|
245931
|
6.1 |
MEDIUM
Network
|
elementor
|
elementor_page_builder
|
The elementor-edit-template class in wp-admin/customize.php in the Elementor Pro plugin before 2.0.10 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18379
|
2024-11-21 12:55 |
2019-10-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245932
|
6.5 |
MEDIUM
Network
|
broadcom
|
symantec_proxysg advanced_secure_gateway
|
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. An information disclosure vulnerability in the WebFTP …
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-18371
|
2024-11-21 12:55 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245933
|
6.1 |
MEDIUM
Network
|
broadcom
|
symantec_proxysg advanced_secure_gateway
|
The ASG/ProxySG FTP proxy WebFTP mode allows intercepting FTP connections where a user accesses an FTP server via a ftp:// URL in a web browser. A stored cross-site scripting (XSS) vulnerability in t…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18370
|
2024-11-21 12:55 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245934
|
4.6 |
MEDIUM
Physics
|
ti
|
tm4c123_firmware tm4c129_firmware
|
An issue was discovered in the Texas Instruments (TI) TM4C, MSP432E and MSP432P microcontroller series. The eXecute-Only-Memory (XOM) implementation prevents code read-outs on protected memory by gen…
|
CWE-200
Information Exposure
|
CVE-2018-18056
|
2024-11-21 12:55 |
2019-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245935
|
6.8 |
MEDIUM
Physics
|
intel
|
ssd_dc_s4500_firmware ssd_dc_s4600_firmware
|
Improper authentication in firmware for Intel(R) SSD DC S4500 Series and Intel(R) SSD DC S4600 Series before SCV10150 may allow an unprivileged user to potentially enable escalation of privilege via …
|
CWE-287
Improper Authentication
|
CVE-2018-18095
|
2024-11-21 12:55 |
2019-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245936
|
7.5 |
HIGH
Network
|
dnnsoftware
|
dotnetnuke
|
DNN (aka DotNetNuke) 9.2 through 9.2.2 incorrectly converts encryption key source values, resulting in lower than expected entropy. NOTE: this issue exists because of an incomplete fix for CVE-2018-1…
|
CWE-331
Insufficient Entropy
|
CVE-2018-18326
|
2024-11-21 12:55 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245937
|
9.8 |
CRITICAL
Network
|
scriptzee
|
hotel_booking_engine
|
SQL injection exists in Scriptzee Hotel Booking Engine 1.0 via the hotels h_room_type parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17842
|
2024-11-21 12:55 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245938
|
9.8 |
CRITICAL
Network
|
flippa_marketplace_clone_project
|
flippa_marketplace_clone
|
SQL injection exists in Scriptzee Flippa Marketplace Clone 1.0 via the site-search sortBy or sortDir parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17841
|
2024-11-21 12:55 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245939
|
9.8 |
CRITICAL
Network
|
education_website_project
|
education_website
|
SQL injection exists in Scriptzee Education Website 1.0 via the college_list.html subject, city, or country parameter.
|
CWE-89
SQL Injection
|
CVE-2018-17840
|
2024-11-21 12:55 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245940
|
9.8 |
CRITICAL
Network
|
westerndigital
|
my_book_live_firmware
|
Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug via shell metacharacters in the /api/1.0/rest/language_configuration language parameter…
|
CWE-78
OS Command
|
CVE-2018-18472
|
2024-11-21 12:55 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|