|
247941
|
5.8 |
MEDIUM
Network
|
cisco
|
firepower_management_center
|
A vulnerability in the VPN configuration management of Cisco FireSIGHT System Software could allow an unauthenticated, remote attacker to bypass VPN security due to unintended side effects of dynamic…
|
CWE-693
Protection Mechanism Failure
|
CVE-2018-0333
|
2024-11-21 12:38 |
2018-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247942
|
7.5 |
HIGH
Network
|
cisco
|
web_security_appliance
|
A vulnerability in traffic-monitoring functions in Cisco Web Security Appliance (WSA) could allow an unauthenticated, remote attacker to circumvent Layer 4 Traffic Monitor (L4TM) functionality and by…
|
NVD-CWE-noinfo
|
CVE-2018-0353
|
2024-11-21 12:38 |
2018-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247943
|
5.9 |
MEDIUM
Network
|
t-joy
|
kinepass
|
The KINEPASS App for Android Ver 3.1.1 and earlier, and for iOS Ver 3.1.2 and earlier do not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and …
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0591
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247944
|
4.3 |
MEDIUM
Network
|
ultimatemember
|
user_profile_\&_membership
|
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to modify the other users profiles via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0590
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247945
|
4.3 |
MEDIUM
Network
|
ultimatemember
|
user_profile_\&_membership
|
Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to bypass access restriction to add a new form in the 'Forms' page via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0589
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247946
|
7.5 |
HIGH
Network
|
ultimatemember
|
user_profile_\&_membership
|
Directory traversal vulnerability in the AJAX function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-0588
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247947
|
4.3 |
MEDIUM
Network
|
ultimatemember
|
user_profile_\&_membership
|
Unrestricted file upload vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated users to upload arbitrary image files via unspecified vectors.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-0587
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247948
|
4.3 |
MEDIUM
Network
|
ultimatemember
|
user_profile_\&_membership
|
Directory traversal vulnerability in the shortcodes function of Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote authenticated attackers to read arbitrary files via unspecifi…
|
CWE-22
Path Traversal
|
CVE-2018-0586
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247949
|
5.4 |
MEDIUM
Network
|
ultimatemember
|
ultimate_member
|
Cross-site scripting vulnerability in Ultimate Member plugin prior to version 2.0.4 for WordPress allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0585
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247950
|
6.1 |
MEDIUM
Network
|
asus
|
rt-ac1200hp_firmware
|
Cross-site scripting vulnerability in ASUS RT-AC1200HP Firmware version prior to 3.0.0.4.380.4180 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0583
|
2024-11-21 12:38 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|