|
245761
|
7.5 |
HIGH
Network
|
lightbend
|
spray-json
|
Lightbend Spray spray-json through 1.3.4 allows remote attackers to cause a denial of service (resource consumption) because of Algorithmic Complexity during the parsing of a field composed of many d…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-18853
|
2024-11-21 12:56 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245762
|
8.8 |
HIGH
Network
|
octopus
|
octopus_server
|
In Octopus Deploy 2018.8.0 through 2018.9.x before 2018.9.1, an authenticated user with permission to modify deployment processes could upload a maliciously crafted YAML configuration, potentially al…
|
NVD-CWE-noinfo
|
CVE-2018-18850
|
2024-11-21 12:56 |
2018-10-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245763
|
8.8 |
HIGH
Network
|
zblogcn
|
z-blogphp
|
CSRF exists in zb_users/plugin/AppCentre/theme.js.php in Z-BlogPHP 1.5.2.1935 (Zero), which allows remote attackers to execute arbitrary PHP code.
|
CWE-352
Origin Validation Error
|
CVE-2018-18842
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245764
|
4.8 |
MEDIUM
Network
|
sem-cms
|
semcms
|
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexkey parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18841
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245765
|
5.4 |
MEDIUM
Network
|
sem-cms
|
semcms
|
XSS was discovered in SEMCMS PHP V3.4 via the SEMCMS_SeoAndTag.php?Class=edit&CF=SeoAndTag tag_indexmetatit parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18840
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245766
|
9.8 |
CRITICAL
Network
|
doccms
|
doccms
|
upload_template() in system/changeskin.php in DocCms 2016.5.12 allows remote attackers to execute arbitrary PHP code via a template file.
|
CWE-94
Code Injection
|
CVE-2018-18835
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245767
|
9.8 |
CRITICAL
Network
|
mz-automation
|
libiec61850
|
An issue has been found in libIEC61850 v1.3. It is a heap-based buffer overflow in BerEncoder_encodeOctetString in mms/asn1/ber_encoder.c.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18834
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245768
|
9.8 |
CRITICAL
Network
|
dkcms
|
dkcms
|
admin/check.asp in DKCMS 9.4 allows SQL Injection via an ASPSESSIONID cookie to admin/admin.asp.
|
CWE-89
SQL Injection
|
CVE-2018-18832
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245769
|
7.5 |
HIGH
Network
|
mingsoft
|
mcms
|
An issue was discovered in com\mingsoft\cms\action\GeneraterAction.java in MCMS 4.6.5. An attacker can write a .jsp file (in the position parameter) to an arbitrary directory via a ../ Directory Trav…
|
CWE-22
Path Traversal
|
CVE-2018-18831
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245770
|
9.8 |
CRITICAL
Network
|
mingsoft
|
mcms
|
An issue was discovered in com\mingsoft\basic\action\web\FileAction.java in MCMS 4.6.5. Since the upload interface does not verify the user login status, you can use this interface to upload files wi…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-18830
|
2024-11-21 12:56 |
2018-10-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|