|
247751
|
8.1 |
HIGH
Network
|
artica
|
integria_ims
|
Artica Integria IMS version 5.0 MR56 Package 58, likely earlier versions contains a CWE-640: Weak Password Recovery Mechanism for Forgotten Password vulnerability in Password recovery process, line 4…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-1000812
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247752
|
8.8 |
HIGH
Network
|
bludit
|
bludit
|
bludit version 3.0.0 contains a Unrestricted Upload of File with Dangerous Type vulnerability in Content Upload in Pages Editor that can result in Remote Command Execution. This attack appear to be e…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-1000811
|
2024-11-21 12:40 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247753
|
9.8 |
CRITICAL
Network
|
paloaltonetworks
|
expedition
|
The Palo Alto Networks Expedition Migration tool 1.0.107 and earlier may allow an unauthenticated attacker with remote access to run system level commands on the device hosting this service/applicati…
|
CWE-269
Improper Privilege Management
|
CVE-2018-10143
|
2024-11-21 12:40 |
2018-12-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247754
|
8.8 |
HIGH
Network
|
jenkins redhat
|
pipeline\ openshift_container_platform
|
A sandbox bypass vulnerability exists in Pipeline: Groovy Plugin 2.59 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java, groovy-cps/lib/src/main/java/com/…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000866
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247755
|
8.8 |
HIGH
Network
|
jenkins redhat
|
script_security openshift_container_platform
|
A sandbox bypass vulnerability exists in Script Security Plugin 1.47 and earlier in groovy-sandbox/src/main/java/org/kohsuke/groovy/sandbox/SandboxTransformer.java that allows attackers with Job/Conf…
|
CWE-269
Improper Privilege Management
|
CVE-2018-1000865
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247756
|
6.5 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift_container_platform
|
A denial of service vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in CronTab.java that allows attackers with Overall/Read permission to have a request handling thread ent…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-1000864
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247757
|
8.2 |
HIGH
Network
|
jenkins redhat
|
jenkins openshift_container_platform
|
A data modification vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in User.java, IdStrategy.java that allows attackers to submit crafted user names that can cause an impro…
|
CWE-22
Path Traversal
|
CVE-2018-1000863
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247758
|
4.3 |
MEDIUM
Network
|
jenkins redhat
|
jenkins openshift_container_platform
|
An information exposure vulnerability exists in Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in DirectoryBrowserSupport.java that allows attackers with the ability to control build output to br…
|
CWE-200
Information Exposure
|
CVE-2018-1000862
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247759
|
9.8 |
CRITICAL
Network
|
jenkins redhat
|
jenkins openshift_container_platform
|
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that all…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000861
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247760
|
8.8 |
HIGH
Network
|
kubernetes
|
minikube
|
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebindi…
|
CWE-352
Origin Validation Error
|
CVE-2018-1002103
|
2024-11-21 12:40 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|