|
247401
|
9.8 |
CRITICAL
Network
|
genetechsolutions
|
pie_register
|
SQL injection vulnerability in the Pie Register plugin before 3.0.10 for WordPress allows remote attackers to execute arbitrary SQL commands via the invitation codes grid.
|
CWE-89
SQL Injection
|
CVE-2018-10969
|
2024-11-21 12:42 |
2018-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247402
|
5.4 |
MEDIUM
Network
|
pandorafms
|
artica_pandora_fms
|
XSS in Artica Pandora FMS before 7.0 NG 723 allows an attacker to execute arbitrary code via a crafted "refr" parameter in a "/pandora_console/index.php?sec=estado&sec2=operation/agentes/estado_agent…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11223
|
2024-11-21 12:42 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247403
|
7.5 |
HIGH
Network
|
artica
|
pandora_fms
|
Local File Inclusion (LFI) in Artica Pandora FMS through version 7.23 allows an attacker to call any php file via the /pandora_console/ajax.php ajax endpoint.
|
CWE-20
Improper Input Validation
|
CVE-2018-11222
|
2024-11-21 12:42 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247404
|
9.8 |
CRITICAL
Network
|
artica
|
pandora_fms
|
Unauthenticated untrusted file upload in Artica Pandora FMS through version 7.23 allows an attacker to upload an arbitrary plugin via include/ajax/update_manager.ajax in the update system.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11221
|
2024-11-21 12:42 |
2018-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247405
|
4.8 |
MEDIUM
Network
|
blackcat-cms
|
blackcat_cms
|
Cross-site scripting (XSS) vulnerability in backend/pages/modify.php in BlackCatCMS 1.3 allows remote authenticated users with the Admin role to inject arbitrary web script or HTML via the search pan…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10821
|
2024-11-21 12:42 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247406
|
5.9 |
MEDIUM
Network
|
fedoraproject redhat debian
|
389_directory_server enterprise_linux debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_eus enterprise_linux_serv…
|
389-ds-base before versions 1.4.0.10, 1.3.8.3 is vulnerable to a race condition in the way 389-ds-base handles persistent search, resulting in a crash if the server is under load. An anonymous attack…
|
CWE-362
Race Condition
|
CVE-2018-10850
|
2024-11-21 12:42 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247407
|
9.8 |
CRITICAL
Network
|
crestron
|
crestron_toolbox_protocol_firmware
|
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via command injection in Crestron Toolbox Protoc…
|
CWE-78
OS Command
|
CVE-2018-11229
|
2024-11-21 12:42 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247408
|
9.8 |
CRITICAL
Network
|
crestron
|
crestron_toolbox_protocol_firmware
|
Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Pro…
|
CWE-94
Code Injection
|
CVE-2018-11228
|
2024-11-21 12:42 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247409
|
7.3 |
HIGH
Network
|
gamerpolls
|
gamerpolls
|
An issue was discovered in GamerPolls 0.4.6, related to config/environments/all.js and config/initializers/02_passport.js. An attacker can edit the Passport.js contents of the session cookie to conta…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10966
|
2024-11-21 12:42 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247410
|
7.3 |
HIGH
Network
|
aprendecondedos
|
dedos-web
|
In Dedos-web 1.0, the cookie and session secrets used in the Express.js application have hardcoded values that are visible in the source code published on GitHub. An attacker can edit the contents of…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10813
|
2024-11-21 12:42 |
2018-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|