|
247481
|
9.8 |
CRITICAL
Network
|
odoo
|
odoo
|
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the su…
|
CWE-284
Improper Access Control
|
CVE-2018-14885
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247482
|
6.1 |
MEDIUM
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14919
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247483
|
9.8 |
CRITICAL
Network
|
lexmark
|
cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware mx41x_firmware mx51x_firmware xm1145_firmware mx61x_firmware xm3150_firmware mx71x_firmware
|
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15519
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247484
|
9.8 |
CRITICAL
Network
|
bubblesoftapps
|
bubbleupnp
|
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnera…
|
CWE-611
XXE
|
CVE-2018-15506
|
2024-11-21 12:50 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247485
|
5.3 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enum…
|
CWE-200
Information Exposure
|
CVE-2018-15131
|
2024-11-21 12:50 |
2019-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247486
|
9.8 |
CRITICAL
Network
|
polycom
|
group_series hdx pano
|
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functional…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15128
|
2024-11-21 12:50 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247487
|
7.5 |
HIGH
Network
|
cisco
|
firepower_threat_defense
|
A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-15462
|
2024-11-21 12:50 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247488
|
8.6 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software firepower_threat_defense
|
A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to ca…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-15388
|
2024-11-21 12:50 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247489
|
7.5 |
HIGH
Network
|
bpcbt
|
smartvista
|
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
|
CWE-384
Session Fixation
|
CVE-2018-15208
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247490
|
7.2 |
HIGH
Network
|
bpcbt
|
smartvista
|
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.js…
|
CWE-269
Improper Privilege Management
|
CVE-2018-15207
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|