|
247351
|
7.5 |
HIGH
Network
|
mi
|
xiaomi_miwifi_xiaomi_55dd_firmware
|
An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL…
|
CWE-200
Information Exposure
|
CVE-2018-16307
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247352
|
3.3 |
LOW
Local
|
fspro
|
event_log_explorer
|
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
|
CWE-611
XXE
|
CVE-2018-16252
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247353
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview
|
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16148
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247354
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview
|
The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16147
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247355
|
7.2 |
HIGH
Network
|
opsview
|
opsview
|
The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurabl…
|
CWE-78
OS Command
|
CVE-2018-16146
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247356
|
8.1 |
HIGH
Network
|
opsview
|
opsview
|
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow att…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16145
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247357
|
9.8 |
CRITICAL
Network
|
opsview
|
opsview
|
The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password…
|
CWE-78
OS Command
|
CVE-2018-16144
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247358
|
5.9 |
MEDIUM
Network
|
amcrest
|
amcrest_ipc-hx1x3x-lexus_eng_n_amcrest
|
Amcrest networked devices use the same hardcoded SSL private key across different customers' installations, which allows remote attackers to defeat cryptographic protection mechanisms by leveraging k…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-16546
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247359
|
4.9 |
MEDIUM
Network
|
gxlcms
|
gxlcms
|
Gxlcms 2.0 before bug fix 20180915 has Directory Traversal exploitable by an administrator.
|
CWE-22
Path Traversal
|
CVE-2018-16437
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247360
|
7.2 |
HIGH
Network
|
gxlcms
|
gxlcms
|
Gxlcms 2.0 before bug fix 20180915 has SQL Injection exploitable by an administrator.
|
CWE-89
SQL Injection
|
CVE-2018-16436
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|