|
249151
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_server_2012 windows_10 windows_8.1 windows_server_2016 windows_server_2008 windows_7 windows_rt_8.1 windows_server
|
The Windows kernel in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016…
|
CWE-665
Improper Initialization
|
CVE-2018-0811
|
2024-11-21 12:39 |
2018-03-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249152
|
9.1 |
CRITICAL
Network
|
mercurial debian
|
mercurial debian_linux
|
Mercurial version 4.5 and earlier contains a Incorrect Access Control (CWE-285) vulnerability in Protocol server that can result in Unauthorized data access. This attack appear to be exploitable via …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-1000132
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249153
|
9.8 |
CRITICAL
Network
|
wpsupportplus
|
wp_support_plus_responsive_ticket_system
|
Pradeep Makone wordpress Support Plus Responsive Ticket System version 9.0.2 and earlier contains a SQL Injection vulnerability in the function to get tickets, the parameter email in cookie was injec…
|
CWE-89
SQL Injection
|
CVE-2018-1000131
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249154
|
8.1 |
HIGH
Network
|
jolokia
|
webarchive_agent
|
A JNDI Injection vulnerability exists in Jolokia agent version 1.3.7 in the proxy mode that allows a remote attacker to run arbitrary Java code on the server.
|
CWE-74
Injection
|
CVE-2018-1000130
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249155
|
6.1 |
MEDIUM
Network
|
jolokia
|
jolokia
|
An XSS vulnerability exists in the Jolokia agent version 1.3.7 in the HTTP servlet that allows an attacker to execute malicious javascript in the victim's browser.
|
CWE-79
Cross-site Scripting
|
CVE-2018-1000129
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249156
|
7.5 |
HIGH
Network
|
memcached debian canonical redhat
|
memcached debian_linux ubuntu_linux openstack
|
memcached version prior to 1.4.37 contains an Integer Overflow vulnerability in items.c:item_free() that can result in data corruption and deadlocks due to items existing in hash table being reused f…
|
CWE-190 CWE-667
Integer Overflow or Wraparound Improper Locking
|
CVE-2018-1000127
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249157
|
7.5 |
HIGH
Network
|
ajenti
|
ajenti
|
Ajenti version 2 contains an Information Disclosure vulnerability in Line 176 of the code source that can result in user and system enumeration as well as data from the /etc/ajenti/config.yml file. T…
|
CWE-200
Information Exposure
|
CVE-2018-1000126
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249158
|
10.0 |
CRITICAL
Network
|
i-librarian
|
i\ _librarian
|
I Librarian I-librarian version 4.8 and earlier contains a XML External Entity (XXE) vulnerability in line 154 of importmetadata.php(simplexml_load_string) that can result in an attacker reading the …
|
CWE-611 CWE-918
XXE Server-Side Request Forgery (SSRF)
|
CVE-2018-1000124
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249159
|
9.8 |
CRITICAL
Network
|
ionicframework
|
ios_keychain
|
Ionic Team Cordova plugin iOS Keychain version before commit 18233ca25dfa92cca018b9c0935f43f78fd77fbf contains an Information Exposure Through Log Files (CWE-532) vulnerability in CDVKeychain.m that …
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-1000123
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249160
|
9.8 |
CRITICAL
Network
|
inversoft
|
prime-jwt
|
inversoft prime-jwt version prior to version 1.3.0 or prior to commit 0d94dcef0133d699f21d217e922564adbb83a227 contains an input validation vulnerability in JWTDecoder.decode that can result in a JWT…
|
CWE-20
Improper Input Validation
|
CVE-2018-1000125
|
2024-11-21 12:39 |
2018-03-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|