|
248911
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_name parameter, related to moduledepends, a different vulnerability than CVE-2017-16799.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10029
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248912
|
5.3 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 allows remote attackers to obtain sensitive information via a direct request to the install/ or log/ URI.
|
CWE-200
Information Exposure
|
CVE-2018-10028
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248913
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
The WeChat module in YzmCMS 3.7.1 has reflected XSS via the admin/module/init.html echostr parameter, related to the valid function in application/wechat/controller/index.class.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10026
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248914
|
9.8 |
CRITICAL
Network
|
ubiquoss
|
vp5208a_firmware
|
ubiQuoss Switch VP5208A creates a bcm_password file at /cgi-bin/ with the user credentials in cleartext when a failed login attempt occurs. The file can be reached via an HTTP request. The credential…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-10024
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248915
|
5.4 |
MEDIUM
Network
|
catfish-cms
|
catfish_cms
|
Catfish CMS V4.7.21 allows XSS via the pinglun parameter to cat/index/index/pinglun (aka an authenticated comment).
|
CWE-79
Cross-site Scripting
|
CVE-2018-10023
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248916
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
drivers/scsi/libsas/sas_scsi_host.c in the Linux kernel before 4.16 allows local users to cause a denial of service (ata qc leak) by triggering certain failure conditions. NOTE: a third party dispute…
|
NVD-CWE-noinfo
|
CVE-2018-10021
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248917
|
6.5 |
MEDIUM
Network
|
openmpt
|
openmpt libopenmpt
|
soundlib/Snd_fx.cpp in OpenMPT before 1.27.07.00 and libopenmpt before 0.3.8 allows remote attackers to cause a denial of service (out-of-bounds read) via an IT or MO3 file with many nested pattern l…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10017
|
2024-11-21 12:40 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248918
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
Netwide Assembler (NASM) 2.14rc0 has a division-by-zero vulnerability in the expr5 function in asm/eval.c via a malformed input file.
|
CWE-369
Divide By Zero
|
CVE-2018-10016
|
2024-11-21 12:40 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248919
|
6.5 |
MEDIUM
Network
|
ffmpeg debian
|
ffmpeg debian_linux
|
The decode_init function in libavcodec/utvideodec.c in FFmpeg through 3.4.2 allows remote attackers to cause a denial of service (out of array read) via an AVI file.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10001
|
2024-11-21 12:40 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248920
|
6.1 |
MEDIUM
Network
|
videodownloaderultimate
|
video_downloader
|
The Video Downloader professional extension before 2018-04-05 for Chrome has Universal XSS (UXSS) via vectors related to a link64_msgAddLinks event.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10000
|
2024-11-21 12:40 |
2018-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|