|
248841
|
9.8 |
CRITICAL
Network
|
jenkins redhat
|
jenkins openshift_container_platform
|
A code execution vulnerability exists in the Stapler web framework used by Jenkins 2.153 and earlier, LTS 2.138.3 and earlier in stapler/core/src/main/java/org/kohsuke/stapler/MetaClass.java that all…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-1000861
|
2024-11-21 12:40 |
2018-12-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248842
|
8.8 |
HIGH
Network
|
kubernetes
|
minikube
|
In Minikube versions 0.3.0-0.29.0, minikube exposes the Kubernetes Dashboard listening on the VM IP at port 30000. In VM environments where the IP is easy to predict, the attacker can use DNS rebindi…
|
CWE-352
Origin Validation Error
|
CVE-2018-1002103
|
2024-11-21 12:40 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248843
|
9.8 |
CRITICAL
Network
|
kubernetes
|
kubernetes
|
In Kubernetes versions 1.9.0-1.9.9, 1.10.0-1.10.5, and 1.11.0-1.11.1, user input was handled insecurely while setting up volume mounts on Windows nodes, which could lead to command line argument inje…
|
NVD-CWE-noinfo
|
CVE-2018-1002101
|
2024-11-21 12:40 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248844
|
9.8 |
CRITICAL
Network
|
kubernetes redhat netapp
|
kubernetes openshift_container_platform trident
|
In all Kubernetes versions prior to v1.10.11, v1.11.5, and v1.12.3, incorrect handling of error responses to proxied upgrade requests in the kube-apiserver allowed specially crafted requests to estab…
|
CWE-388
7PK - Errors
|
CVE-2018-1002105
|
2024-11-21 12:40 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248845
|
4.8 |
MEDIUM
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in u…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1002009
|
2024-11-21 12:40 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248846
|
4.8 |
MEDIUM
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in l…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1002008
|
2024-11-21 12:40 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248847
|
4.8 |
MEDIUM
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit. There is an XSS vulnerability in i…
|
CWE-79
Cross-site Scripting
|
CVE-2018-1002007
|
2024-11-21 12:40 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248848
|
4.8 |
MEDIUM
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in integration-contact-form.html.php:14: via POST request variable classes
|
CWE-79
Cross-site Scripting
|
CVE-2018-1002006
|
2024-11-21 12:40 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248849
|
4.8 |
MEDIUM
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
These vulnerabilities require administrative privileges to exploit. There is an XSS vulnerability in bft_list.html.php:43: via the filter_signup_date parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-1002005
|
2024-11-21 12:40 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248850
|
4.8 |
MEDIUM
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
There is a reflected XSS vulnerability in WordPress Arigato Autoresponder and News letter v2.5.1.8 This vulnerability requires administrative privileges to exploit.
|
CWE-79
Cross-site Scripting
|
CVE-2018-1002004
|
2024-11-21 12:40 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|