|
246681
|
6.1 |
MEDIUM
Network
|
multidots
|
woocommerce_quick_reports
|
The MULTIDOTS WooCommerce Quick Reports plugin 1.0.6 and earlier for WordPress is vulnerable to Stored XSS. It allows an attacker to inject malicious JavaScript code on the WooCommerce -> Orders admi…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11485
|
2024-11-21 12:43 |
2018-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246682
|
6.1 |
MEDIUM
Network
|
graylog
|
graylog
|
Graylog before v2.4.4 has an XSS security issue with unescaped text in dashboard names, related to components/dashboard/Dashboard.jsx, components/dashboard/EditDashboardModal.jsx, and pages/ShowDashb…
|
CWE-79
Cross-site Scripting
|
CVE-2018-11651
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246683
|
6.1 |
MEDIUM
Network
|
graylog
|
graylog
|
Graylog before v2.4.4 has an XSS security issue with unescaped text in notifications, related to toastr and util/UserNotification.js.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11650
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246684
|
6.1 |
MEDIUM
Network
|
gethue
|
hue
|
Hue 3.12 has XSS via the /pig/save/ name and script parameters.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11649
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246685
|
7.5 |
HIGH
Network
|
webkitgtk
|
webkitgtk\+
|
webkitFaviconDatabaseSetIconForPageURL and webkitFaviconDatabaseSetIconURLForPageURL in UIProcess/API/glib/WebKitFaviconDatabase.cpp in WebKit, as used in WebKitGTK+ through 2.21.3, mishandle an unse…
|
NVD-CWE-noinfo
|
CVE-2018-11646
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246686
|
5.3 |
MEDIUM
Network
|
artifex
|
ghostscript
|
psi/zfile.c in Artifex Ghostscript before 9.21rc1 permits the status command even if -dSAFER is used, which might allow remote attackers to determine the existence and size of arbitrary files, a simi…
|
CWE-200
Information Exposure
|
CVE-2018-11645
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246687
|
6.5 |
MEDIUM
Network
|
multidots
|
woo_checkout_for_digital_goods
|
An issue was discovered in the MULTIDOTS Woo Checkout for Digital Goods plugin 2.1 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an attacker (via spear phishin…
|
CWE-352
Origin Validation Error
|
CVE-2018-11633
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246688
|
6.5 |
MEDIUM
Network
|
multidots
|
add_social_share_messenger_buttons_whatsapp_and_viber
|
An issue was discovered in the MULTIDOTS Add Social Share Messenger Buttons Whatsapp and Viber plugin 1.0.8 for WordPress. If an admin user can be tricked into visiting a crafted URL created by an at…
|
CWE-352
Origin Validation Error
|
CVE-2018-11632
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246689
|
4.3 |
MEDIUM
Adjacent
|
rondaful_project
|
rondaful_m1_wristband_smart_band_1_firmware
|
Rondaful M1 Wristband Smart Band 1 devices allow remote attackers to send an arbitrary number of call or SMS notifications via crafted Bluetooth Low Energy (BLE) traffic.
|
NVD-CWE-noinfo
|
CVE-2018-11631
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246690
|
6.1 |
MEDIUM
Network
|
sinatrarb redhat
|
sinatra cloudforms
|
Sinatra before 2.0.2 has XSS via the 400 Bad Request page that occurs upon a params parser exception.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11627
|
2024-11-21 12:43 |
2018-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|