LiveActive security incident?Get immediate response
CVE archive

May 2018

Browse CVE records published in May 2018, with severity, affected products, CWE, KEV, and source-backed vulnerability context.

Showing 50 of 1309 matching CVEs · Page 14 of 27.

Unknown · CVSS Not scored

CVE-2018-11413: An issue was discovered in BearAdmin 0.5.

An issue was discovered in BearAdmin 0.5. Remote attackers can download arbitrary files via /admin/databack/download.html?name= directory traversal sequences, as demonstrated by name=../application/database.php to read the MySQL credentials in the configuration.

Published May 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11392: An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Manageme...

An arbitrary file upload vulnerability in /classes/profile.class.php in Jigowatt "PHP Login & User Management" before 4.1.1, as distributed in the Envato Market, allows any remote authenticated user to upload .php files to the web server via a profile avatar field. This results in arbitrary code execution by requesting the .php file.

Published May 29, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11414: An issue was discovered in BearAdmin 0.5.

An issue was discovered in BearAdmin 0.5. There is admin/admin_log/index.html?user_id= SQL injection because admin\controller\AdminLog.php constructs a MySQL query improperly.

Published May 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11410: An issue was discovered in Liblouis 3.5.0.

An issue was discovered in Liblouis 3.5.0. A invalid free in the compileRule function in compileTranslationTable.c allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact.

Published May 24, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11329: The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attac...

The DrugDealer function of a smart contract implementation for Ether Cartel, an Ethereum game, allows attackers to take over the contract's ownership, aka ceoAnyone. After that, all the digital assets (including Ether balance and tokens) might be manipulated by the attackers, as exploited in the wild in May 2018.

Published May 22, 2018 · Updated Aug 5, 2024

Unknown · CVSS Not scored

CVE-2018-11325: An issue was discovered in Joomla!

An issue was discovered in Joomla! Core before 3.8.8. The web install application would autofill password fields after either a form validation error or navigating to a previous install step, and display the plaintext password for the administrator account at the confirmation screen.

Published May 22, 2018 · Updated Aug 5, 2024