|
246681
|
9.1 |
CRITICAL
Network
|
ruckuswireless
|
vsz_firmware scg-200_firmware sz-300_firmware sz-100_firmware
|
Ruckus SmartZone (formerly Virtual SmartCell Gateway or vSCG) 3.5.0, 3.5.1, 3.6.0, and 3.6.1 (Essentials and High Scale) on vSZ, SZ-100, SZ-300, and SCG-200 devices allows remote attackers to obtain …
|
CWE-200
Information Exposure
|
CVE-2018-11036
|
2024-11-21 12:42 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246682
|
6.1 |
MEDIUM
Network
|
zimbra synacor
|
zimbra_collaboration_suite
|
Zimbra Web Client (ZWC) in Zimbra Collaboration Suite 8.8 before 8.8.8.Patch4 and 8.7 before 8.7.11.Patch4 has Persistent XSS via a contact group.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10939
|
2024-11-21 12:42 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246683
|
5.3 |
MEDIUM
Network
|
schedmd debian
|
slurm debian_linux
|
SchedMD Slurm before 17.02.11 and 17.1x.x before 17.11.7 mishandles user names (aka user_name fields) and group ids (aka gid fields).
|
CWE-20
Improper Input Validation
|
CVE-2018-10995
|
2024-11-21 12:42 |
2018-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246684
|
7.5 |
HIGH
Network
|
canonical git-scm
|
ubuntu_linux git
|
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11233
|
2024-11-21 12:42 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246685
|
7.8 |
HIGH
Local
|
debian canonical redhat git-scm gitforwindows
|
debian_linux ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux enterprise_linux_server enterprise_linux_server_eus git
|
In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, remote code execution can occur. With a crafted .gitmodules file, a malicious project…
|
CWE-22
Path Traversal
|
CVE-2018-11235
|
2024-11-21 12:42 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246686
|
6.1 |
MEDIUM
Network
|
ruckussecurity
|
icx7450-48_firmware
|
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11027
|
2024-11-21 12:42 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246687
|
8.1 |
HIGH
Network
|
divido
|
divido
|
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
|
CWE-89
SQL Injection
|
CVE-2018-11231
|
2024-11-21 12:42 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246688
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor_5-link
|
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11093
|
2024-11-21 12:42 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246689
|
6.5 |
MEDIUM
Network
|
horse_market_sell_\&_rent_portal_project
|
horse_market_sell_\&_rent_portal
|
Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information remotely.
|
CWE-352
Origin Validation Error
|
CVE-2018-11096
|
2024-11-21 12:42 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246690
|
6.5 |
MEDIUM
Network
|
admin_notes_project
|
admin_notes
|
An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.
|
CWE-352
Origin Validation Error
|
CVE-2018-11092
|
2024-11-21 12:42 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|