|
248391
|
7.2 |
HIGH
Network
|
combodo
|
itop
|
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-…
|
CWE-94
Code Injection
|
CVE-2018-10642
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248392
|
9.8 |
CRITICAL
Network
|
meross
|
mss110_firmware
|
Meross MSS110 devices through 1.1.24 contain an unauthenticated admin.htm administrative interface.
|
CWE-287
Improper Authentication
|
CVE-2018-10544
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248393
|
8.8 |
HIGH
Network
|
hrsale_project
|
hrsale
|
A Local File Inclusion vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
|
CWE-20
Improper Input Validation
|
CVE-2018-10260
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248394
|
7.8 |
HIGH
Local
|
safervpn
|
safervpn
|
SaferVPN 4.2.5 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "SaferVPN.Service" service. The "SaferVPN.Service" service executes "openvpn.exe" using OpenVPN config files…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10647
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248395
|
7.8 |
HIGH
Local
|
cyberghostvpn
|
cyberghost
|
CyberGhost 6.5.0.3180 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "CG6Service" service. This service establishes a NetNamedPipe endpoint that allows arbitrary ins…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10646
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248396
|
7.8 |
HIGH
Local
|
goldenfrog
|
vyprvpn
|
Golden Frog VyprVPN 2.12.1.8015 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "VyprVPN" service. This service establishes a NetNamedPipe endpoint that allows applic…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10645
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248397
|
5.4 |
MEDIUM
Network
|
hrsale_project
|
hrsale
|
An Authenticated Stored XSS vulnerability was found in HRSALE The Ultimate HRM v1.0.2, exploitable by a low privileged user.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10259
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248398
|
8.8 |
HIGH
Network
|
codeslab
|
shopy_point_of_sale
|
A CSV Injection vulnerability was discovered in Shopy Point of Sale v1.0 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading to po…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-10258
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248399
|
8.8 |
HIGH
Local
|
hrsale_project
|
hrsale
|
A CSV Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to inject a command that will be included in the exported CSV file, leading…
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2018-10257
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248400
|
8.8 |
HIGH
Network
|
hrsale_project
|
hrsale
|
A SQL Injection vulnerability was discovered in HRSALE The Ultimate HRM v1.0.2 that allows a user with low level privileges to directly modify the SQL query.
|
CWE-89
SQL Injection
|
CVE-2018-10256
|
2024-11-21 12:41 |
2018-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|