|
246721
|
7.8 |
HIGH
Local
|
watchguard
|
ap200_firmware ap102_firmware ap100_firmware
|
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a l…
|
CWE-287
Improper Authentication
|
CVE-2018-10576
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246722
|
9.8 |
CRITICAL
Network
|
watchguard
|
ap200_firmware ap102_firmware ap100_firmware
|
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10575
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246723
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
BigTree before 4.2.22 has XSS in the Users management page via the name or company field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10364
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246724
|
9.8 |
CRITICAL
Network
|
bigtreecms
|
bigtree_cms
|
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php do…
|
CWE-94
Code Injection
|
CVE-2018-10574
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246725
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the scan parameter.
|
NVD-CWE-noinfo
|
CVE-2018-10573
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246726
|
6.5 |
MEDIUM
Network
|
open-emr
|
openemr
|
interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
|
NVD-CWE-noinfo
|
CVE-2018-10572
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246727
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10570
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246728
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/fin…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10571
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246729
|
7.5 |
HIGH
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy before 2018.4.7, target and tenant tag variable scopes were not checked against the list of tenants the user has access to.
|
CWE-269
Improper Privilege Management
|
CVE-2018-10550
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246730
|
5.4 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
An issue was discovered in Nagios XI 5.4.13. There is XSS exploitable via CSRF in (1) the Schedule New Report screen via the hour, minute, or ampm parameter, related to components/scheduledreporting;…
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-10554
|
2024-11-21 12:41 |
2018-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|