|
247731
|
7.5 |
HIGH
Network
|
ge
|
mds_pulsenet
|
Multiple variants of XML External Entity (XXE) attacks may be used to exfiltrate data from the host Windows platform in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior.
|
CWE-611
XXE
|
CVE-2018-10613
|
2024-11-21 12:41 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247732
|
9.8 |
CRITICAL
Network
|
ge
|
mds_pulsenet
|
Java remote method invocation (RMI) input port in GE MDS PulseNET and MDS PulseNET Enterprise version 3.2.1 and prior may be exploited to allow unauthenticated users to launch applications and suppor…
|
CWE-287
Improper Authentication
|
CVE-2018-10611
|
2024-11-21 12:41 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247733
|
5.4 |
MEDIUM
Network
|
modx
|
modx_revolution
|
MODX Revolution 2.6.3 has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10382
|
2024-11-21 12:41 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247734
|
6.1 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community Edition (CE) and Enterprise Edition (EE) before 10.5.8, 10.6.x before 10.6.5, and 10.7.x before 10.7.2. The Move Issue feature contained a persistent XSS v…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10379
|
2024-11-21 12:41 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247735
|
5.3 |
MEDIUM
Network
|
samsung
|
samsung_mobile
|
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in mem…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10751
|
2024-11-21 12:41 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247736
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adaudit_plus
|
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2018-10466
|
2024-11-21 12:41 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247737
|
5.3 |
MEDIUM
Network
|
dataiku
|
data_science_studio
|
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
|
CWE-200
Information Exposure
|
CVE-2018-10732
|
2024-11-21 12:41 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247738
|
8.8 |
HIGH
Network
|
trendmicro
|
smart_protection_server
|
A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to …
|
CWE-89
SQL Injection
|
CVE-2018-10350
|
2024-11-21 12:41 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247739
|
6.3 |
MEDIUM
Adjacent
|
bd
|
database_manager performa reada
|
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) …
|
CWE-89
SQL Injection
|
CVE-2018-10595
|
2024-11-21 12:41 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247740
|
5.6 |
MEDIUM
Adjacent
|
bd
|
database_manager performa reada
|
A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA,…
|
CWE-89
SQL Injection
|
CVE-2018-10593
|
2024-11-21 12:41 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|