|
246371
|
7.3 |
HIGH
Network
|
siemens
|
simatic_s7-1200_v4_firmware
|
A vulnerability has been identified in SIMATIC S7-1200 CPU family version 4 (All versions < V4.2.3). The web interface could allow a Cross-Site Request Forgery (CSRF) attack if an unsuspecting user i…
|
CWE-352
Origin Validation Error
|
CVE-2018-13800
|
2024-11-21 12:48 |
2018-10-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246372
|
9.8 |
CRITICAL
Network
|
d-link
|
dir-809_a1_firmware dir-809_a2_firmware dir-809_guestzone_firmware
|
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. Device passwords, such as the admin password and the WPA key, are stored in cleartext.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-14081
|
2024-11-21 12:48 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246373
|
7.5 |
HIGH
Network
|
d-link
|
dir-809_a1_firmware dir-809_a2_firmware dir-809_guestzone_firmware
|
An issue was discovered on D-Link DIR-809 A1 through 1.09, A2 through 1.11, and Guest Zone through 1.09 devices. One can bypass authentication mechanisms to download the configuration file.
|
CWE-287
Improper Authentication
|
CVE-2018-14080
|
2024-11-21 12:48 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246374
|
6.1 |
MEDIUM
Network
|
progress
|
kendo_ui
|
Cross-site scripting (XSS) vulnerability in Progress Kendo UI Editor v2018.1.221 allows remote attackers to inject arbitrary JavaScript into the DOM of the WYSIWYG editor because of the editorNS.Seri…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14037
|
2024-11-21 12:48 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246375
|
7.8 |
HIGH
Local
|
ee
|
ee40vb_firmware
|
The installer for the Alcatel OSPREY3_MINI Modem component on EE EE40VB 4G mobile broadband modems with firmware before EE40_00_02.00_45 sets weak permissions (Everyone:Full Control) for the "Web Con…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14327
|
2024-11-21 12:48 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246376
|
8.8 |
HIGH
Network
|
samsung
|
galaxy_s8_firmware
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Samsung Galaxy S8 G950FXXU1AQL5. User interaction is required to exploit this vulnerability in that…
|
CWE-20
Improper Input Validation
|
CVE-2018-14318
|
2024-11-21 12:48 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246377
|
7.5 |
HIGH
Network
|
smarty debian
|
smarty debian_linux
|
Smarty_Security::isTrustedResourceDir() in Smarty before 3.1.33 is prone to a path traversal vulnerability due to insufficient template code sanitization. This allows attackers controlling the execut…
|
CWE-22
Path Traversal
|
CVE-2018-13982
|
2024-11-21 12:48 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246378
|
6.5 |
MEDIUM
Network
|
podofo_project
|
podofo
|
This vulnerability allows remote attackers to disclose sensitive information on vulnerable installations of PoDoFo. User interaction is required to exploit this vulnerability in that the target must …
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14320
|
2024-11-21 12:48 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246379
|
8.6 |
HIGH
Network
|
siemens
|
scalance_x408_firmware scalance_x300_firmware scalance_x414_firmware
|
A vulnerability has been identified in SCALANCE X300 (All versions < V4.0.0), SCALANCE X408 (All versions < V4.0.0), SCALANCE X414 (All versions). The web interface on port 443/tcp could allow an att…
|
CWE-20
Improper Input Validation
|
CVE-2018-13807
|
2024-11-21 12:48 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246380
|
7.8 |
HIGH
Local
|
siemens
|
td_keypad_designer
|
A vulnerability has been identified in SIEMENS TD Keypad Designer (All versions). A DLL hijacking vulnerability exists in all versions of SIEMENS TD Keypad Designer which could allow an attacker to e…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2018-13806
|
2024-11-21 12:48 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|