|
245821
|
7.5 |
HIGH
Network
|
tenda
|
ac7_firmware ac9_firmware ac10_firmware ac15_firmware ac18_firmware
|
An issue was discovered on Tenda AC7 V15.03.06.44_CN, AC9 V15.03.05.19(6318)_CN, AC10 V15.03.06.23_CN, AC15 V15.03.05.19_CN, and AC18 V15.03.05.19(6318)_CN devices. There is a buffer overflow vulnera…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18727
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245822
|
4.8 |
MEDIUM
Network
|
yunucms
|
yunucms
|
An XSS issue was discovered in index.php/admin/area/editarea/id/110000 in YUNUCMS 1.1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18723
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245823
|
4.8 |
MEDIUM
Network
|
yunucms
|
yunucms
|
An XSS issue was discovered in admin/content/editcontent?id=29&gopage=1 in YUNUCMS 1.1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18722
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245824
|
4.8 |
MEDIUM
Network
|
yunucms
|
yunucms
|
An XSS issue was discovered in admin/link/editlink?id=5 in YUNUCMS 1.1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18721
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245825
|
4.8 |
MEDIUM
Network
|
yunucms
|
yunucms
|
An XSS issue was discovered in index.php/admin/system/basic in YUNUCMS 1.1.5.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18720
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245826
|
7.8 |
HIGH
Local
|
gnome debian
|
gthumb debian_linux
|
An issue was discovered in gThumb through 3.6.2. There is a double-free vulnerability in the add_themes_from_dir method in dlg-contact-sheet.c because of two successive calls of g_free, each of which…
|
CWE-415
Double Free
|
CVE-2018-18718
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245827
|
4.8 |
MEDIUM
Network
|
eleanor-cms
|
eleanor_cms
|
An issue was discovered in Eleanor CMS through 2015-03-19. XSS exists via the ajax.php?direct=admin&file=autocomplete&query=[XSS] URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18717
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245828
|
7.5 |
HIGH
Network
|
phpyun
|
phpyun
|
The function down_sql_action() in /admin/model/database.class.php in PHPYun 4.6 allows remote attackers to read arbitrary files via directory traversal in an m=database&c=down_sql&name=../ URI.
|
CWE-22
Path Traversal
|
CVE-2018-18713
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245829
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's username via index.php?m=member&f=index&v=edit&uid=1.
|
CWE-352
Origin Validation Error
|
CVE-2018-18712
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245830
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is a CSRF vulnerability that can change the super administrator's password via index.php?m=core&f=panel&v=edit_info.
|
CWE-352
Origin Validation Error
|
CVE-2018-18711
|
2024-11-21 12:56 |
2018-10-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|