|
247341
|
6.8 |
MEDIUM
Physics
|
pulsesecure
|
pulse_secure_desktop_client
|
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
|
CWE-295
Improper Certificate Validation
|
CVE-2018-16261
|
2024-11-21 12:52 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247342
|
7.8 |
HIGH
Local
|
artifex canonical debian
|
ghostscript ubuntu_linux debian_linux
|
An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the sta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16585
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247343
|
6.1 |
MEDIUM
Network
|
exceljs_project
|
exceljs
|
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16459
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247344
|
8.8 |
HIGH
Network
|
micropyramid
|
django_crm
|
MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.
|
CWE-352
Origin Validation Error
|
CVE-2018-16552
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247345
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16551
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247346
|
9.8 |
CRITICAL
Network
|
teamviewer
|
teamviewer
|
TeamViewer 10.x through 13.x allows remote attackers to bypass the brute-force authentication protection mechanism by skipping the "Cancel" step, which makes it easier to determine the correct value …
|
NVD-CWE-noinfo
|
CVE-2018-16550
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247347
|
5.3 |
MEDIUM
Network
|
php_file_browser_script_project
|
php_file_browser_script
|
HScripts PHP File Browser Script v1.0 allows Directory Traversal via the index.php path parameter.
|
CWE-22
Path Traversal
|
CVE-2018-16549
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247348
|
6.5 |
MEDIUM
Network
|
zziplib_project
|
zziplib
|
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16548
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247349
|
6.1 |
MEDIUM
Network
|
e107
|
e107
|
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16381
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247350
|
6.1 |
MEDIUM
Network
|
btiteam
|
xbtit
|
An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16361
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|