|
246841
|
6.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
An issue was discovered in YzmCMS 3.8. There is a CSRF vulnerability that can add an admin account via /index.php/admin/admin_manage/add.html.
|
CWE-352
Origin Validation Error
|
CVE-2018-10223
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246842
|
8.8 |
HIGH
Network
|
icmsdev
|
icms
|
An issue was discovered in idreamsoft iCMS V7.0. There is a CSRF vulnerability that can add a Column via /admincp.php?app=article_category&do=save&frame=iPHP.
|
CWE-352
Origin Validation Error
|
CVE-2018-10222
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246843
|
5.4 |
MEDIUM
Network
|
wuzhicms
|
wuzhicms
|
An issue was discovered in WUZHI CMS V4.1.0. There is a persistent XSS vulnerability that can steal the administrator cookies via the tag[tag] parameter to the index.php?m=tags&f=index&v=add&&_su=wuz…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10221
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246844
|
8.8 |
HIGH
Network
|
mushmush
|
glastopf
|
Glastopf 3.1.3-dev has SSRF, as demonstrated by the abc.php a parameter. NOTE: the vendor indicates that this is intentional behavior because the product is a web application honeypot, and modules/ha…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-10220
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246845
|
5.3 |
MEDIUM
Network
|
baijiacms_project
|
baijiacms
|
baijiacms V3 has physical path leakage via an index.php?mod=mobile&name=member&do=index request.
|
CWE-200
Information Exposure
|
CVE-2018-10219
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246846
|
5.3 |
MEDIUM
Network
|
hyper
|
hyperstart
|
hyperstart 1.0.0 in HyperHQ Hyper has memory leaks in the container_setup_modules and hyper_rescan_scsi functions in container.c, related to runV 1.0.0 for Docker.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-10205
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246847
|
9.8 |
CRITICAL
Network
|
mruby
|
mruby
|
In versions of mruby up to and including 1.4.0, a use-after-free vulnerability exists in src/io.c::File#initilialize_copy(). An attacker that can cause Ruby code to be run can possibly use this to ex…
|
CWE-416
Use After Free
|
CVE-2018-10199
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246848
|
8.8 |
HIGH
Network
|
purevpn
|
purevpn
|
PureVPN 6.0.1 for Windows suffers from a SYSTEM privilege escalation vulnerability in its "sevpnclient" service. When configured to use the OpenVPN protocol, the "sevpnclient" service executes "openv…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10204
|
2024-11-21 12:41 |
2018-04-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246849
|
7.1 |
HIGH
Local
|
lrzsz_project suse debian
|
lrzsz linux_enterprise_server linux_enterprise_debuginfo linux_enterprise_desktop debian_linux
|
lrzsz before version 0.12.21~rc can leak information to the receiving side due to an incorrect length check in the function zsdata that causes a size_t to wrap around.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10195
|
2024-11-21 12:40 |
2021-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246850
|
7.5 |
HIGH
Network
|
bitcoinsv
|
bitcoin_sv
|
Bitcoin SV before 0.1.1 allows uncontrolled resource consumption when deserializing transactions.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-1000893
|
2024-11-21 12:40 |
2020-12-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|