|
246941
|
9.8 |
CRITICAL
Network
|
zoneminder
|
zoneminder
|
ZoneMinder version <= 1.32.2 contains a Other/Unknown vulnerability in User-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000832
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246942
|
10.0 |
CRITICAL
Network
|
k9mail
|
k-9_mail
|
K9Mail version <= v5.600 contains a XML External Entity (XXE) vulnerability in WebDAV response parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This …
|
CWE-611
XXE
|
CVE-2018-1000831
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246943
|
10.0 |
CRITICAL
Network
|
xr3player_project
|
xr3player
|
XR3Player version <= V3.124 contains a XML External Entity (XXE) vulnerability in Playlist parser that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
|
CWE-611
XXE
|
CVE-2018-1000830
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246944
|
9.0 |
CRITICAL
Network
|
anyplace_project
|
anyplace
|
Anyplace version before commit 80359b4 contains a XML External Entity (XXE) vulnerability in Man in the middle on map API call that can result in Disclosure of confidential data, denial of service, S…
|
CWE-611
XXE
|
CVE-2018-1000829
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246945
|
9.0 |
CRITICAL
Network
|
frostwire
|
frostwire
|
FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of …
|
CWE-611
XXE
|
CVE-2018-1000828
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246946
|
9.8 |
CRITICAL
Network
|
ubilling
|
ubilling
|
Ubilling version <= 0.9.2 contains a Other/Unknown vulnerability in user-controlled parameter that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000827
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246947
|
6.1 |
MEDIUM
Network
|
microweber
|
microweber
|
Microweber version <= 1.0.7 contains a Cross Site Scripting (XSS) vulnerability in Admin login form template that can result in Execution of JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000826
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246948
|
10.0 |
CRITICAL
Network
|
freecol
|
freecol
|
FreeCol version <= nightly-2018-08-22 contains a XML External Entity (XXE) vulnerability in FreeColXMLReader parser that can result in Disclosure of confidential data, denial of service, SSRF, port s…
|
CWE-611
XXE
|
CVE-2018-1000825
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246949
|
9.8 |
CRITICAL
Network
|
megamek
|
megamek
|
MegaMek version < v0.45.1 contains a Other/Unknown vulnerability in Object Stream Connection that can result in Disclosure of confidential data, denial of service, SSRF, remote code execution.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000824
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246950
|
10.0 |
CRITICAL
Network
|
exist-db
|
exist
|
exist version <= 5.0.0-RC4 contains a XML External Entity (XXE) vulnerability in XML Parser for REST Server that can result in Disclosure of confidential data, denial of service, SSRF, port scanning.
|
CWE-611
XXE
|
CVE-2018-1000823
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|