|
247711
|
4.8 |
MEDIUM
Network
|
domainmod
|
domainmod
|
DomainMOD version 4.09.03 and above. Also verified in the latest version 4.11.01 contains a Cross Site Scripting (XSS) vulnerability in Segment Name field in the segments page that can result in Arbi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000856
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247712
|
6.1 |
MEDIUM
Network
|
basecamp
|
easymon
|
easymon version 1.4 and earlier contains a Cross Site Scripting (XSS) vulnerability in Endpoint where monitoring is mounted that can result in Reflected XSS that affects Firefox. Can be used to steal…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000855
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247713
|
9.8 |
CRITICAL
Network
|
esigate
|
esigate
|
esigate.org esigate version 5.2 and earlier contains a CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability in ESI directive with u…
|
CWE-74
Injection
|
CVE-2018-1000854
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247714
|
6.5 |
MEDIUM
Network
|
freerdp canonical fedoraproject
|
freerdp ubuntu_linux fedora
|
FreeRDP FreeRDP 2.0.0-rc3 released version before commit 205c612820dac644d665b5bb1cdf437dc5ca01e3 contains a Other/Unknown vulnerability in channels/drdynvc/client/drdynvc_main.c, drdynvc_process_cap…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-1000852
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247715
|
9.8 |
CRITICAL
Network
|
copay
|
copay_bitcoin_wallet
|
Copay Bitcoin Wallet version 5.01 to 5.1.0 included. contains a Other/Unknown vulnerability in wallet private key storage that can result in Users' private key can be compromised. . This attack appea…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-1000851
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247716
|
7.5 |
HIGH
Network
|
squareup
|
retrofit
|
Square Retrofit version versions from (including) 2.0 and 2.5.0 (excluding) contains a Directory Traversal vulnerability in RequestBuilder class, method addPathParameter that can result in By manipul…
|
CWE-22
Path Traversal
|
CVE-2018-1000850
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247717
|
8.8 |
HIGH
Network
|
alpinelinux
|
alpine_linux
|
Alpine Linux version Versions prior to 2.6.10, 2.7.6, and 2.10.1 contains a Other/Unknown vulnerability in apk-tools (Alpine Linux' package manager) that can result in Remote Code Execution. This att…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000849
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247718
|
6.1 |
MEDIUM
Network
|
wampserver
|
wampserver
|
Wampserver version prior to version 3.1.5 contains a Cross Site Scripting (XSS) vulnerability in index.php localhost page that can result in very low. This attack appear to be exploitable via payload…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000848
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247719
|
5.4 |
MEDIUM
Network
|
freshdns_project
|
freshdns
|
FreshDNS version 1.0.3 and prior contains a Cross Site Scripting (XSS) vulnerability in Account data form; Zone editor that can result in Execution of attacker's JavaScript code in victim's session. …
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000847
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247720
|
8.8 |
HIGH
Network
|
freshdns_project
|
freshdns
|
FreshDNS version 1.0.3 and earlier contains a Cross ite Request Forgery (CSRF) vulnerability in All (authenticated) API calls in index.php / class.manager.php that can result in Editing domains and z…
|
CWE-352
Origin Validation Error
|
CVE-2018-1000846
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|