Vulnerabilities (CVE)

CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2018-15185 1 Naukri Clone Script Project 1 Naukri Clone Script 2018-10-09 5.5 MEDIUM 6.5 MEDIUM
PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 allows remote attackers to cause a denial of service (page update outage) via crafted PHP and JavaScript code in the "Current Position" field.
CVE-2018-15184 1 Naukri Clone Script Project 1 Naukri Clone Script 2018-10-09 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Naukri / Shine / Jobsite Clone Script 3.0.4 has Stored XSS via the USERNAME field, a related issue to CVE-2018-6795.
CVE-2018-15188 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-10-09 5.5 MEDIUM 6.5 MEDIUM
PHP Scripts Mall advanced-real-estate-script 4.0.9 allows remote attackers to cause a denial of service (page structure loss) via crafted JavaScript code in the Name field of a profile.
CVE-2016-8527 1 Hp 1 Airwave 2018-10-09 4.3 MEDIUM 6.1 MEDIUM
Aruba Airwave all versions up to, but not including, 8.2.3.1 is vulnerable to a reflected cross-site scripting (XSS). The vulnerability is present in the VisualRF component of AirWave. By exploiting this vulnerability, an attacker who can trick a logged-in AirWave administrative user into clicking a link could obtain sensitive information, such as session cookies or passwords. The vulnerability requires that an administrative users click on the malicious link while currently logged into AirWave in the same browser.
CVE-2018-7070 1 Hp 1 Centralview Fraud Risk Management 2018-10-09 5.0 MEDIUM 5.3 MEDIUM
HPE has identified a remote disclosure of information vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.
CVE-2018-7071 1 Hp 1 Network Function Virtualization Director 2018-10-06 4.0 MEDIUM 4.3 MEDIUM
HPE has identified a remote access to sensitive information vulnerability in HPE Network Function Virtualization Director (NFVD) 4.2.1 prior to gui patch 3.
CVE-2018-15191 1 Hotel Booking Script Project 1 Hotel Booking Script 2018-10-06 4.0 MEDIUM 6.5 MEDIUM
PHP Scripts Mall hotel-booking-script 2.0.4 allows remote attackers to cause a denial of service via crafted JavaScript code in the First Name, Last Name, or Address field.
CVE-2018-15190 1 Hotel Booking Script Project 1 Hotel Booking Script 2018-10-06 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall hotel-booking-script 2.0.4 allows XSS via the First Name, Last Name, or Address field.
CVE-2018-15189 1 Advanced Real Estate Script Project 1 Advanced Real Estate Script 2018-10-05 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall advanced-real-estate-script has XSS via the Name field of a profile.
CVE-2018-14503 1 Coremail 1 Coremail Xt 2018-10-05 4.3 MEDIUM 6.1 MEDIUM
Cross-site scripting (XSS) vulnerability in intervalCheck.jsp in Coremail XT 3.0 allows remote attackers to inject arbitrary web script or HTML via the sid parameter.
CVE-2018-14837 1 Wolfcms 1 Wolf Cms 2018-10-05 3.5 LOW 4.8 MEDIUM
Wolf CMS 0.8.3.1 has XSS in the Snippets tab, as demonstrated by a ?/admin/snippet/edit/1 URI.
CVE-2017-13652 1 Netapp 1 Oncommand Insight 2018-10-05 4.3 MEDIUM 6.5 MEDIUM
NetApp OnCommand Insight version 7.3.0 and versions prior to 7.2.0 are susceptible to clickjacking attacks which could cause a user to perform an unintended action in the user interface.
CVE-2016-4392 1 Hp 1 Business Service Management 2018-10-05 3.5 LOW 5.4 MEDIUM
A remote cross site scripting vulnerability has been identified in HP Business Service Management software v9.1x, v9.20 - v9.25IP1.
CVE-2018-15182 1 Car Rental Script Project 1 Car Rental Script 2018-10-05 3.5 LOW 5.4 MEDIUM
PHP Scripts Mall Car Rental Script 2.0.8 has XSS via the FirstName and LastName fields.
CVE-2018-15130 1 Thinksaas 1 Thinksaas 2018-10-05 3.5 LOW 5.4 MEDIUM
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=group&ac=create&ts=do groupdesc parameter.
CVE-2017-8991 1 Hp 1 Centralview Fraud Risk Management 2018-10-05 3.5 LOW 5.4 MEDIUM
HPE has identified a cross site scripting (XSS) vulnerability in HPE CentralView Fraud Risk Management earlier than version CV 6.1. This issue is resolved in HF16 for HPE CV 6.1 or subsequent version.
CVE-2018-7075 1 Hp 1 Intelligent Management Center 2018-10-05 4.3 MEDIUM 6.1 MEDIUM
A remote cross-site scripting (XSS) vulnerability was identified in HPE Intelligent Management Center (iMC) PLAT version v7.3 (E0506). The vulnerability is fixed in Intelligent Management Center PLAT 7.3 E0605P04 or subsequent version.
