|
246181
|
7.8 |
HIGH
Local
|
jhead_project
|
jhead
|
The ProcessGpsInfo function of the gpsinfo.c file of jhead 3.00 may allow a remote attacker to cause a denial-of-service attack or unspecified other impact via a malicious JPEG file, because of incon…
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2018-16554
|
2024-11-21 12:52 |
2018-09-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246182
|
8.6 |
HIGH
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows reading of arbitrary files via signEzUI/playlist/edit/upload/..%2f URIs.
|
CWE-200
Information Exposure
|
CVE-2018-16288
|
2024-11-21 12:52 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246183
|
9.8 |
CRITICAL
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows file upload via signEzUI/playlist/edit/upload/..%2f URIs.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16287
|
2024-11-21 12:52 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246184
|
9.8 |
CRITICAL
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows authentication bypass because the CAPTCHA requirement is skipped if a captcha:pass cookie is sent, and because the PIN is limited to four digits.
|
CWE-287
Improper Authentication
|
CVE-2018-16286
|
2024-11-21 12:52 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246185
|
5.3 |
MEDIUM
Adjacent
|
o.bike
|
smart_locker_firmware obike-stationless_bike_sharing
|
oBike relies on Hangzhou Luoping Smart Locker to lock bicycles, which allows attackers to bypass the locking mechanism by using Bluetooth Low Energy (BLE) to replay ciphertext based on a predictable …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2018-16242
|
2024-11-21 12:52 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246186
|
6.5 |
MEDIUM
Network
|
e107
|
e107
|
e107_admin/banlist.php in e107 2.1.8 allows SQL injection via the old_ip parameter.
|
CWE-89
SQL Injection
|
CVE-2018-16389
|
2024-11-21 12:52 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246187
|
7.2 |
HIGH
Network
|
e107
|
e107
|
e107_web/js/plupload/upload.php in e107 2.1.8 allows remote attackers to execute arbitrary PHP code by uploading a .php filename with the image/jpeg content type.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16388
|
2024-11-21 12:52 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246188
|
7.5 |
HIGH
Network
|
currency_converter_script_project
|
currency_converter_script
|
PHP Scripts Mall Currency Converter Script 2.0.5 allows remote attackers to cause a denial of service (web-interface change) via an inverted comma.
|
CWE-20
Improper Input Validation
|
CVE-2018-16454
|
2024-11-21 12:52 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246189
|
5.4 |
MEDIUM
Network
|
filemanagerpro
|
file_manager
|
The mndpsingh287 File Manager plugin V2.9 for WordPress has XSS via the lang parameter in a wp-admin/admin.php?page=wp_file_manager request because set_transient is used in file_folder_manager.php an…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16363
|
2024-11-21 12:52 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246190
|
5.3 |
MEDIUM
Network
|
endress
|
wirelesshart_fieldgate_swg70_firmware
|
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
|
CWE-22
Path Traversal
|
CVE-2018-16059
|
2024-11-21 12:52 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|