Total
7427 CVE
CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
---|---|---|---|---|---|
CVE-2018-20902 | 1 Cpanel | 1 Cpanel | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
cPanel before 71.9980.37 allows attackers to read root's crontab file by leveraging ClamAV installation (SEC-408). | |||||
CVE-2018-20894 | 1 Cpanel | 1 Cpanel | 2024-11-21 | 2.1 LOW | 3.3 LOW |
cPanel before 74.0.0 makes web-site contents accessible to other local users via Git repositories (SEC-443). | |||||
CVE-2018-20889 | 1 Cpanel | 1 Cpanel | 2024-11-21 | 3.6 LOW | 4.4 MEDIUM |
cPanel before 74.0.0 allows certain file-read operations via password file caching (SEC-425). | |||||
CVE-2018-20870 | 1 Cpanel | 1 Cpanel | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
The WebDAV transport feature in cPanel before 76.0.8 enables debug logging (SEC-467). | |||||
CVE-2018-20812 | 1 Pulsesecure | 1 Pulse Secure Desktop Client | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
An information exposure issue where IPv6 DNS traffic would be sent outside of the VPN tunnel (when Traffic Enforcement was enabled) exists in Pulse Secure Pulse Secure Desktop 9.0R1 and below. This is applicable only to dual-stack (IPv4/IPv6) endpoints. | |||||
CVE-2018-20811 | 1 Ivanti | 1 Connect Secure | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
A hidden RPC service issue was found with Pulse Secure Pulse Connect Secure 8.3RX before 8.3R2 and 8.1RX before 8.1R12. | |||||
CVE-2018-20776 | 1 Frog Cms Project | 1 Frog Cms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Frog CMS 0.9.5 provides a directory listing for a /public request. | |||||
CVE-2018-20681 | 1 Mate-desktop | 1 Mate-screensaver | 2024-11-21 | 3.6 LOW | 6.1 MEDIUM |
mate-screensaver before 1.20.2 in MATE Desktop Environment allows physically proximate attackers to view screen content and possibly control applications. By unplugging and re-plugging or power-cycling external output devices (such as additionally attached graphical outputs via HDMI, VGA, DVI, etc.) the content of a screensaver-locked session can be revealed. In some scenarios, the attacker can execute applications, such as by clicking with a mouse. | |||||
CVE-2018-20609 | 1 Txjia | 1 Imcat | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
imcat 4.4 allows remote attackers to obtain potentially sensitive configuration information via the root/tools/adbug/check.php URI. | |||||
CVE-2018-20608 | 1 Txjia | 1 Imcat | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
imcat 4.4 allows remote attackers to read phpinfo output via the root/tools/adbug/binfo.php?phpinfo1 URI. | |||||
CVE-2018-20607 | 1 Txjia | 1 Imcat | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
imcat 4.4 allows remote attackers to obtain potentially sensitive debugging information via the root/tools/adbug/binfo.php URI. | |||||
CVE-2018-20606 | 1 Txjia | 1 Imcat | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
imcat 4.4 allows full path disclosure via a dev.php?tools-ipaddr&api=Pcoln&uip= URI. | |||||
CVE-2018-20602 | 1 Lfdycms | 1 Lei Feng Tv Cms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI. | |||||
CVE-2018-20571 | 1 Damicms | 1 Damicms | 2024-11-21 | 5.0 MEDIUM | 7.5 HIGH |
DamiCMS 6.0.1 allows remote attackers to read arbitrary files via a crafted admin.php?s=Tpl/Add/id request, as demonstrated by admin.php?s=Tpl/Add/id/.\Public\Config\config.ini.php to read the global configuration file. | |||||
CVE-2018-20555 | 1 Designchemical | 1 Social Network Tabs | 2024-11-21 | 7.5 HIGH | 9.8 CRITICAL |
The Design Chemical Social Network Tabs plugin 1.7.1 for WordPress allows remote attackers to discover Twitter access_token, access_token_secret, consumer_key, and consumer_secret values by reading the dcwp_twitter.php source code. This leads to Twitter account takeover. | |||||
CVE-2018-20511 | 2 Debian, Linux | 2 Debian Linux, Linux Kernel | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
An issue was discovered in the Linux kernel before 4.18.11. The ipddp_ioctl function in drivers/net/appletalk/ipddp.c allows local users to obtain sensitive kernel address information by leveraging CAP_NET_ADMIN to read the ipddp_route dev and next fields via an SIOCFINDIPDDPRT ioctl call. | |||||
CVE-2018-20510 | 1 Linux | 1 Linux Kernel | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
The print_binder_transaction_ilocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading "*from *code *flags" lines in a debugfs file. | |||||
CVE-2018-20509 | 1 Linux | 1 Linux Kernel | 2024-11-21 | 2.1 LOW | 5.5 MEDIUM |
The print_binder_ref_olocked function in drivers/android/binder.c in the Linux kernel 4.14.90 allows local users to obtain sensitive address information by reading " ref *desc *node" lines in a debugfs file. | |||||
CVE-2018-20495 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 5.0 MEDIUM | 5.3 MEDIUM |
An issue was discovered in GitLab Community and Enterprise Edition 11.3.x and 11.4.x before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure. | |||||
CVE-2018-20488 | 1 Gitlab | 1 Gitlab | 2024-11-21 | 4.0 MEDIUM | 4.3 MEDIUM |
An issue was discovered in GitLab Community and Enterprise Edition before 11.4.13, 11.5.x before 11.5.6, and 11.6.x before 11.6.1. It allows Information Exposure. |