|
246241
|
6.5 |
MEDIUM
Network
|
uclouvain debian
|
openjpeg debian_linux
|
OpenJPEG 2.3.0 has a NULL pointer dereference for "red" in the imagetopnm function of jp2/convert.c
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18088
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246242
|
5.4 |
MEDIUM
Network
|
bixie
|
portfolio
|
The Bixie Portfolio plugin 1.2.0 for Pagekit has XSS: a logged-in user who has the "Manage portfolio" privilege can inject arbitrary web script or HTML via the Image URL field in the portfolio editor…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18087
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246243
|
8.8 |
HIGH
Network
|
phome
|
empirecms
|
EmpireCMS v7.5 has an arbitrary file upload vulnerability in the LoadInMod function in e/class/moddofun.php, exploitable by logged-in users.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-18086
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246244
|
9.8 |
CRITICAL
Network
|
comsenz
|
duomicms
|
An issue was discovered in DuomiCMS 3.0. SQL injection exists in the ajax.php file, as demonstrated by the uid parameter.
|
CWE-89
SQL Injection
|
CVE-2018-18084
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246245
|
9.8 |
CRITICAL
Network
|
comsenz
|
duomicms
|
An issue was discovered in DuomiCMS 3.0. Remote PHP code execution is possible via the search.php searchword parameter because "eval" is used during "if" processing.
|
CWE-94
Code Injection
|
CVE-2018-18083
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246246
|
6.1 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
XSS exists in Waimai Super Cms 20150505 via the fname parameter to the admin.php?m=Food&a=addsave or admin.php?m=Food&a=editsave URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18082
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246247
|
9.8 |
CRITICAL
Network
|
wikidforum_project
|
wikidforum
|
WikidForum 2.20 has SQL Injection via the rpc.php parent_post_id or num_records parameter, or the index.php?action=search select_sort parameter.
|
CWE-89
SQL Injection
|
CVE-2018-18075
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246248
|
7.5 |
HIGH
Network
|
python canonical opensuse redhat
|
requests ubuntu_linux leap enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server
|
The Requests package before 2.20.0 for Python sends an HTTP Authorization header to an http URI upon receiving a same-hostname https-to-http redirect, which makes it easier for remote attackers to di…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-18074
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246249
|
5.4 |
MEDIUM
Network
|
naviwebs
|
navigate_cms
|
Navigate CMS has Stored XSS via the navigate.php Title field in an edit action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18029
|
2024-11-21 12:55 |
2018-10-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246250
|
7.5 |
HIGH
Network
|
mercedes-benz
|
mercedes_me
|
An issue was discovered in the Daimler Mercedes-Benz Me app 2.11.0-846 for iOS. The encrypted Connected Vehicle API data exchange between the app and a server might be intercepted. The app can be use…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2018-18071
|
2024-11-21 12:55 |
2018-10-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|