a=uploadify_upload&type=php URI.
CVE-2018-19081 2 Foscam, Opticam 6 C2, C2 Application Firmware, C2 System Firmware and 3 more 2018-12-13 10.0 HIGH 9.8 CRITICAL
An issue was discovered on Foscam Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The ONVIF devicemgmt SetDNS method allows remote attackers to execute arbitrary OS commands via the IPv4Address field.
CVE-2018-17983 1 Mercurial 1 Mercurial 2018-12-13 6.4 MEDIUM 9.1 CRITICAL
cext/manifest.c in Mercurial before 4.7.2 has an out-of-bounds read during parsing of a malformed manifest entry.
CVE-2014-10075 1 Karo Project 1 Karo 2018-12-13 7.5 HIGH 9.8 CRITICAL
The karo gem 2.3.8 for Ruby allows Remote command injection via the host field.
CVE-2018-0645 1 Bit-part 1 Mtappjquery 2018-12-13 7.5 HIGH 9.8 CRITICAL
MTAppjQuery 1.8.1 and earlier allows remote PHP code execution via unspecified vectors.
CVE-2018-9446 1 Google 1 Android 2018-12-12 10.0 HIGH 9.8 CRITICAL
In smp_br_state_machine_event of smp_br_main.cc, there is a possible out of bounds write due to memory corruption. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. Product: Android Versions: Android-6.0 Android-6.0.1 Android-7.0 Android-7.1.1 Android-7.1.2 Android-8.0 Android-8.1 Android ID: A-80145946.
CVE-2018-19126 1 Prestashop 1 Prestashop 2018-12-12 7.5 HIGH 9.8 CRITICAL
PrestaShop 1.6.x before 1.6.1.23 and 1.7.x before 1.7.4.4 allows remote attackers to execute arbitrary code via a file upload.
CVE-2018-19180 1 Yunucms 1 Yunucms 2018-12-12 7.5 HIGH 9.8 CRITICAL
statics/app/index/controller/Install.php in YUNUCMS 1.1.5 (if install.lock is not present) allows remote attackers to execute arbitrary PHP code by placing this code in the index.php?s=index/install/setup2 DB_PREFIX field, which is written to database.php.
CVE-2018-19220 1 Laobancms 1 Laobancms 2018-12-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in LAOBANCMS 2.0. It allows remote attackers to execute arbitrary PHP code via the host parameter to the install/ URI.
CVE-2018-19221 1 Laobancms 1 Laobancms 2018-12-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in LAOBANCMS 2.0. It allows SQL Injection via the admin/login.php guanliyuan parameter.
CVE-2018-3892 1 Yitechnology 2 Yi Home Camera, Yi Home Camera Firmware 2018-12-11 7.5 HIGH 9.8 CRITICAL
An exploitable firmware downgrade vulnerability exists in the time syncing functionality of Yi Home Camera 27US 1.8.7.0D. A specially crafted packet can cause a buffer overflow, resulting in code execution. An attacker can intercept and alter network traffic to trigger this vulnerability.
CVE-2018-18830 1 Mingsoft 1 Mcms 2018-12-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files without setting a cookie. First, start an upload of JSP code with a .png filename, and then intercept the data packet. In the name parameter, change the suffix to jsp. In the response, the server returns the storage path of the file, which can be accessed to execute arbitrary JSP code.
CVE-2018-18934 1 Popojicms 1 Popojicms 2018-12-11 7.5 HIGH 9.8 CRITICAL
An issue was discovered in PopojiCMS v2.0.1. admin_component.php is exploitable via the po-admin/route.php?mod=component&act=addnew URI by using the fupload parameter to upload a ZIP file containing arbitrary PHP code (that is extracted and can be executed). This can also be exploited via CSRF.
CVE-2018-19076 2 Foscam, Opticam 6 C2, C2 Application Firmware, C2 System Firmware and 3 more 2018-12-11 5.0 MEDIUM 9.8 CRITICAL
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The FTP and RTSP services make it easier for attackers to conduct brute-force authentication attacks, because failed-authentication limits apply only to HTTP (not FTP or RTSP).
CVE-2018-19063 2 Foscam, Opticam 6 C2, C2 Application Firmware, C2 System Firmware and 3 more 2018-12-11 10.0 HIGH 9.8 CRITICAL
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. The admin account has a blank password.
CVE-2018-19067 2 Foscam, Opticam 6 C2, C2 Application Firmware, C2 System Firmware and 3 more 2018-12-11 10.0 HIGH 9.8 CRITICAL
An issue was discovered on Foscam C2 devices with System Firmware 1.11.1.8 and Application Firmware 2.72.1.32, and Opticam i5 devices with System Firmware 1.5.2.11 and Application Firmware 2.21.1.128. There is a hardcoded Ak47@99 password for the factory~ account.