|
246591
|
8.8 |
HIGH
Network
|
joomla
|
joomla\!
|
An issue was discovered in Joomla! 2.5.0 through 3.8.8 before 3.8.9. The autoload code checks classnames to be valid, using the "class_exists" function in PHP. In PHP 5.3, this function validates inv…
|
CWE-20
Improper Input Validation
|
CVE-2018-12712
|
2024-11-21 12:45 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246592
|
6.1 |
MEDIUM
Network
|
joomla
|
joomla\!
|
An XSS issue was discovered in the language switcher module in Joomla! 1.6.0 through 3.8.8 before 3.8.9. In some cases, the link of the current language might contain unescaped HTML special character…
|
CWE-79
Cross-site Scripting
|
CVE-2018-12711
|
2024-11-21 12:45 |
2018-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246593
|
8.8 |
HIGH
Network
|
lfdycms
|
lfcms
|
Cross-site request forgery (CSRF) vulnerability in admin.php in LFCMS 3.7.0 allows remote attackers to hijack the authentication of unspecified users for requests that add administrator users via the…
|
CWE-352
Origin Validation Error
|
CVE-2018-12603
|
2024-11-21 12:45 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246594
|
7.5 |
HIGH
Network
|
saj-electric
|
saj_solar_inverter
|
SAJ Solar Inverter allows remote attackers to obtain potentially sensitive information via a direct request for the inverter_info.htm or english_main.htm URI.
|
CWE-200
Information Exposure
|
CVE-2018-12735
|
2024-11-21 12:45 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246595
|
8.8 |
HIGH
Network
|
lfdycms
|
lfcms
|
A CSRF vulnerability exists in LFCMS 3.7.0: users can be added arbitrarily.
|
CWE-352
Origin Validation Error
|
CVE-2018-12602
|
2024-11-21 12:45 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246596
|
7.5 |
HIGH
Network
|
block18
|
block18
|
The approveAndCallcode function of a smart contract implementation for Block 18 (18T), an tradable Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances into …
|
CWE-20
Improper Input Validation
|
CVE-2018-12703
|
2024-11-21 12:45 |
2018-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246597
|
7.5 |
HIGH
Network
|
gve
|
globalvillage_ecosystem
|
The approveAndCallcode function of a smart contract implementation for Globalvillage ecosystem (GVE), an Ethereum ERC20 token, allows attackers to steal assets (e.g., transfer the contract's balances…
|
CWE-20
Improper Input Validation
|
CVE-2018-12702
|
2024-11-21 12:45 |
2018-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246598
|
4.3 |
MEDIUM
Adjacent
|
google
|
chromecast_firmware home_firmware
|
The API service on Google Home and Chromecast devices before mid-July 2018 does not prevent DNS rebinding attacks from reading the scan_results JSON data, which allows remote attackers to determine t…
|
CWE-200
Information Exposure
|
CVE-2018-12716
|
2024-11-21 12:45 |
2018-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246599
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
An issue was discovered in the Linux kernel through 4.17.2. The filter parsing in kernel/trace/trace_events_filter.c could be called with no filter, which is an N=0 case when it expected at least one…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12714
|
2024-11-21 12:45 |
2018-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246600
|
9.8 |
CRITICAL
Network
|
digisol
|
dg-br4000ng_firmware
|
DIGISOL DG-BR4000NG devices have a Buffer Overflow via a long Authorization HTTP header.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-12706
|
2024-11-21 12:45 |
2018-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|