|
247811
|
6.5 |
MEDIUM
Network
|
datenstrom
|
yellow
|
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
|
CWE-352
Origin Validation Error
|
CVE-2018-10758
|
2024-11-21 12:41 |
2018-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247812
|
9.8 |
CRITICAL
Network
|
csp_mysql_user_manager_project
|
csp_mysql_user_manager
|
CSP MySQL User Manager 2.3.1 allows SQL injection, and resultant Authentication Bypass, via a crafted username during a login attempt.
|
CWE-89
SQL Injection
|
CVE-2018-10757
|
2024-11-21 12:41 |
2018-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247813
|
9.8 |
CRITICAL
Network
|
moinejf debian fedoraproject
|
abcm2ps debian_linux fedora
|
Stack-based buffer overflow in the delayed_output function in music.c in abcm2ps through 8.13.20 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified …
|
CWE-787
Out-of-bounds Write
|
CVE-2018-10753
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247814
|
4.8 |
MEDIUM
Network
|
tagregator_project
|
tagregator
|
The Tagregator plugin 0.6 for WordPress has stored XSS via the title field in an Add New action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10752
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247815
|
9.8 |
CRITICAL
Network
|
sierrawireless
|
aleos
|
A vulnerability in Sierra Wireless AirLink GX400, GX440, ES440, and LS300 routers with firmware before 4.4.7 and GX450, ES450, RV50, RV50X, MP70, and MP70E routers with firmware before 4.9.3 could al…
|
CWE-1188 CWE-862
Insecure Default Initialization of Resource Missing Authorization
|
CVE-2018-10251
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247816
|
4.8 |
MEDIUM
Network
|
google mozilla lg
|
chrome firefox nexus_5
|
A hardware vulnerability in GPU memory modules allows attackers to accelerate micro-architectural attacks through the use of the JavaScript WebGL API.
|
CWE-200
Information Exposure
|
CVE-2018-10229
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247817
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'staticGet' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) us…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10750
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247818
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'commit' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10749
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247819
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as a 'show' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using t…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10748
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247820
|
8.8 |
HIGH
Network
|
d-link
|
dsl-3782_firmware
|
An issue was discovered on D-Link DSL-3782 EU 1.01 devices. An authenticated user can pass a long buffer as an 'unset' parameter to the '/userfs/bin/tcapi' binary (in the Diagnostics component) using…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10747
|
2024-11-21 12:41 |
2018-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|