|
246741
|
6.1 |
MEDIUM
Network
|
mybiz
|
myprocurenet
|
An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser …
|
CWE-79
Cross-site Scripting
|
CVE-2018-11090
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246742
|
6.1 |
MEDIUM
Network
|
signal
|
signal-desktop
|
js/views/message_view.js in Open Whisper Signal (aka Signal-Desktop) before 1.10.1 allows XSS via a URL.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10994
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246743
|
9.9 |
CRITICAL
Network
|
mybiz
|
myprocurenet
|
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system comm…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-11091
|
2024-11-21 12:42 |
2018-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246744
|
6.6 |
MEDIUM
Network
|
commscope
|
arris_tg1682g_firmware
|
Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices are distributed by some ISPs with a default password of "password" for the admin account that is used over an unencrypted http://192.168.0…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-10989
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246745
|
8.0 |
HIGH
Network
|
commscope
|
arris_tg1682g_firmware
|
On Arris Touchstone Telephony Gateway TG1682G 9.1.103J6 devices, a logout action does not immediately destroy all state on the device related to the validity of the "credential" cookie, which might m…
|
CWE-613
Insufficient Session Expiration
|
CVE-2018-10990
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246746
|
6.5 |
MEDIUM
Network
|
exiv2
|
exiv2
|
In Exiv2 0.26, the Exiv2::PngImage::printStructure function in pngimage.cpp allows remote attackers to cause an information leak via a crafted file.
|
CWE-200
Information Exposure
|
CVE-2018-11037
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246747
|
7.8 |
HIGH
Local
|
2345.cc
|
security_guard
|
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating…
|
CWE-20
Improper Input Validation
|
CVE-2018-11035
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246748
|
7.8 |
HIGH
Local
|
2345.cc
|
security_guard
|
In 2345 Security Guard 3.7, the driver file (2345NsProtect.sys, X64 version) allows local users to cause a denial of service (BSOD) or possibly have unspecified other impact because of not validating…
|
CWE-20
Improper Input Validation
|
CVE-2018-11034
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246749
|
5.9 |
MEDIUM
Network
|
rasputinonline
|
rasputin_online_coin
|
The request_dividend function of a smart contract implementation for ROC (aka Rasputin Online Coin), an Ethereum ERC20 token, allows attackers to steal all of the contract's Ether.
|
NVD-CWE-noinfo
|
CVE-2018-10944
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246750
|
7.8 |
HIGH
Local
|
xpdfreader
|
xpdf
|
The DCTStream::readHuffSym function in Stream.cc in the DCT decoder in xpdf before 4.00 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other imp…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-11033
|
2024-11-21 12:42 |
2018-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|