|
246801
|
9.8 |
CRITICAL
Network
|
solarwinds
|
sftp\/scp_server
|
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords f…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-16791
|
2024-11-21 12:53 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246802
|
10.0 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the b…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17160
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246803
|
8.8 |
HIGH
Network
|
pluck-cms
|
pluck
|
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
|
CWE-352
Origin Validation Error
|
CVE-2018-16634
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246804
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16633
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246805
|
5.4 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16631
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246806
|
4.8 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16629
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246807
|
5.4 |
MEDIUM
Network
|
getkirby
|
kirby
|
panel/login in Kirby v2.5.12 allows XSS via a blog name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16628
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246808
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, the NFS server lacks a bounds check in the READDIRPLUS NFS request. Unprivileged remote users with access to the NFS server can cause a res…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-17159
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246809
|
7.5 |
HIGH
Network
|
freebsd
|
freebsd
|
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error can occur when handling the client address length field in an NFSv4 request. Unprivileged remote users with acces…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17158
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246810
|
9.8 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD before 11.2-STABLE(r340854) and 11.2-RELEASE-p5, an integer overflow error when handling opcodes can cause memory corruption by sending a specially crafted NFSv4 request. Unprivileged remo…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-17157
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|