|
246571
|
9.8 |
CRITICAL
Network
|
hp
|
fortify_software_security_center
|
An XML external entity (XXE) vulnerability in Fortify Software Security Center (SSC), version 17.1, 17.2, 18.1 allows remote unauthenticated users to read arbitrary files or conduct server-side reque…
|
CWE-611
XXE
|
CVE-2018-12463
|
2024-11-21 12:45 |
2018-07-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246572
|
8.8 |
HIGH
Network
|
eclipse
|
vert.x
|
In version from 3.0.0 to 3.5.2 of Eclipse Vert.x, the CSRFHandler do not assert that the XSRF Cookie matches the returned XSRF header/form parameter. This allows replay attacks with previously issued…
|
CWE-352
Origin Validation Error
|
CVE-2018-12540
|
2024-11-21 12:45 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246573
|
6.1 |
MEDIUM
Network
|
netiq
|
imanager
|
NetIQ iManager 3.1.1 addresses potential XSS vulnerabilities.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12462
|
2024-11-21 12:45 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246574
|
7.5 |
HIGH
Network
|
netiq
|
edirectory
|
Fixed issues with NetIQ eDirectory prior to 9.1.1 when checking certificate revocation.
|
CWE-295
Improper Certificate Validation
|
CVE-2018-12461
|
2024-11-21 12:45 |
2018-07-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246575
|
8.8 |
HIGH
Network
|
beescms
|
beescms
|
In BEESCMS 4.0, CSRF allows administrators to be added arbitrarily, a related issue to CVE-2018-10266.
|
CWE-352
Origin Validation Error
|
CVE-2018-12739
|
2024-11-21 12:45 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246576
|
9.8 |
CRITICAL
Network
|
microsoft
|
forefront_unified_access_gateway
|
uniquesig0/InternalSite/InitParams.aspx in Microsoft Forefront Unified Access Gateway 2010 allows remote attackers to trigger outbound DNS queries for arbitrary hosts via a comma-separated list of UR…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-12571
|
2024-11-21 12:45 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246577
|
8.1 |
HIGH
Network
|
ntop
|
ntopng
|
An issue was discovered in ntopng 3.4 before 3.4.180617. The PRNG involved in the generation of session IDs is not seeded at program startup. This results in deterministic session IDs being allocated…
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2018-12520
|
2024-11-21 12:45 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246578
|
6.8 |
MEDIUM
Network
|
onosproject
|
onos
|
Time-of-check to time-of-use (TOCTOU) race condition in org.onosproject.acl (aka the access control application) in ONOS v1.13 and earlier allows attackers to bypass network access control via data p…
|
CWE-362
Race Condition
|
CVE-2018-12691
|
2024-11-21 12:45 |
2018-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246579
|
9.8 |
CRITICAL
Network
|
3cx
|
live_chat
|
The WP Live Chat Support Pro plugin before 8.0.07 for WordPress is vulnerable to unauthenticated Remote Code Execution due to client-side validation of allowed file types, as demonstrated by a v1/rem…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-12426
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246580
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wr841n_firmware
|
The Ping and Traceroute features on TP-Link TL-WR841N v13 00000001 0.9.1 4.16 v0001.0 Build 180119 Rel.65243n devices allow authenticated blind Command Injection.
|
CWE-78
OS Command
|
CVE-2018-12577
|
2024-11-21 12:45 |
2018-07-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|