|
247511
|
5.4 |
MEDIUM
Network
|
octopus
|
octopus_deploy
|
In Octopus Deploy 3.4.x before 2018.4.7, an authenticated user is able to view/update/save variable values within the Tenant Variables area for Environments that do not exist within their associated …
|
CWE-200
Information Exposure
|
CVE-2018-10581
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247512
|
6.1 |
MEDIUM
Network
|
wunderfarm
|
wf_cookie_consent
|
An issue was discovered in the wunderfarm WF Cookie Consent plugin 1.1.3 for WordPress. A persistent cross-site scripting vulnerability has been identified in the web interface of the plugin that all…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10371
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247513
|
7.8 |
HIGH
Local
|
watchguard
|
ap200_firmware ap102_firmware ap100_firmware
|
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Improper authentication handling by the native Access Point web UI allows authentication using a l…
|
CWE-287
Improper Authentication
|
CVE-2018-10576
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247514
|
9.8 |
CRITICAL
Network
|
watchguard
|
ap200_firmware ap102_firmware ap100_firmware
|
An issue was discovered on WatchGuard AP100, AP102, and AP200 devices with firmware before 1.2.9.15. Hardcoded credentials exist for an unprivileged SSH account with a shell of /bin/false.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10575
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247515
|
5.4 |
MEDIUM
Network
|
bigtreecms
|
bigtree_cms
|
BigTree before 4.2.22 has XSS in the Users management page via the name or company field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10364
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247516
|
9.8 |
CRITICAL
Network
|
bigtreecms
|
bigtree_cms
|
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php do…
|
CWE-94
Code Injection
|
CVE-2018-10574
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247517
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
interface/fax/fax_dispatch.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the scan parameter.
|
NVD-CWE-noinfo
|
CVE-2018-10573
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247518
|
6.5 |
MEDIUM
Network
|
open-emr
|
openemr
|
interface/patient_file/letter.php in OpenEMR before 5.0.1 allows remote authenticated users to bypass intended access restrictions via the newtemplatename and form_body parameters.
|
NVD-CWE-noinfo
|
CVE-2018-10572
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247519
|
4.8 |
MEDIUM
Network
|
frogcms_project
|
frogcms
|
Frog CMS 0.9.5 has XSS in /install/index.php via the ['config']['admin_username'] field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10570
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247520
|
6.1 |
MEDIUM
Network
|
open-emr
|
openemr
|
Multiple reflected cross-site scripting (XSS) vulnerabilities in OpenEMR before 5.0.1 allow remote attackers to inject arbitrary web script or HTML via the (1) patient parameter to interface/main/fin…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10571
|
2024-11-21 12:41 |
2018-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|