|
246611
|
7.5 |
HIGH
Network
|
ca
|
unified_infrastructure_management
|
A hardcoded passphrase, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-13820
|
2024-11-21 12:48 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246612
|
7.5 |
HIGH
Network
|
ca
|
unified_infrastructure_management
|
A hardcoded secret key, in CA Unified Infrastructure Management 8.5.1, 8.5, and 8.4.7, allows attackers to access sensitive information.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-13819
|
2024-11-21 12:48 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246613
|
8.8 |
HIGH
Network
|
foxitsoftware
|
foxit_reader
|
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Reader 9.1.0.5096. User interaction is required to exploit this vulnerability in that the tar…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-14317
|
2024-11-21 12:48 |
2018-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246614
|
5.4 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore allows XSS via Users, Assets, Data Objects, Video Thumbnails, Image Thumbnails, Field-Collections, Objectbrick, Classification Store, Document Types, Predefined Properties, Predefined Asset M…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14059
|
2024-11-21 12:48 |
2018-08-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246615
|
4.0 |
MEDIUM
Local
|
signal
|
signal-desktop
|
Open Whisper Signal (aka Signal-Desktop) before 1.15.0-beta.10 allows information leakage.
|
CWE-200
Information Exposure
|
CVE-2018-14023
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246616
|
5.3 |
MEDIUM
Network
|
paymorrow
|
paymorrow
|
An issue was discovered in the Paymorrow module 1.0.0 before 1.0.2 and 2.0.0 before 2.0.1 for OXID eShop. An attacker can bypass delivery-address change detection if the payment module doesn't use eS…
|
NVD-CWE-noinfo
|
CVE-2018-14020
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246617
|
7.5 |
HIGH
Network
|
wi2be
|
smart_hp_wmt
|
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to obtain sensitive information via /Status/SystemStatusRpm.esp.
|
CWE-200
Information Exposure
|
CVE-2018-14079
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246618
|
9.8 |
CRITICAL
Network
|
wi2be
|
smart_hp_wmt
|
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to reset the admin password via the /ConfigWizard/ChangePwd.esp?2admin URL (Attackers can login using the "admin" username wi…
|
CWE-287
Improper Authentication
|
CVE-2018-14078
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246619
|
7.5 |
HIGH
Network
|
wi2be
|
smart_hp_wmt
|
Wi2be SMART HP WMT R1.2.20_201400922 allows unauthorized remote attackers to backup the device configuration via a direct request to /Maintenance/configfile.cfg.
|
NVD-CWE-noinfo
|
CVE-2018-14077
|
2024-11-21 12:48 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246620
|
6.5 |
MEDIUM
Network
|
pimcore
|
pimcore
|
Pimcore before 5.3.0 allows SQL Injection via the REST web service API.
|
CWE-89
SQL Injection
|
CVE-2018-14058
|
2024-11-21 12:48 |
2018-08-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|