|
247741
|
6.4 |
MEDIUM
Physics
|
telegram
|
telegram
|
An issue was discovered in the org.telegram.messenger application 4.8.11 for Android. The Passcode feature allows authentication bypass via runtime manipulation that forces a certain method's return …
|
CWE-287
Improper Authentication
|
CVE-2018-15542
|
2024-11-21 12:51 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247742
|
5.4 |
MEDIUM
Network
|
claromentis
|
claromentis
|
The Discuss v1.2.1 module in Claromentis 8.2.2 is vulnerable to stored Cross Site Scripting (XSS). An authenticated attacker will be able to place malicious JavaScript in the discussion forum, which …
|
CWE-79
Cross-site Scripting
|
CVE-2018-15903
|
2024-11-21 12:51 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247743
|
8.8 |
HIGH
Network
|
pivotal_software
|
pivotal_container_service
|
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application lo…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-15763
|
2024-11-21 12:51 |
2018-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247744
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.
|
CWE-862
Missing Authorization
|
CVE-2018-16048
|
2024-11-21 12:51 |
2018-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247745
|
7.5 |
HIGH
Network
|
mensamax
|
mensamax
|
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES Cryptographic Key allows an attacker who decodes the application to decry…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-15753
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247746
|
8.1 |
HIGH
Network
|
mensamax
|
mensamax
|
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information allows man-in-the-middle attackers to eavesdrop authe…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2018-15752
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247747
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion
|
_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15563
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247748
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.
|
CWE-352
Origin Validation Error
|
CVE-2018-15702
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247749
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Cookie field.
|
CWE-20
Improper Input Validation
|
CVE-2018-15701
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247750
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Referer field.
|
CWE-20
Improper Input Validation
|
CVE-2018-15700
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|