|
251401
|
6.1 |
MEDIUM
Network
|
soflyy
|
wp_all_import
|
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.7 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0547
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251402
|
6.1 |
MEDIUM
Network
|
soflyy
|
wp_all_import
|
Cross-site scripting vulnerability in WP All Import plugin prior to version 3.4.6 for WordPress allows an attacker to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0546
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251403
|
7.8 |
HIGH
Local
|
woodybells
|
winshot
|
Untrusted search path vulnerability in WinShot 1.53a and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0544
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251404
|
7.8 |
HIGH
Local
|
woodybells
|
jtrim
|
Untrusted search path vulnerability in Jtrim 1.53c and earlier (Installer) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0543
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251405
|
5.3 |
MEDIUM
Network
|
jubat
|
jubatus
|
Directory traversal vulnerability in Jubatus 1.0.2 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-0525
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251406
|
7.3 |
HIGH
Network
|
jubat
|
jubatus
|
Jubatus 1.0.2 and earlier allows remote code execution via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0524
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251407
|
8.8 |
HIGH
Adjacent
|
buffalo
|
wxr-1900dhp2_firmware
|
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors.
|
CWE-78
OS Command
|
CVE-2018-0523
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251408
|
7.8 |
HIGH
Local
|
buffalo
|
wxr-1900dhp2_firmware
|
Buffer overflow in Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to execute arbitrary code via a specially crafted file.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0522
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251409
|
8.8 |
HIGH
Adjacent
|
buffalo
|
wxr-1900dhp2_firmware
|
Buffalo WXR-1900DHP2 firmware Ver.2.48 and earlier allows an attacker to bypass authentication and execute arbitrary commands on the device via unspecified vectors.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2018-0521
|
2024-11-21 12:38 |
2018-03-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251410
|
7.5 |
HIGH
Network
|
torproject
|
tor
|
A use-after-free issue was discovered in Tor 0.3.2.x before 0.3.2.10. It allows remote attackers to cause a denial of service (relay crash) because the KIST implementation allows a channel to be adde…
|
CWE-416
Use After Free
|
CVE-2018-0491
|
2024-11-21 12:38 |
2018-03-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|