|
246801
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
Netwide Assembler (NASM) 2.14rc0 has an endless while loop in the assemble_file function of asm/nasm.c because of a globallineno integer overflow.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10316
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246802
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
WUZHI CMS 4.1.0 allows persistent XSS via the form%5Bqq_10%5D parameter to the /index.php?m=member&f=index&v=profile&set_iframe=1 URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10313
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246803
|
8.8 |
HIGH
Network
|
wuzhicms
|
wuzhi_cms
|
index.php?m=member&v=pw_reset in WUZHI CMS 4.1.0 allows CSRF to change the password of a common member.
|
CWE-352
Origin Validation Error
|
CVE-2018-10312
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246804
|
6.1 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
A vulnerability was discovered in WUZHI CMS 4.1.0. There is persistent XSS that allows remote attackers to inject arbitrary web script or HTML via the tag[pinyin] parameter to the /index.php?m=tags&f…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10311
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246805
|
5.4 |
MEDIUM
Network
|
responsive_cookie_consent_project
|
responsive_cookie_consent
|
The Responsive Cookie Consent plugin before 1.8 for WordPress mishandles number fields, leading to XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10309
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246806
|
9.8 |
CRITICAL
Network
|
simplemachines
|
simple_machines_forum
|
The MessageSearch2 function in PersonalMessage.php in Simple Machines Forum (SMF) before 2.0.15 does not properly use the possible_users variable in a query, which might allow attackers to bypass int…
|
NVD-CWE-noinfo
|
CVE-2018-10305
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246807
|
8.8 |
HIGH
Network
|
foxitsoftware
|
phantompdf foxit_reader
|
A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code, aka iDefense ID V-y0nqfutlf3.
|
CWE-416
Use After Free
|
CVE-2018-10303
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246808
|
7.8 |
HIGH
Local
|
foxitsoftware
|
phantompdf foxit_reader
|
A use-after-free in Foxit Reader before 9.1 and PhantomPDF before 9.1 allows remote attackers to execute arbitrary code, aka iDefense ID V-jyb51g3mv9.
|
CWE-416
Use After Free
|
CVE-2018-10302
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246809
|
6.1 |
MEDIUM
Network
|
web-dorado
|
wd_instagram_feed
|
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 Premium for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloa…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10301
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246810
|
6.1 |
MEDIUM
Network
|
web-dorado
|
wd_instagram_feed
|
Cross-site scripting (XSS) vulnerability in the Web-Dorado Instagram Feed WD plugin before 1.3.1 for WordPress allows remote attackers to inject arbitrary web script or HTML by passing payloads in an…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10300
|
2024-11-21 12:41 |
2018-04-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|