|
246181
|
7.5 |
HIGH
Network
|
mesilat
|
zabbix
|
The MESILAT Zabbix plugin before 1.1.15 for Atlassian Confluence allows attackers to read arbitrary files.
|
CWE-200
Information Exposure
|
CVE-2018-18289
|
2024-11-21 12:55 |
2018-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246182
|
5.3 |
MEDIUM
Network
|
asus
|
rt-ac58u_firmware
|
On ASUS RT-AC58U 3.0.0.4.380_6516 devices, remote attackers can discover hostnames and IP addresses by reading dhcpLeaseInfo data in the HTML source code of the Main_Login.asp page.
|
CWE-200
Information Exposure
|
CVE-2018-18287
|
2024-11-21 12:55 |
2018-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246183
|
6.1 |
MEDIUM
Network
|
zeit
|
next.js
|
Next.js 7.0.0 and 7.0.1 has XSS via the 404 or 500 /_error page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18282
|
2024-11-21 12:55 |
2018-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246184
|
7.8 |
HIGH
Local
|
pdfalto_project
|
pdfalto
|
A issue was found in pdfalto 0.2. There is a heap-based buffer overflow in the TextPage::addAttributsNode function in XmlAltoOutputDev.cc.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18274
|
2024-11-21 12:55 |
2018-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246185
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
XSS exists in CMS Made Simple version 2.2.7 via the m1_extra parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18271
|
2024-11-21 12:55 |
2018-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246186
|
6.1 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
XSS exists in CMS Made Simple version 2.2.7 via the m1_news_url parameter in an admin/moduleinterface.php "Content-->News-->Add Article" action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18270
|
2024-11-21 12:55 |
2018-10-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246187
|
9.8 |
CRITICAL
Network
|
asuswrt-merlin_project
|
rt-ac5300_firmware rt_ac1900p_firmware rt-ac68u_firmware rt-ac68p_firmware rt-ac88u_firmware rt-ac66u_b1_firmware rt-ac56u_firmware rt-ac3200_firmware rt-ac68uf_firmware rt…
|
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because exec.php has a popen call. NOTE: the vendor indicates that Mer…
|
NVD-CWE-noinfo
|
CVE-2018-18320
|
2024-11-21 12:55 |
2018-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246188
|
9.8 |
CRITICAL
Network
|
asuswrt-merlin_project
|
rt-ac5300_firmware rt_ac1900p_firmware rt-ac68u_firmware rt-ac68p_firmware rt-ac88u_firmware rt-ac66u_b1_firmware rt-ac56u_firmware rt-ac3200_firmware rt-ac68uf_firmware rt…
|
An issue was discovered in the Merlin.PHP component 0.6.6 for Asuswrt-Merlin devices. An attacker can execute arbitrary commands because api.php has an eval call, as demonstrated by the /6/api.php?fu…
|
CWE-94
Code Injection
|
CVE-2018-18319
|
2024-11-21 12:55 |
2018-10-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246189
|
5.3 |
MEDIUM
Network
|
yokogawa
|
fcj_firmware fcn-100_firmware fcn-rtu_firmware fcn-500_firmware
|
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The application utilizes multiple methods of session management which could result in a denial of service to…
|
CWE-384
Session Fixation
|
CVE-2018-17902
|
2024-11-21 12:55 |
2018-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246190
|
9.8 |
CRITICAL
Network
|
yokogawa
|
fcj_firmware fcn-100_firmware fcn-rtu_firmware fcn-500_firmware
|
Yokogawa STARDOM Controllers FCJ, FCN-100, FCN-RTU, FCN-500, All versions R4.10 and prior, The web application improperly protects credentials which could allow an attacker to obtain credentials for …
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-17900
|
2024-11-21 12:55 |
2018-10-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|