|
246311
|
4.3 |
MEDIUM
Network
|
wisetail
|
learning_management_system
|
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to access non-purchased course contents (quiz / test) via a modified id parameter.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-16971
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246312
|
4.3 |
MEDIUM
Network
|
wisetail
|
learning_management_system
|
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
|
CWE-538
File and Directory Information Exposure
|
CVE-2018-16970
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246313
|
7.8 |
HIGH
Local
|
webroot
|
secureanywhere
|
Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.
|
CWE-123
Write-what-where Condition
|
CVE-2018-16962
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246314
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16729
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246315
|
5.4 |
MEDIUM
Network
|
feindura
|
feindura
|
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16728
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246316
|
5.4 |
MEDIUM
Network
|
razorcms
|
razorcms
|
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16727
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246317
|
5.4 |
MEDIUM
Network
|
razorcms
|
razorcms
|
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16726
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246318
|
5.4 |
MEDIUM
Network
|
dlink
|
dir-600m_firmware
|
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16605
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246319
|
6.5 |
MEDIUM
Adjacent
|
inteno
|
dg400_firmware
|
Inteno DG400 WU7U_ELION3.11.6-170614_1328 devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses, as demonstrated by macof.
|
NVD-CWE-noinfo
|
CVE-2018-16950
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246320
|
8.0 |
HIGH
Network
|
xunfeng_project
|
xunfeng
|
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.
|
CWE-352
Origin Validation Error
|
CVE-2018-16951
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|