|
248671
|
7.4 |
HIGH
Network
|
ana
|
ana
|
The ANA App for iOS version 4.0.22 and earlier does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a cr…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-0611
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248672
|
7.2 |
HIGH
Network
|
zenphoto
|
zenphoto
|
Local file inclusion vulnerability in Zenphoto 1.4.14 and earlier allows a remote attacker with an administrative privilege to execute arbitrary code or obtain sensitive information.
|
CWE-269
Improper Privilege Management
|
CVE-2018-0610
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248673
|
7.8 |
HIGH
Local
|
linecorp
|
line
|
Untrusted search path vulnerability in LINE for Windows versions before 5.8.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0609
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248674
|
9.8 |
CRITICAL
Network
|
dena
|
h2o
|
Buffer overflow in H2O version 2.2.4 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (DoS) via unspecified vectors.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-0608
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248675
|
7.2 |
HIGH
Network
|
pixelpost
|
pixelpost
|
SQL injection vulnerability in the Pixelpost v1.7.3 and earlier allows remote authenticated attackers to execute arbitrary SQL commands via unspecified vectors.
|
CWE-89
SQL Injection
|
CVE-2018-0606
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248676
|
6.1 |
MEDIUM
Network
|
pixelpost
|
pixelpost
|
Cross-site scripting vulnerability in Pixelpost v1.7.3 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0605
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248677
|
7.2 |
HIGH
Network
|
pixelpost
|
pixelpost
|
Pixelpost v1.7.3 and earlier allows remote code execution via unspecified vectors.
|
NVD-CWE-noinfo
|
CVE-2018-0604
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248678
|
6.1 |
MEDIUM
Network
|
geminilabs
|
site_reviews
|
Cross-site scripting vulnerability in Site Reviews versions prior to 2.15.3 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0603
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248679
|
6.1 |
MEDIUM
Network
|
email_subscribers_\&_newsletters_project
|
email_subscribers_\&_newsletters
|
Cross-site scripting vulnerability in Email Subscribers & Newsletters versions prior to 3.5.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
|
CWE-79
Cross-site Scripting
|
CVE-2018-0602
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248680
|
7.8 |
HIGH
Local
|
axpdfium_project
|
axpdfium
|
Untrusted search path vulnerability in axpdfium v0.01 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
|
CWE-426
Untrusted Search Path
|
CVE-2018-0601
|
2024-11-21 12:38 |
2018-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|