|
247201
|
7.8 |
HIGH
Local
|
convert_forms_project
|
convert_forms
|
The Convert Forms extension before 2.0.4 for Joomla! is vulnerable to Remote Command Execution using CSV Injection that is mishandled when exporting a Leads file.
|
NVD-CWE-noinfo
|
CVE-2018-10063
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247202
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
The hi3660_stub_clk_probe function in drivers/clk/hisilicon/clk-hi3660-stub.c in the Linux kernel before 4.16 allows local users to cause a denial of service (NULL pointer dereference) by triggering …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10074
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247203
|
4.8 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 has XSS in manager/admin_vod.php via the keyword parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10073
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247204
|
5.5 |
MEDIUM
Local
|
jungo
|
windriver
|
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953827bf DeviceIoControl call.
|
CWE-20
Improper Input Validation
|
CVE-2018-10072
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247205
|
5.5 |
MEDIUM
Local
|
jungo
|
windriver
|
windrvr1260.sys in Jungo DriverWizard WinDriver 12.6.0 allows attackers to cause a denial of service (BSOD) via a 0x953826DB DeviceIoControl call.
|
CWE-20
Improper Input Validation
|
CVE-2018-10071
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247206
|
6.1 |
MEDIUM
Network
|
jdownloads
|
jdownloads
|
The jDownloads extension before 3.2.59 for Joomla! has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10068
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247207
|
5.4 |
MEDIUM
Network
|
cacti debian
|
cacti debian_linux
|
Cacti before 1.1.37 has XSS because it makes certain htmlspecialchars calls without the ENT_QUOTES flag (these calls occur when the html_escape function in lib/html.php is not used).
|
CWE-79
Cross-site Scripting
|
CVE-2018-10061
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247208
|
5.4 |
MEDIUM
Network
|
cacti debian
|
cacti debian_linux
|
Cacti before 1.1.37 has XSS because it does not properly reject unintended characters, related to use of the sanitize_uri function in lib/functions.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10060
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247209
|
5.4 |
MEDIUM
Network
|
cacti
|
cacti
|
Cacti before 1.1.37 has XSS because the get_current_page function in lib/functions.php relies on $_SERVER['PHP_SELF'] instead of $_SERVER['SCRIPT_NAME'] to determine a page name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10059
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247210
|
9.8 |
CRITICAL
Network
|
ipvanish
|
ipvanish
|
IPVanish 3.0.11 for macOS suffers from a root privilege escalation vulnerability. The `com.ipvanish.osx.vpnhelper` LaunchDaemon implements an insecure XPC service that could allow an attacker to exec…
|
NVD-CWE-noinfo
|
CVE-2018-10192
|
2024-11-21 12:40 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|