|
246791
|
9.8 |
CRITICAL
Network
|
phpliteadmin
|
phpliteadmin
|
An issue was discovered in phpLiteAdmin 1.9.5 through 1.9.7.1. Due to loose comparison with '==' instead of '===' in classes/Authorization.php for the user-provided login password, it is possible to …
|
CWE-287
Improper Authentication
|
CVE-2018-10362
|
2024-11-21 12:41 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246792
|
7.8 |
HIGH
Local
|
kde
|
ktexteditor
|
An issue was discovered in KTextEditor 5.34.0 through 5.45.0. Insecure handling of temporary files in the KTextEditor's kauth_ktexteditor_helper service (as utilized in the Kate text editor) can allo…
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2018-10361
|
2024-11-21 12:41 |
2018-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246793
|
6.1 |
MEDIUM
Network
|
phpipam
|
phpipam
|
app/tools/mac-lookup/index.php in phpIPAM 1.3.1 has Reflected XSS on /tools/mac-lookup/ via the mac parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10329
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246794
|
7.4 |
HIGH
Adjacent
|
momentum
|
momentum_axel_720p_firmware
|
Momentum Axel 720P 5.1.8 devices have a hardcoded password of streaming for the appagent account, which allows remote attackers to view the RTSP video stream.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10328
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246795
|
5.5 |
MEDIUM
Local
|
linux canonical debian
|
linux_kernel ubuntu_linux debian_linux
|
The xfs_bmap_extents_to_btree function in fs/xfs/libxfs/xfs_bmap.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_bmapi_write NULL pointer dereference) via a …
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10323
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246796
|
5.5 |
MEDIUM
Local
|
linux redhat
|
linux_kernel enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server virtualization_host
|
The xfs_dinode_verify function in fs/xfs/libxfs/xfs_inode_buf.c in the Linux kernel through 4.16.3 allows local users to cause a denial of service (xfs_ilock_attr_map_shared invalid pointer dereferen…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-10322
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246797
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has a stored Cross Site Scripting Vulnerability via "Admin Site title" in Settings.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10321
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246798
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS via the admin/?/layout/edit layout[name] parameter, aka Edit Layout.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10320
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246799
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS via the admin/?/snippet/edit snippet[name] parameter, aka Edit Snippet.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10319
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246800
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS via the admin/?/page/edit page[keywords] parameter, aka Edit Page Metadata.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10318
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|