|
247821
|
6.1 |
MEDIUM
Network
|
webidsupport
|
webid
|
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000868
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247822
|
8.8 |
HIGH
Network
|
webidsupport
|
webid
|
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to …
|
CWE-89
SQL Injection
|
CVE-2018-1000867
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247823
|
4.7 |
MEDIUM
Network
|
phpipam
|
phpipam
|
phpipam version 1.3.2 and earlier contains a Cross Site Scripting (XSS) vulnerability in The value of the phpipamredirect cookie is copied into an HTML tag on the login page encapsulated in single qu…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000860
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247824
|
8.8 |
HIGH
Network
|
gnupg canonical
|
gnupg ubuntu_linux
|
GnuPG version 2.1.12 - 2.2.11 contains a Cross ite Request Forgery (CSRF) vulnerability in dirmngr that can result in Attacker controlled CSRF, Information Disclosure, DoS. This attack appear to be e…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000858
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247825
|
8.8 |
HIGH
Network
|
open-systems
|
log-user-session
|
log-user-session version 0.7 and earlier contains a Directory Traversal vulnerability in Main SUID-binary /usr/local/bin/log-user-session that can result in User to root privilege escalation. This at…
|
CWE-22
Path Traversal
|
CVE-2018-1000857
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247826
|
4.8 |
MEDIUM
Network
|
domainmod
|
domainmod
|
DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page that can result in Arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000856
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247827
|
6.1 |
MEDIUM
Network
|
basecamp
|
easymon
|
easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox. Can be used to steal…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000855
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247828
|
9.8 |
CRITICAL
Network
|
esigate
|
esigate
|
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with u…
|
CWE-74
Injection
|
CVE-2018-1000854
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247829
|
6.5 |
MEDIUM
Network
|
freerdp canonical fedoraproject
|
freerdp ubuntu_linux fedora
|
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_cap…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000852
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247830
|
9.8 |
CRITICAL
Network
|
copay
|
copay_bitcoin_wallet
|
Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appea…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-1000851
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|