|
248591
|
7.8 |
HIGH
Local
|
ponsoftware
|
explzh
|
Directory traversal vulnerability in Explzh v.7.58 and earlier allows an attacker to read arbitrary files via unspecified vectors.
|
CWE-22
Path Traversal
|
CVE-2018-0646
|
2024-11-21 12:38 |
2018-09-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248592
|
6.1 |
MEDIUM
Network
|
qnap
|
photo_station
|
Cross-site scripting vulnerability in QNAP Photo Station versions 5.7.0 and earlier could allow remote attackers to inject Javascript code in the compromised application.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0715
|
2024-11-21 12:38 |
2018-08-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248593
|
5.9 |
MEDIUM
Network
|
canonical debian
|
ubuntu_linux advanced_package_tool
|
The mirror:// method implementation in Advanced Package Tool (APT) 1.6.x before 1.6.4 and 1.7.x before 1.7.0~alpha3 mishandles gpg signature verification for the InRelease file of a fallback mirror, …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-0501
|
2024-11-21 12:38 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248594
|
6.7 |
MEDIUM
Local
|
cisco
|
web_security_appliance
|
A vulnerability in the account management subsystem of Cisco Web Security Appliance (WSA) could allow an authenticated, local attacker to elevate privileges to root. The attacker must authenticate wi…
|
CWE-269
Improper Privilege Management
|
CVE-2018-0428
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248595
|
8.8 |
HIGH
Network
|
cisco
|
application_policy_infrastructure_controller_enterprise_module
|
A vulnerability in the CronJob scheduler API of Cisco Digital Network Architecture (DNA) Center could allow an authenticated, remote attacker to perform a command injection attack. The vulnerability …
|
CWE-78
OS Command
|
CVE-2018-0427
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248596
|
7.5 |
HIGH
Network
|
cisco
|
email_security_appliance
|
A vulnerability in certain attachment detection mechanisms of Cisco Email Security Appliances (ESA) could allow an unauthenticated, remote attacker to bypass the filtering functionality of an affecte…
|
CWE-20
Improper Input Validation
|
CVE-2018-0419
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248597
|
8.6 |
HIGH
Network
|
cisco
|
ios_xr
|
A vulnerability in the Local Packet Transport Services (LPTS) feature set of Cisco ASR 9000 Series Aggregation Services Router Software could allow an unauthenticated, remote attacker to cause a deni…
|
CWE-20
Improper Input Validation
|
CVE-2018-0418
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248598
|
6.8 |
MEDIUM
Adjacent
|
cisco
|
wap121_firmware wap125_firmware wap131_firmware wap150_firmware wap321_firmware wap351_firmware wap361_firmware wap371_firmware
|
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Serie…
|
CWE-388
7PK - Errors
|
CVE-2018-0415
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248599
|
5.3 |
MEDIUM
Adjacent
|
cisco
|
wap121_firmware wap125_firmware wap131_firmware wap150_firmware wap321_firmware wap351_firmware wap361_firmware wap371_firmware
|
A vulnerability in the implementation of Extensible Authentication Protocol over LAN (EAPOL) functionality in Cisco Small Business 100 Series Wireless Access Points and Cisco Small Business 300 Serie…
|
NVD-CWE-noinfo
|
CVE-2018-0412
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248600
|
8.6 |
HIGH
Network
|
cisco
|
web_security_appliance
|
A vulnerability in the web proxy functionality of Cisco AsyncOS Software for Cisco Web Security Appliances could allow an unauthenticated, remote attacker to exhaust system memory and cause a denial …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-0410
|
2024-11-21 12:38 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|