|
246411
|
4.0 |
MEDIUM
Local
|
signal
|
signal-desktop
|
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
|
CWE-200
Information Exposure
|
CVE-2018-14023
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246412
|
5.3 |
MEDIUM
Network
|
paymorrow
|
paymorrow
|
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eS…
|
NVD-CWE-noinfo
|
CVE-2018-14020
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246413
|
7.5 |
HIGH
Network
|
wi2be
|
smart_hp_wmt
|
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp.
|
CWE-200
Information Exposure
|
CVE-2018-14079
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246414
|
9.8 |
CRITICAL
Network
|
wi2be
|
smart_hp_wmt
|
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username wi…
|
CWE-287
Improper Authentication
|
CVE-2018-14078
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246415
|
7.5 |
HIGH
Network
|
wi2be
|
smart_hp_wmt
|
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to backup the device configuration via a direct request to /Maintenance/configfile.cfg.
|
NVD-CWE-noinfo
|
CVE-2018-14077
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246416
|
6.5 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
|
CWE-89
SQL Injection
|
CVE-2018-14058
|
2024-11-21 12:48 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246417
|
8.8 |
HIGH
Network
|
pimcore
|
pimcore
|
Pimcore before 5.3.0 allows remote attackers to conduct cross-site request forgery (CSRF) attacks by leveraging validation of the X-pimcore-csrf-token anti-CSRF token only in the "Settings > Users / …
|
CWE-352
Origin Validation Error
|
CVE-2018-14057
|
2024-11-21 12:48 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246418
|
9.8 |
CRITICAL
Network
|
citrix
|
xenserver
|
Citrix XenServer 7.1 and newer allows Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2018-14007
|
2024-11-21 12:48 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246419
|
8.1 |
HIGH
Network
|
libcgroup_project debian fedoraproject
|
libcgroup debian_linux fedora
|
libcgroup up to and including 0.41 creates /var/log/cgred with mode 0666 regardless of the configured umask, leading to disclosure of information.
|
CWE-200
Information Exposure
|
CVE-2018-14348
|
2024-11-21 12:48 |
2018-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246420
|
7.2 |
HIGH
Network
|
wordpress
|
wordpress
|
In WordPress 4.9.7, plugins uploaded via the admin area are not verified as being ZIP files. This allows for PHP files to be uploaded. Once a PHP file is uploaded, the plugin extraction fails, but th…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-14028
|
2024-11-21 12:48 |
2018-08-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|