|
247211
|
7.8 |
HIGH
Local
|
londontrustmedia
|
private_internet_access
|
A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges. The vul…
|
CWE-269
Improper Privilege Management
|
CVE-2018-10190
|
2024-11-21 12:40 |
2018-04-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247212
|
9.8 |
CRITICAL
Network
|
nordvpn
|
nordvpn
|
NordVPN 6.12.7.0 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "nordvpn-service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary in…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10170
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247213
|
9.8 |
CRITICAL
Network
|
protonmail
|
protonvpn
|
ProtonVPN 1.3.3 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "ProtonVPN Service" service. This service establishes an NetNamedPipe endpoint that allows arbitrary i…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10169
|
2024-11-21 12:40 |
2018-04-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247214
|
7.8 |
HIGH
Local
|
debian libreoffice redhat canonical
|
debian_linux libreoffice enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ubuntu_linux
|
The SwCTBWrapper::Read function in sw/source/filter/ww8/ww8toolbar.cxx in LibreOffice before 5.4.6.1 and 6.x before 6.0.2.1 does not validate a customizations index, which allows remote attackers to …
|
CWE-787 CWE-129
Out-of-bounds Write Improper Validation of Array Index
|
CVE-2018-10120
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247215
|
7.8 |
HIGH
Local
|
libreoffice debian redhat canonical
|
libreoffice debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ubuntu_linux
|
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of s…
|
CWE-416
Use After Free
|
CVE-2018-10119
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247216
|
8.8 |
HIGH
Network
|
h2database cognitect
|
h2 datomic
|
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designe…
|
CWE-20
Improper Input Validation
|
CVE-2018-10054
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247217
|
4.8 |
MEDIUM
Network
|
iscripts
|
supportdesk
|
iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10052
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247218
|
5.4 |
MEDIUM
Network
|
iscripts
|
supportdesk
|
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10051
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247219
|
7.2 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
|
CWE-89
SQL Injection
|
CVE-2018-10050
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247220
|
4.8 |
MEDIUM
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10049
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|