|
246001
|
9.8 |
CRITICAL
Network
|
citrix
|
netscaler_sd-wan sd-wan
|
A SQL Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
|
CWE-89
SQL Injection
|
CVE-2018-17446
|
2024-11-21 12:54 |
2018-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246002
|
9.8 |
CRITICAL
Network
|
citrix
|
netscaler_sd-wan sd-wan
|
A Command Injection issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
|
CWE-77
Command Injection
|
CVE-2018-17445
|
2024-11-21 12:54 |
2018-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246003
|
7.5 |
HIGH
Network
|
citrix
|
netscaler_sd-wan sd-wan
|
A Directory Traversal issue was discovered in Citrix SD-WAN 10.1.0 and NetScaler SD-WAN 9.3.x before 9.3.6 and 10.0.x before 10.0.4.
|
CWE-22
Path Traversal
|
CVE-2018-17444
|
2024-11-21 12:54 |
2018-10-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246004
|
6.8 |
MEDIUM
Physics
|
teltonika
|
rut900_firmware rut950_firmware rut955_firmware
|
Teltonika RUT9XX routers with firmware before 00.04.233 provide a root terminal on a serial interface without proper access control. This allows attackers with physical access to execute arbitrary co…
|
CWE-287
Improper Authentication
|
CVE-2018-17534
|
2024-11-21 12:54 |
2018-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246005
|
6.1 |
MEDIUM
Network
|
teltonika
|
rut900_firmware rut950_firmware rut955_firmware
|
Teltonika RUT9XX routers with firmware before 00.05.01.1 are prone to cross-site scripting vulnerabilities in hotspotlogin.cgi due to insufficient user input sanitization.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17533
|
2024-11-21 12:54 |
2018-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246006
|
9.8 |
CRITICAL
Network
|
teltonika
|
rut900_firmware rut950_firmware rut955_firmware
|
Teltonika RUT9XX routers with firmware before 00.04.233 are prone to multiple unauthenticated OS command injection vulnerabilities in autologin.cgi and hotspotlogin.cgi due to insufficient user input…
|
CWE-78
OS Command
|
CVE-2018-17532
|
2024-11-21 12:54 |
2018-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246007
|
6.1 |
MEDIUM
Network
|
sugarcrm
|
sugarcrm
|
Multiple vulnerabilities in YUI and FlashCanvas embedded in SugarCRM Community Edition 6.5.26 could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack on a targe…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17784
|
2024-11-21 12:54 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246008
|
6.1 |
MEDIUM
Network
|
intelbras
|
nplug_firmware
|
Intelbras NPLUG 1.0.0.14 devices have XSS via a crafted SSID that is received via a network broadcast.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17337
|
2024-11-21 12:54 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246009
|
7.8 |
HIGH
Local
|
seqrite
|
end_point_security
|
Seqrite End Point Security v7.4 has "Everyone: (F)" permission for %PROGRAMFILES%\Seqrite\Seqrite, which allows local users to gain privileges by replacing an executable file with a Trojan horse.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-17775
|
2024-11-21 12:54 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246010
|
6.1 |
MEDIUM
Network
|
dlink
|
central_wifimanager
|
An issue was discovered on D-Link Central WiFi Manager before v 1.03r0100-Beta1. The 'sitename' parameter of the UpdateSite endpoint is vulnerable to stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17443
|
2024-11-21 12:54 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|