|
246641
|
9.8 |
CRITICAL
Network
|
monstra
|
monstra_cms
|
plugins/box/users/users.plugin.php in Monstra CMS 3.0.4 allows Login Rate Limiting Bypass via manipulation of the login_attempts cookie.
|
CWE-20
Improper Input Validation
|
CVE-2018-11678
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246642
|
9.8 |
CRITICAL
Network
|
yzmcms
|
yzmcms
|
The forgotten-password feature in index.php/member/reset/reset_email.html in YzmCMS v3.2 through v3.7 has a Response Discrepancy Information Exposure issue and an unexpectedly long lifetime for a ver…
|
CWE-200
Information Exposure
|
CVE-2018-11554
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246643
|
9.8 |
CRITICAL
Network
|
pluck-cms
|
pluck
|
An issue was discovered in Pluck before 4.7.7-dev2. /data/inc/images.php allows remote attackers to upload and execute arbitrary PHP code by using the image/jpeg content type for a .htaccess file.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11736
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246644
|
6.1 |
MEDIUM
Network
|
ximdex
|
ximdex
|
index.php?action=createaccount in Ximdex 4.0 has XSS via the sname or fname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11735
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246645
|
5.4 |
MEDIUM
Network
|
recent_threads_project
|
recent_threads
|
The Recent Threads plugin before 1.1 for MyBB allows XSS via a thread subject.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11715
|
2024-11-21 12:43 |
2018-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246646
|
9.8 |
CRITICAL
Network
|
tp-link
|
tl-wr840n_firmware tl-wr841n_firmware
|
An issue was discovered on TP-Link TL-WR840N v5 00000005 0.9.1 3.16 v0001.0 Build 170608 Rel.58696n and TL-WR841N v13 00000013 0.9.1 4.16 v0001.0 Build 170622 Rel.64334n devices. This issue is caused…
|
CWE-384
Session Fixation
|
CVE-2018-11714
|
2024-11-21 12:43 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246647
|
6.5 |
MEDIUM
Network
|
webkitgtk gnome
|
webkitgtk\+ libsoup
|
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ prior to version 2.20.0 or without libsoup 2.62.0, unexpectedly failed to …
|
NVD-CWE-noinfo
|
CVE-2018-11713
|
2024-11-21 12:43 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246648
|
7.5 |
HIGH
Network
|
webkitgtk
|
webkitgtk\+
|
WebCore/platform/network/soup/SocketStreamHandleImplSoup.cpp in the libsoup network backend of WebKit, as used in WebKitGTK+ versions 2.20.0 and 2.20.1, failed to perform TLS certificate verification…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-11712
|
2024-11-21 12:43 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246649
|
9.8 |
CRITICAL
Network
|
canon
|
mf210_firmware mf220_firmware
|
A remote attacker can bypass the System Manager Mode on the Canon MF210 and MF220 web interface without knowing the PIN for /login.html via vectors involving /portal_top.html to get full access to th…
|
CWE-287
Improper Authentication
|
CVE-2018-11711
|
2024-11-21 12:43 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246650
|
8.8 |
HIGH
Network
|
openmpt
|
libopenmpt
|
soundlib/pattern.h in libopenmpt before 0.3.9 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted AMS file because of an i…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-11710
|
2024-11-21 12:43 |
2018-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|