|
255301
|
7.5 |
HIGH
Network
|
nmap
|
nmap
|
nse_libssh2.cc in Nmap 7.70 is subject to a denial of service condition due to a double free when an SSH connection fails, as demonstrated by a leading \n character to ssh-brute.nse or ssh-auth-metho…
|
CWE-415
Double Free
|
CVE-2017-18594
|
2024-11-21 12:20 |
2019-08-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255302
|
6.1 |
MEDIUM
Network
|
updraftplus
|
updraftplus
|
The updraftplus plugin before 1.13.5 for WordPress has XSS in rare cases where an attacker controls a string logged to a log file.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18593
|
2024-11-21 12:20 |
2019-08-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255303
|
7.5 |
HIGH
Network
|
wc-marketplace
|
wc_catalog_enquiry
|
The woocommerce-catalog-enquiry plugin before 3.1.0 for WordPress has an incorrect wp_upload directory for file uploads.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2017-18592
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255304
|
6.1 |
MEDIUM
Network
|
gdragon
|
gd_rating_system
|
The gd-rating-system plugin before 2.1 for WordPress has XSS in log.php.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18591
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255305
|
6.1 |
MEDIUM
Network
|
bestwebsoft
|
timesheet
|
The timesheet plugin before 0.1.5 for WordPress has multiple XSS issues.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18590
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255306
|
7.5 |
HIGH
Network
|
cookie_project
|
cookie
|
An issue was discovered in the cookie crate before 0.7.6 for Rust. Large integers in the Max-Age of a cookie cause a panic.
|
CWE-20
Improper Input Validation
|
CVE-2017-18589
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255307
|
5.3 |
MEDIUM
Network
|
security-framework_project
|
security-framework
|
An issue was discovered in the security-framework crate before 0.1.12 for Rust. Hostname verification for certificates does not occur if ClientBuilder uses custom root certificates.
|
CWE-295
Improper Certificate Validation
|
CVE-2017-18588
|
2024-11-21 12:20 |
2019-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255308
|
5.3 |
MEDIUM
Network
|
hyper
|
hyper
|
An issue was discovered in the hyper crate before 0.9.18 for Rust. It mishandles newlines in headers.
|
CWE-93
CRLF Injection
|
CVE-2017-18587
|
2024-11-21 12:20 |
2019-08-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255309
|
8.1 |
HIGH
Network
|
ivycat
|
posts_in_page
|
The posts-in-page plugin before 1.3.0 for WordPress has ic_add_posts template='../ directory traversal.
|
CWE-22
Path Traversal
|
CVE-2017-18585
|
2024-11-21 12:20 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255310
|
6.1 |
MEDIUM
Network
|
dwbooster
|
corner_ad
|
The corner-ad plugin before 1.0.8 for WordPress has XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2017-18579
|
2024-11-21 12:20 |
2019-08-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|