|
246011
|
6.1 |
MEDIUM
Network
|
icinga
|
icinga_web_2
|
Icinga Web 2 has XSS via the /icingaweb2/monitoring/list/services dir parameter, the /icingaweb2/user/list query string, the /icingaweb2/monitoring/timeline query string, or the /icingaweb2/setup que…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18248
|
2024-11-21 12:55 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246012
|
5.4 |
MEDIUM
Network
|
icinga
|
icinga_web_2
|
Icinga Web 2 before 2.6.2 has XSS via the /icingaweb2/navigation/add icon parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18247
|
2024-11-21 12:55 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246013
|
6.5 |
MEDIUM
Network
|
icinga
|
icinga_web_2
|
Icinga Web 2 before 2.6.2 has CSRF via /icingaweb2/config/moduledisable?name=monitoring to disable the monitoring module, or via /icingaweb2/config/moduleenable?name=setup to enable the setup module.
|
CWE-352
Origin Validation Error
|
CVE-2018-18246
|
2024-11-21 12:55 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246014
|
5.4 |
MEDIUM
Network
|
nagios debian
|
nagios_core debian_linux
|
Nagios Core 4.4.2 has XSS via the alert summary reports of plugin results, as demonstrated by a SCRIPT element delivered by a modified check_load plugin to NRPE.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18245
|
2024-11-21 12:55 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246015
|
9.8 |
CRITICAL
Network
|
ricoh
|
myprint
|
Hardcoded credentials in the Ricoh myPrint application 2.9.2.4 for Windows and 2.2.7 for Android give access to any externally disclosed myPrint WSDL API, as demonstrated by discovering API secrets o…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-18006
|
2024-11-21 12:55 |
2018-12-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246016
|
7.8 |
HIGH
Local
|
intel
|
solid_state_drive_toolbox
|
Improper directory permissions in Intel Solid State Drive Toolbox before 3.5.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-18097
|
2024-11-21 12:55 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246017
|
5.5 |
MEDIUM
Local
|
intel
|
quickassist_technology_for_linux
|
Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18096
|
2024-11-21 12:55 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246018
|
7.8 |
HIGH
Local
|
intel
|
vtune_amplifier
|
Improper file permissions in the installer for Intel VTune Amplifier 2018 Update 3 and before may allow unprivileged user to potentially gain privileged access via local access.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-18093
|
2024-11-21 12:55 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246019
|
6.1 |
MEDIUM
Network
|
microfocus
|
edirectory
|
Cross site scripting vulnerability in eDirectory prior to 9.1 SP2
|
CWE-79
Cross-site Scripting
|
CVE-2018-17952
|
2024-11-21 12:55 |
2018-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246020
|
7.5 |
HIGH
Network
|
microfocus
|
edirectory
|
Incorrect enforcement of authorization checks in eDirectory prior to 9.1 SP2
|
CWE-863
Incorrect Authorization
|
CVE-2018-17950
|
2024-11-21 12:55 |
2018-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|