|
247671
|
4.8 |
MEDIUM
Network
|
dilicms
|
dilicms
|
An issue was discovered in DiliCMS (aka DiligentCMS) 2.4.0. There is a Stored XSS Vulnerability in the fourth textbox of "System setting->site setting" of admin/index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10430
|
2024-11-21 12:41 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247672
|
9.8 |
CRITICAL
Network
|
cosmocms
|
cosmo
|
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php.
|
CWE-94
Code Injection
|
CVE-2018-10429
|
2024-11-21 12:41 |
2018-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247673
|
7.8 |
HIGH
Local
|
hz-soft
|
security_guard
|
An issue was discovered in Shanghai 2345 Security Guard 3.7.0. 2345MPCSafe.exe, 2345SafeTray.exe, and 2345Speedup.exe allow local users to bypass intended process protections, and consequently termin…
|
NVD-CWE-noinfo
|
CVE-2018-10425
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247674
|
2.7 |
LOW
Network
|
1234n
|
minicms
|
mc-admin/post-edit.php in MiniCMS 1.10 allows full path disclosure via a modified id field.
|
CWE-200
Information Exposure
|
CVE-2018-10424
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247675
|
2.7 |
LOW
Network
|
1234n
|
minicms
|
mc-admin/post.php in MiniCMS 1.10 allows remote attackers to obtain a directory listing of the top-level directory of the web root via a link that becomes available after posting an article.
|
CWE-200
Information Exposure
|
CVE-2018-10423
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247676
|
4.8 |
MEDIUM
Network
|
hongcms_project
|
hongcms
|
An issue was discovered in HongCMS 3.0.0. The post news feature has Stored XSS via the content field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10422
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247677
|
7.5 |
HIGH
Network
|
xiph.org debian redhat
|
libvorbis debian_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
bark_noise_hybridmp in psy.c in Xiph.Org libvorbis 1.3.6 has a stack-based buffer over-read.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-10393
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247678
|
8.8 |
HIGH
Network
|
xiph.org debian redhat
|
libvorbis debian_linux enterprise_linux enterprise_linux_eus enterprise_linux_server_tus enterprise_linux_server_aus
|
mapping0_forward in mapping0.c in Xiph.Org libvorbis 1.3.6 does not validate the number of channels, which allows remote attackers to cause a denial of service (heap-based buffer overflow or over-rea…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2018-10392
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247679
|
4.8 |
MEDIUM
Network
|
wuzhicms
|
wuzhi_cms
|
An issue was discovered in WUZHI CMS 4.1.0. There is XSS via the email parameter to the index.php?m=member&v=register URI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10391
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247680
|
9.8 |
CRITICAL
Network
|
mcafee
|
tunnelbear
|
TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbit…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-10381
|
2024-11-21 12:41 |
2018-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|