CVE-2018-15129 1 Thinksaas 1 Thinksaas 2018-10-05 3.5 LOW 5.4 MEDIUM
ThinkSAAS through 2018-07-25 has XSS via the index.php?app=article&ac=comment&ts=do content parameter.
CVE-2018-15169 1 Zohocorp 1 Manageengine Applications Manager 2018-10-05 4.3 MEDIUM 6.1 MEDIUM
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.do method parameter.
CVE-2018-15178 1 Gogs 1 Gogs 2018-10-05 5.8 MEDIUM 6.1 MEDIUM
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to parameter, related to the function isValidRedirect in routes/user/auth.go.
CVE-2016-4400 1 Hp 1 Network Node Manager I 2018-10-04 3.5 LOW 5.4 MEDIUM
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).
CVE-2016-4399 1 Hp 1 Network Node Manager I 2018-10-04 3.5 LOW 5.4 MEDIUM
A security vulnerability was identified in HP Network Node Manager i (NNMi) Software 10.00, 10.01 (patch1), 10.01 (patch 2), 10.10. The vulnerability could result in cross-site scripting (XSS).
CVE-2018-12943 1 Seeddms 1 Seeddms 2018-10-04 4.3 MEDIUM 6.1 MEDIUM
Cross-Site Scripting (XSS) vulnerability in every page that includes the "action" URL parameter in SeedDMS (formerly LetoDMS and MyDMS) before 5.1.8 allows remote attackers to inject arbitrary web script or HTML via the action parameter.
CVE-2018-7992 1 Huawei 8 Mate 9, Mate 9 Firmware, Mate 9 Pro and 5 more 2018-10-04 4.3 MEDIUM 5.5 MEDIUM
Mdapt Driver of Huawei MediaPad M3 BTV-W09C128B353CUSTC128D001; Mate 9 Pro versions earlier than 8.0.0.356(C00); P10 Plus versions earlier than 8.0.0.357(C00) has a buffer overflow vulnerability. The driver does not sufficiently validate the input, an attacker could trick the user to install a malicious application which would send crafted parameters to the driver. Successful exploit could cause a denial of service condition.
CVE-2018-7934 1 Huawei 2 Mate 10 Pro, Mate 10 Pro Firmware 2018-10-04 7.1 HIGH 5.5 MEDIUM
Some Huawei mobile phone with the versions before BLA-L29 8.0.0.145(C432) have a denial of service (DoS) vulnerability because they do not adapt to specific screen gestures. An attacker may trick users into installing a malicious app. As a result, apps running on the frontend crash after the users make specific screen gestures.
CVE-2018-13055 1 Mantisbt 1 Mantisbt 2018-10-04 4.3 MEDIUM 6.1 MEDIUM
A cross-site scripting (XSS) vulnerability in the View Filters page (view_filters_page.php) in MantisBT 2.1.0 through 2.15.0 allows remote attackers to inject arbitrary code (if CSP settings permit it) through a crafted PATH_INFO.
CVE-2016-4406 1 Hp 3 Integrated Lights-out, Integrated Lights-out 3 Firmware, Integrated Lights-out 4 Firmware 2018-10-04 4.3 MEDIUM 6.1 MEDIUM
A remote cross site scripting vulnerability was identified in HPE iLO 3 all version prior to v1.88 and HPE iLO 4 all versions prior to v2.44.
CVE-2018-16449 1 Onethink 1 Onethink 2018-10-04 4.3 MEDIUM 6.5 MEDIUM
OneThink 1.1.141212 allows CSRF for adding a page via admin.php?s=/Channel/add.html, adding a blog via admin.php?s=/Article/update.html, and setting the audit state via admin.php?s=/Article/setStatus/status/1.html.
CVE-2018-14964 1 Emlsoft Project 1 Emlsoft 2018-10-04 3.5 LOW 5.4 MEDIUM
An issue was discovered in EMLsoft 5.4.5. XSS exists via the eml/upload/eml/?action=address&do=edit page.
CVE-2018-1999026 1 Jenkins 1 Tracetronic Ecu-test 2018-10-04 4.0 MEDIUM 6.5 MEDIUM
A server-side request forgery vulnerability exists in Jenkins TraceTronic ECU-TEST Plugin 2.3 and earlier in ATXPublisher.java that allows attackers to have Jenkins send HTTP requests to an attacker-specified host.
CVE-2018-14962 1 Zzcms 1 Zzcms 2018-10-04 3.5 LOW 5.4 MEDIUM
zzcms 8.3 has stored XSS related to the content variable in user/manage.php and zt/show.php.
CVE-2017-12614 1 Apache 1 Airflow 2018-10-04 4.3 MEDIUM 6.1 MEDIUM
It was noticed an XSS in certain 404 pages that could be exploited to perform an XSS attack. Chrome will detect this as a reflected XSS attempt and prevent the page from loading. Firefox and other browsers don't, and are vulnerable to this attack. Mitigation: The fix for this is to upgrade to Apache Airflow 1.9.0 or above.
