|
247251
|
7.5 |
HIGH
Network
|
siemens
|
dnp3_tcp_firmware iec_61850_firmware iec104_firmware modbus_tcp_firmware profinet_io_firmware cp100_firmware cp200_firmware cp300_firmware
|
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware var…
|
CWE-20
Improper Input Validation
|
CVE-2018-11452
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247252
|
7.5 |
HIGH
Network
|
siemens
|
dnp3_tcp_firmware iec_61850_firmware iec104_firmware modbus_tcp_firmware profinet_io_firmware cp100_firmware cp200_firmware cp300_firmware
|
A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware var…
|
CWE-20
Improper Input Validation
|
CVE-2018-11451
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247253
|
9.8 |
CRITICAL
Network
|
apache
|
openwhisk
|
In Docker Skeleton Runtime for Apache OpenWhisk, a Docker action inheriting the Docker tag openwhisk/dockerskeleton:1.3.0 (or earlier) may allow an attacker to replace the user function inside the co…
|
NVD-CWE-noinfo
|
CVE-2018-11757
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247254
|
9.8 |
CRITICAL
Network
|
apache
|
openwhisk
|
In PHP Runtime for Apache OpenWhisk, a Docker action inheriting one of the Docker tags openwhisk/action-php-v7.2:1.0.0 or openwhisk/action-php-v7.1:1.0.1 (or earlier) may allow an attacker to replace…
|
NVD-CWE-noinfo
|
CVE-2018-11756
|
2024-11-21 12:43 |
2018-07-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247255
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
An issue was discovered in Zoho ManageEngine Desktop Central before 100230. There is unauthenticated remote access to all log files of a Desktop Central instance containing critical information (priv…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-11716
|
2024-11-21 12:43 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247256
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_desktop_central
|
An issue was discovered in Zoho ManageEngine Desktop Central before 100251. By leveraging access to a log file, a context-dependent attacker can obtain (depending on the modules configured) the Base6…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-11717
|
2024-11-21 12:43 |
2018-07-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247257
|
8.0 |
HIGH
Adjacent
|
debian videolan
|
debian_linux vlc_media_player
|
VideoLAN VLC media player 2.2.x is prone to a use after free vulnerability which an attacker can leverage to execute arbitrary code via crafted MKV files. Failed exploit attempts will likely result i…
|
CWE-416
Use After Free
|
CVE-2018-11529
|
2024-11-21 12:43 |
2018-07-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247258
|
6.1 |
MEDIUM
Network
|
siemens
|
teamcenter_product_lifecycle_management
|
A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the …
|
CWE-79
Cross-site Scripting
|
CVE-2018-11450
|
2024-11-21 12:43 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247259
|
7.5 |
HIGH
Network
|
ribboncommunications
|
sonus_sbc_1000_firmware sonus_sbc_2000_firmware sbc_swe_lite_firmware
|
A Local File Inclusion (LFI) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the downloading of arbitrary files via an unspecified vector. It affects the 1000 a…
|
CWE-22
Path Traversal
|
CVE-2018-11543
|
2024-11-21 12:43 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247260
|
9.8 |
CRITICAL
Network
|
ribboncommunications
|
sonus_sbc_1000_firmware sonus_sbc_2000_firmware sbc_swe_lite_firmware
|
A Remote Command Execution (RCE) vulnerability in the Sonus SBC 1000 / SBC 2000 / SBC SWe Lite web interface allows for the execution of arbitrary commands via an unspecified vector. It affects the 1…
|
NVD-CWE-noinfo
|
CVE-2018-11542
|
2024-11-21 12:43 |
2018-07-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|