|
247181
|
8.8 |
HIGH
Network
|
gegl
|
gegl
|
An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_swap_constructed function in buffer/gegl-tile-backend-swap.c allows remote attackers to cause a denial of service (write access v…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10112
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247182
|
7.5 |
HIGH
Network
|
gegl
|
gegl
|
An issue was discovered in GEGL through 0.3.32. The render_rectangle function in process/gegl-processor.c has unbounded memory allocation, leading to a denial of service (application crash) upon allo…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10111
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247183
|
4.8 |
MEDIUM
Network
|
monstra
|
monstra
|
Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has access to the editor role, and enters the payload in the content section of a new page in the blog catalog.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10109
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247184
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-815_firmware
|
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the Treturn parameter to /htdocs/webinc/js/bsc_sms_inbox.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10108
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247185
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-815_firmware
|
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10107
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247186
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-815_firmware
|
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.ph…
|
CWE-200
Information Exposure
|
CVE-2018-10106
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247187
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10102
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247188
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
|
CWE-601
Open Redirect
|
CVE-2018-10101
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247189
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
|
CWE-601
Open Redirect
|
CVE-2018-10100
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247190
|
6.1 |
MEDIUM
Network
|
smartscriptsolutions
|
domain_trader
|
XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10097
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|