|
248091
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition 11.x before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows Information Exposure via a Gitlab Prometheus integrati…
|
CWE-200
Information Exposure
|
CVE-2018-18644
|
2024-11-21 12:56 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248092
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18642
|
2024-11-21 12:56 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248093
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Cleartext Storage of Sensitive Information.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-18641
|
2024-11-21 12:56 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248094
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It has Information Exposure Through Browser Caching.
|
CWE-200
Information Exposure
|
CVE-2018-18640
|
2024-11-21 12:56 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248095
|
7.8 |
HIGH
Local
|
omron
|
cx-one cx-programmer cx-server
|
In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing f…
|
CWE-416
Use After Free
|
CVE-2018-18989
|
2024-11-21 12:56 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248096
|
6.1 |
MEDIUM
Network
|
spidercontrol
|
scada_webserver
|
Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18991
|
2024-11-21 12:56 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248097
|
8.8 |
HIGH
Network
|
invt
|
vt-designer
|
VT-Designer Version 2.1.7.31 is vulnerable by the program populating objects with user supplied input via a file without first checking for validity, allowing attacker supplied input to be written to…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-18987
|
2024-11-21 12:56 |
2018-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248098
|
8.8 |
HIGH
Network
|
invt
|
vt-designer
|
VT-Designer Version 2.1.7.31 is vulnerable by the program reading the contents of a file (which is already in memory) into another heap-based buffer, which may cause the program to crash or allow rem…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18983
|
2024-11-21 12:56 |
2018-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248099
|
7.8 |
HIGH
Local
|
switchvpn
|
switchvpn
|
A local privilege escalation vulnerability has been identified in the SwitchVPN client 2.1012.03 for macOS. Due to over-permissive configuration settings and a SUID binary, an attacker is able to exe…
|
NVD-CWE-noinfo
|
CVE-2018-18860
|
2024-11-21 12:56 |
2018-12-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248100
|
9.8 |
CRITICAL
Network
|
advanced_comment_system_project
|
advanced_comment_system
|
internal/advanced_comment_system/admin.php in Advanced Comment System 1.0 is prone to an SQL injection vulnerability because it fails to sufficiently sanitize user-supplied data before using it in an…
|
CWE-89
SQL Injection
|
CVE-2018-18619
|
2024-11-21 12:56 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|