CVE-2018-14869 1 Php Template Store Script Project 1 Php Template Store Script 2018-10-04 3.5 LOW 5.4 MEDIUM
PHP Template Store Script 3.0.6 allows XSS via the Address line 1, Address Line 2, Bank name, or A/C Holder name field in a profile.
CVE-2018-15199 1 Auracms 1 Auracms 2018-10-04 3.5 LOW 5.4 MEDIUM
AuraCMS 2.3 allows XSS via a Bukutamu -> AddGuestbook action.
CVE-2018-7755 2 Canonical, Linux 2 Ubuntu Linux, Linux Kernel 2018-10-04 2.1 LOW 5.5 MEDIUM
An issue was discovered in the fd_locked_ioctl function in drivers/block/floppy.c in the Linux kernel through 4.15.7. The floppy driver will copy a kernel pointer to user memory in response to the FDGETPRM ioctl. An attacker can send the FDGETPRM ioctl and use the obtained kernel pointer to discover the location of kernel code and data and bypass kernel security protections such as KASLR.
CVE-2018-14775 1 Openbsd 1 Openbsd 2018-10-03 4.9 MEDIUM 5.5 MEDIUM
tss_alloc in sys/arch/i386/i386/gdt.c in OpenBSD 6.2 and 6.3 has a Local Denial of Service (system crash) due to incorrect I/O port access control on the i386 architecture.
CVE-2017-9569 1 Citizensbanktx 1 Cbtx On The Go 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The Citizens Bank (TX) cbtx-on-the-go/id892396102 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9577 1 Fcbl 1 First Citizens Bank-mobile 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The "First Citizens Bank-Mobile Banking" by First Citizens Bank (AL) app 3.0.0 -- aka first-citizens-bank-mobile-banking/id566037101 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9576 1 Mononabank 1 Middleton Community Bank Mobile 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The "Middleton Community Bank Mobile Banking" by Middleton Community Bank app 3.0.0 -- aka middleton-community-bank-mobile-banking/id721843238 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9572 1 Athensstatebank 1 Athens State Bank Mobile 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The athens-state-bank-mobile-banking/id719748589 app 3.0.0 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9571 1 Ccbank 1 Ccb Mobile Banking 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The Citizens Community Bank (TN) ccb-mobile-banking/id610030469 app 3.0.1 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9578 1 Rivervalleycommunitybank 1 Rvcb Mobile 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The "RVCB Mobile" by RVCB Mobile Banking app 3.0.0 -- aka rvcb-mobile/id757928895 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9584 1 Heritagebankozarks 1 Hbo Mobile Banking 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The "HBO Mobile Banking" by Heritage Bank of Ozarks app 3.0.0 -- aka hbo-mobile-banking/id860224933 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2017-9601 1 Fnbkemp 1 Fnb Kemp Mobile Banking 2018-10-03 4.3 MEDIUM 5.9 MEDIUM
The "FNB Kemp Mobile Banking" by First National Bank of Kemp app 3.0.2 -- aka fnb-kemp-mobile-banking/id571448725 for iOS does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
CVE-2018-1155 1 Tenable 1 Securitycenter 2018-10-03 3.5 LOW 5.4 MEDIUM
In SecurityCenter versions prior to 5.7.0, a cross-site scripting (XSS) issue could allow an authenticated attacker to inject JavaScript code into an image filename parameter within the Reports feature area. Properly updated input validation techniques have been implemented to correct this issue.
CVE-2018-12607 1 Gitlab 1 Gitlab 2018-10-03 3.5 LOW 5.4 MEDIUM
An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The charts feature contained a persistent XSS issue due to a lack of output encoding.
CVE-2018-12606 1 Gitlab 1 Gitlab 2018-10-03 3.5 LOW 5.4 MEDIUM
An issue was discovered in GitLab Community Edition and Enterprise Edition before 10.7.6, 10.8.x before 10.8.5, and 11.x before 11.0.1. The wiki contains a persistent XSS issue due to a lack of output encoding affecting a specific markdown feature.
CVE-2018-12605 1 Gitlab 1 Gitlab 2018-10-03 3.5 LOW 5.4 MEDIUM
An issue was discovered in GitLab Community Edition and Enterprise Edition 10.7.x before 10.7.6. The usage of 'url_for' contained a XSS issue due to it allowing arbitrary protocols as a parameter.
CVE-2018-1999041 1 Jenkins 1 Tinfoil Security 2018-10-03 2.1 LOW 5.5 MEDIUM
An exposure of sensitive information vulnerability exists in Jenkins Tinfoil Security Plugin 1.6.1 and earlier in TinfoilScanRecorder.java that allows attackers with file system access to the Jenkins master to obtain the API secret key stored in this plugin's configuration.
CVE-2018-14977 1 Q-cms 1 Qcms 2018-10-03 4.3 MEDIUM 6.1 MEDIUM
An issue was discovered in QCMS 3.0.1. upload/System/Controller/guest.php has XSS, as demonstrated by the name parameter, a different vulnerability than CVE-2018-8070.