|
246031
|
6.1 |
MEDIUM
Network
|
airties
|
air_5750_firmware
|
AirTies Air 5750 devices with software 1.0.0.18 have XSS via the top.html productboardtype parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17587
|
2024-11-21 12:54 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246032
|
6.5 |
MEDIUM
Network
|
simdcomp_project
|
simdcomp
|
SIMDComp before 0.1.0 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) because it can read (and then discard) extra bytes.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-17427
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246033
|
5.4 |
MEDIUM
Network
|
ptc
|
thingworx_platform
|
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is reflected XSS in the SQUEAL search function.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17218
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246034
|
7.5 |
HIGH
Network
|
ptc
|
thingworx_platform
|
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is a hardcoded encryption key.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-17217
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246035
|
6.5 |
MEDIUM
Network
|
ptc
|
thingworx_platform
|
An issue was discovered in PTC ThingWorx Platform 6.5 through 8.2. There is password hash exposure to privileged users.
|
CWE-200
Information Exposure
|
CVE-2018-17216
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246036
|
6.5 |
MEDIUM
Network
|
zzcms
|
zzcms
|
An issue was discovered in zzcms 8.3. user/zssave.php allows remote attackers to delete arbitrary files via directory traversal sequences in the oldimg parameter in an action=modify request. This can…
|
CWE-22
Path Traversal
|
CVE-2018-17797
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246037
|
9.8 |
CRITICAL
Network
|
mushroom_content_management_system_project
|
mushroom_content_management_system
|
An issue was discovered in MRCMS (aka mushroom) through 3.1.2. The WebParam.java file directly accepts the FIELD_T parameter in a request and uses it as a hash of SQL statements without filtering, re…
|
CWE-89
SQL Injection
|
CVE-2018-17796
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246038
|
8.8 |
HIGH
Network
|
libtiff
|
libtiff
|
The function t2p_write_pdf in tiff2pdf.c in LibTIFF 4.0.9 and earlier allows remote attackers to cause a denial of service (heap-based buffer overflow and application crash) or possibly have unspecif…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17795
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246039
|
6.5 |
MEDIUM
Network
|
gnu
|
binutils
|
An issue was discovered in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.31. There is a NULL pointer dereference in work_stuff_copy_to_from when called from iterate_demangle_function.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-17794
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246040
|
7.5 |
HIGH
Network
|
blynk
|
blynk-server
|
In blynk-server in Blynk before 0.39.7, Directory Traversal exists via a ../ in a URI that has /static or /static/js at the beginning, as demonstrated by reading the /etc/passwd file.
|
CWE-22
Path Traversal
|
CVE-2018-17785
|
2024-11-21 12:54 |
2018-10-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|