|
246471
|
7.5 |
HIGH
Network
|
mercurial
|
mercurial
|
The mpatch_apply function in mpatch.c in Mercurial before 4.6.1 incorrectly proceeds in cases where the fragment start is past the end of the original data, aka OVE-20180430-0004.
|
CWE-20
Improper Input Validation
|
CVE-2018-13346
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246472
|
8.8 |
HIGH
Network
|
gleeztech
|
gleez_cms
|
Gleez CMS 1.2.0 has CSRF, as demonstrated by a /page/add request.
|
CWE-352
Origin Validation Error
|
CVE-2018-13340
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246473
|
6.1 |
MEDIUM
Network
|
angular_redactor_project
|
angular_redactor
|
Imperavi Redactor 3 in Angular Redactor 1.1.6, when HTML content mode is used, allows stored XSS, as demonstrated by an onerror attribute of an IMG element, a related issue to CVE-2018-7035.
|
CWE-79
Cross-site Scripting
|
CVE-2018-13339
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246474
|
9.8 |
CRITICAL
Network
|
cyberark
|
endpoint_privilege_manager
|
In CyberArk Endpoint Privilege Manager (formerly Viewfinity), Privilege Escalation is possible if the attacker has one process that executes as Admin.
|
NVD-CWE-noinfo
|
CVE-2018-13052
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246475
|
8.8 |
HIGH
Network
|
damicms
|
damicms
|
DamiCMS v6.0.0 aand 6.1.0 allows CSRF via admin.php?s=/Admin/doadd to add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-13031
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246476
|
7.5 |
HIGH
Network
|
pfg_project
|
pfg
|
The transfer, transferFrom, and mint functions of a smart contract implementation for PFGc, an Ethereum token, have an integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13328
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246477
|
7.5 |
HIGH
Network
|
chucunlingaigo_project
|
chucunlingaigo
|
The transfer and transferFrom functions of a smart contract implementation for ChuCunLingAIGO (CCLAG), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13327
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246478
|
7.5 |
HIGH
Network
|
bittelux_project
|
bittelux
|
The transfer and transferFrom functions of a smart contract implementation for Bittelux (BTX), an Ethereum token, have an integer overflow. NOTE: this has been disputed by a third party.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13326
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246479
|
7.5 |
HIGH
Network
|
boodskap
|
growchain
|
The _sell function of a smart contract implementation for GROWCHAIN (GROW), an Ethereum token, has an integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-13325
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246480
|
9.8 |
CRITICAL
Network
|
godoc
|
go_doc_dot_org
|
In Go Doc Dot Org (gddo) through 2018-06-27, an attacker could use specially crafted <go-import> tags in packages being fetched by gddo to cause a directory traversal and remote code execution.
|
CWE-22
Path Traversal
|
CVE-2018-12976
|
2024-11-21 12:46 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|