|
247961
|
9.8 |
CRITICAL
Network
|
onosproject
|
onos
|
ONOS ONOS controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in onos\drivers\utilities\src\main\java\org\onosproject\drivers\utilities\XmlConfigParser.java loadx…
|
CWE-611
XXE
|
CVE-2018-1000616
|
2024-11-21 12:40 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247962
|
7.5 |
HIGH
Network
|
onosproject
|
onos
|
ONOS ONOS Controller version 1.13.1 and earlier contains a Denial of Service (Service crash) vulnerability in OVSDB component in ONOS that can result in An adversary can remotely crash OVSDB service …
|
NVD-CWE-noinfo
|
CVE-2018-1000615
|
2024-11-21 12:40 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247963
|
9.8 |
CRITICAL
Network
|
onosproject
|
onos
|
ONOS ONOS Controller version 1.13.1 and earlier contains a XML External Entity (XXE) vulnerability in providers/netconf/alarm/src/main/java/org/onosproject/provider/netconf/alarm/NetconfAlarmTranslat…
|
CWE-611
XXE
|
CVE-2018-1000614
|
2024-11-21 12:40 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247964
|
6.1 |
MEDIUM
Network
|
openconext
|
openconext_engineblock
|
SURFnet OpenConext EngineBlock version 5.7.0 to 5.7.3 contains a Cross Site Scripting (XSS) vulnerability that can result in Allows an attacker to inject arbitrary web scripts or HTML into help and l…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000611
|
2024-11-21 12:40 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247965
|
9.8 |
CRITICAL
Network
|
bouncycastle netapp opensuse oracle
|
legion-of-the-bouncy-castle-java-crytography-api oncommand_workflow_automation leap retail_xstore_point_of_service api_gateway enterprise_repository peoplesoft_enterprise_peopletool…
|
Legion of the Bouncy Castle Legion of the Bouncy Castle Java Cryptography APIs 1.58 up to but not including 1.60 contains a CWE-470: Use of Externally-Controlled Input to Select Classes or Code ('Uns…
|
CWE-470
Unsafe Reflection
|
CVE-2018-1000613
|
2024-11-21 12:40 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247966
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_eventlog_analyzer
|
An issue was discovered in Zoho ManageEngine EventLog Analyzer 11.12. A Cross-Site Scripting vulnerability allows a remote attacker to inject arbitrary web script or HTML via the search functionality…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10076
|
2024-11-21 12:40 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247967
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_eventlog_analyzer
|
Cross-site scripting (XSS) vulnerability in Zoho ManageEngine EventLog Analyzer 11.12 allows remote attackers to inject arbitrary web script or HTML via the import logs feature.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10075
|
2024-11-21 12:40 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247968
|
8.8 |
HIGH
Network
|
jenkins
|
configuration_as_code
|
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in DataBoundConfigurator.java, Attribute.java, BaseConfigurator.java, ExtensionC…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-1000610
|
2024-11-21 12:40 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247969
|
6.5 |
MEDIUM
Network
|
jenkins
|
configuration_as_code
|
A exposure of sensitive information vulnerability exists in Jenkins Configuration as Code Plugin 0.7-alpha and earlier in ConfigurationAsCode.java that allows attackers with Overall/Read access to ob…
|
CWE-200
Information Exposure
|
CVE-2018-1000609
|
2024-11-21 12:40 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247970
|
7.2 |
HIGH
Network
|
jenkins
|
z\/os_connector
|
A exposure of sensitive information vulnerability exists in Jenkins z/OS Connector Plugin 1.2.6.1 and earlier in SCLMSCM.java that allows an attacker with local file system access or control of a Jen…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-1000608
|
2024-11-21 12:40 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|