|
245931
|
5.4 |
MEDIUM
Network
|
kofax
|
front_office_server
|
Kofax Front Office Server version 4.1.1.11.0.5212 (both Thin Client and Administration Console) suffers from multiple authenticated stored XSS vulnerabilities via the (1) "Filename" field in /Kofax/K…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17288
|
2024-11-21 12:54 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245932
|
4.9 |
MEDIUM
Network
|
kofax
|
front_office_server
|
In Kofax Front Office Server Administration Console 4.1.1.11.0.5212, some fields, such as passwords, are obfuscated in the front-end, but the cleartext value can be exfiltrated by using the back-end …
|
CWE-345 CWE-311
Insufficient Verification of Data Authenticity Missing Encryption of Sensitive Data
|
CVE-2018-17287
|
2024-11-21 12:54 |
2019-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245933
|
6.1 |
MEDIUM
Network
|
wpfastestcache
|
wp_fastest_cache
|
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_timeout_pages action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17586
|
2024-11-21 12:54 |
2019-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245934
|
6.1 |
MEDIUM
Network
|
wpfastestcache
|
wp_fastest_cache
|
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the wpfastestcacheoptions wpFastestCachePreload_number or wpFastestCacheLanguage parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17585
|
2024-11-21 12:54 |
2019-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245935
|
8.8 |
HIGH
Network
|
wpfastestcache
|
wp_fastest_cache
|
The WP Fastest Cache plugin 0.8.8.5 for WordPress has CSRF via the wp-admin/admin.php wpfastestcacheoptions page.
|
CWE-352
Origin Validation Error
|
CVE-2018-17584
|
2024-11-21 12:54 |
2019-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245936
|
6.1 |
MEDIUM
Network
|
wpfastestcache
|
wp_fastest_cache
|
The WP Fastest Cache plugin 0.8.8.5 for WordPress has XSS via the rules[0][content] parameter in a wpfc_save_exclude_pages action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17583
|
2024-11-21 12:54 |
2019-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245937
|
8.8 |
HIGH
Network
|
uipath
|
orchestrator
|
UiPath Orchestrator through 2018.2.4 allows any authenticated user to change the information of arbitrary users (even administrators) leading to privilege escalation and remote code execution.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-17305
|
2024-11-21 12:54 |
2019-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245938
|
9.8 |
CRITICAL
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
Shell Metacharacter Injection in the SSH configuration interface on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to execute arbitrary system commands and gain a root shell.
|
CWE-78
OS Command
|
CVE-2018-17565
|
2024-11-21 12:54 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245939
|
9.8 |
CRITICAL
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
A Malformed Input String to /cgi-bin/delete_CA on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to delete configuration parameters and gain admin access to the device.
|
NVD-CWE-noinfo
|
CVE-2018-17564
|
2024-11-21 12:54 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245940
|
5.3 |
MEDIUM
Network
|
grandstream
|
gxp1610_firmware gxp1615_firmware gxp1620_firmware gxp1625_firmware gxp1628_firmware gxp1630_firmware
|
A Malformed Input String to /cgi-bin/api-get_line_status on Grandstream GXP16xx VoIP 1.0.4.128 phones allows attackers to dump the device's configuration in cleartext.
|
CWE-311
Missing Encryption of Sensitive Data
|
CVE-2018-17563
|
2024-11-21 12:54 |
2019-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|