|
246621
|
6.1 |
MEDIUM
Network
|
slims_akasia_project
|
slims_akasia
|
Reflected Cross-Site Scripting (XSS) exists in the Master File module in SLiMS 8 Akasia 8.3.1 via an admin/modules/master_file/rda_cmc.php?keywords= URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12657
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246622
|
6.1 |
MEDIUM
Network
|
slims_akasia_project
|
slims_akasia
|
Reflected Cross-Site Scripting (XSS) exists in the Membership module in SLiMS 8 Akasia 8.3.1 via an admin/modules/membership/index.php?keywords= URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12656
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246623
|
6.1 |
MEDIUM
Network
|
slims_akasia_project
|
slims_akasia
|
Reflected Cross-Site Scripting (XSS) exists in the Circulation module in SLiMS 8 Akasia 8.3.1 via an admin/modules/circulation/loan_rules.php?keywords= URI, a related issue to CVE-2017-7242.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12655
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246624
|
6.1 |
MEDIUM
Network
|
slims_akasia_project
|
slims_akasia
|
Reflected Cross-Site Scripting (XSS) exists in the Bibliography module in SLiMS 8 Akasia 8.3.1 via an admin/modules/bibliography/index.php?keywords= URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12654
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246625
|
9.8 |
CRITICAL
Network
|
misp
|
misp
|
An issue was discovered in app/Controller/UsersController.php in MISP 2.4.92. An adversary can bypass the brute-force protection by using a PUT HTTP method instead of a POST HTTP method in the login …
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2018-12649
|
2024-11-21 12:45 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246626
|
7.5 |
HIGH
Network
|
exempi_project
|
exempi
|
The WEBP::GetLE32 function in XMPFiles/source/FormatSupport/WEBP_Support.hpp in Exempi 2.4.5 has a NULL pointer dereference.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-12648
|
2024-11-21 12:45 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246627
|
7.5 |
HIGH
Network
|
froxlor
|
froxlor
|
Froxlor through 0.9.39.5 has Incorrect Access Control for tickets not owned by the current user.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12642
|
2024-11-21 12:45 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246628
|
5.5 |
MEDIUM
Local
|
gnu
|
binutils
|
An issue was discovered in arm_pt in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. Stack Exhaustion occurs in the C++ demangling functions provided by libiberty, and there are re…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-12641
|
2024-11-21 12:45 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246629
|
7.5 |
HIGH
Network
|
circontrol
|
scada
|
CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs.
|
CWE-20
Improper Input Validation
|
CVE-2018-12635
|
2024-11-21 12:45 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246630
|
9.8 |
CRITICAL
Network
|
circontrol
|
circarlife_scada
|
CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI.
|
CWE-200
Information Exposure
|
CVE-2018-12634
|
2024-11-21 12:45 |
2018-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|