|
245721
|
8.1 |
HIGH
Network
|
xiph debian
|
icecast debian_linux
|
A buffer overflow was discovered in the URL-authentication backend of the Icecast before 2.4.4. If the backend is enabled, then any malicious HTTP client can send a request for that specific resource…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18820
|
2024-11-21 12:56 |
2018-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245722
|
4.8 |
MEDIUM
Network
|
jeecms
|
jeecms
|
JEECMS 9.3 has XSS via an index.do#/content/update?type=update URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18952
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245723
|
7.5 |
HIGH
Network
|
kindeditor
|
kindeditor
|
KindEditor through 4.1.11 has a path traversal vulnerability in php/upload_json.php. Anyone can browse a file or directory in the kindeditor/attached/ folder via the path parameter without authentica…
|
CWE-22
Path Traversal
|
CVE-2018-18950
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245724
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_opmanager
|
Zoho ManageEngine OpManager 12.3 before 123222 has SQL Injection via Mail Server settings.
|
CWE-89
SQL Injection
|
CVE-2018-18949
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245725
|
4.8 |
MEDIUM
Network
|
basercms
|
basercms
|
An issue was discovered in baserCMS before 4.1.4. In the Register New Category feature of the Upload menu, the category name can be used for XSS via the data[UploaderCategory][name] parameter to an a…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18943
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245726
|
7.2 |
HIGH
Network
|
basercms
|
basercms
|
In baserCMS before 4.1.4, lib\Baser\Model\ThemeConfig.php allows remote attackers to execute arbitrary PHP code via the admin/theme_configs/form data[ThemeConfig][logo] parameter.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-18942
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245727
|
4.8 |
MEDIUM
Network
|
wuzhi_cms_project
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via a seventh input field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18939
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245728
|
4.8 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is stored XSS in index.php?m=core&f=index via an ontoggle attribute to details/open/ within a second input field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18938
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245729
|
7.5 |
HIGH
Network
|
mz-automation
|
libiec61850
|
An issue has been found in libIEC61850 v1.3. It is a NULL pointer dereference in ClientDataSet_getValues in client/ied_connection.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18937
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245730
|
7.5 |
HIGH
Network
|
popojicms
|
popojicms
|
An issue was discovered in PopojiCMS v2.0.1. admin_library.php allows remote attackers to delete arbitrary files via directory traversal in the po-admin/route.php?mod=library&act=delete id parameter.
|
CWE-22
Path Traversal
|
CVE-2018-18936
|
2024-11-21 12:56 |
2018-11-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|