|
246581
|
4.3 |
MEDIUM
Network
|
tp-link
|
tl-wr841n_firmware
|
TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow clickjacking.
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2018-12576
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246582
|
9.8 |
CRITICAL
Network
|
tp-link
|
tl-wr841n_firmware
|
On TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 171019 Rel.55346n devices, all actions in the web interface are affected by bypass of authentication via an HTTP request.
|
CWE-287
Improper Authentication
|
CVE-2018-12575
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246583
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr841n_firmware
|
CSRF exists for all actions in the web interface on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices.
|
CWE-352
Origin Validation Error
|
CVE-2018-12574
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246584
|
8.8 |
HIGH
Network
|
intex
|
n150_firmware
|
An issue was discovered on Intex N150 devices. The router firmware suffers from multiple CSRF injection point vulnerabilities including changing user passwords and router settings.
|
CWE-352
Origin Validation Error
|
CVE-2018-12529
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246585
|
8.1 |
HIGH
Network
|
intex
|
n150_firmware
|
An issue was discovered on Intex N150 devices. The backup/restore option does not check the file extension uploaded for importing a configuration files backup, which can lead to corrupting the router…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-12528
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246586
|
7.4 |
HIGH
Network
|
motorola
|
mbp853_firmware
|
The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it commu…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-12499
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246587
|
7.2 |
HIGH
Network
|
microfocus
|
secure_messaging_gateway
|
An OS command injection vulnerability in the web administration component of Micro Focus Secure Messaging Gateway (SMG) allows a remote attacker authenticated as a privileged user to execute arbitrar…
|
CWE-78
OS Command
|
CVE-2018-12465
|
2024-11-21 12:45 |
2018-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246588
|
9.8 |
CRITICAL
Network
|
microfocus
|
secure_messaging_gateway
|
A SQL injection vulnerability in the web administration and quarantine components of Micro Focus Secure Messaging Gateway allows an unauthenticated remote attacker to execute arbitrary SQL statements…
|
CWE-89
SQL Injection
|
CVE-2018-12464
|
2024-11-21 12:45 |
2018-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246589
|
7.8 |
HIGH
Local
|
polarisoffice
|
polaris_office_2017
|
Polaris Office 2017 8.1 allows attackers to execute arbitrary code via a Trojan horse puiframeworkproresenu.dll file in the current working directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-12589
|
2024-11-21 12:45 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246590
|
5.3 |
MEDIUM
Network
|
eclipse oracle
|
jetty retail_xstore_point_of_service
|
In Eclipse Jetty Server, all 9.x versions, on webapps deployed using default Error Handling, when an intentionally bad query arrives that doesn't match a dynamic url-pattern, and is eventually handle…
|
NVD-CWE-noinfo
|
CVE-2018-12536
|
2024-11-21 12:45 |
2018-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|