|
246841
|
6.1 |
MEDIUM
Network
|
coppermine-gallery
|
coppermine_photo_gallery
|
ecard.php in Coppermine Photo Gallery (CPG) 1.5.46 has XSS via the sender_name, recipient_email, greetings, or recipient_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14478
|
2024-11-21 12:49 |
2019-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246842
|
5.4 |
MEDIUM
Network
|
polarisft
|
intellect_core_banking
|
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. Reflected XSS exists with an authenticated session via the Customerid, formName, FrameId, or MODE pa…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14875
|
2024-11-21 12:49 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246843
|
8.8 |
HIGH
Network
|
polarisft
|
intellect_core_banking
|
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. Input passed through the code parameter in three pages as collaterals/colexe3t.jsp and /references/refsuppu.jsp…
|
CWE-89
SQL Injection
|
CVE-2018-14874
|
2024-11-21 12:49 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246844
|
7.5 |
HIGH
Network
|
tenda
|
ac7_firmware ac9_firmware ac10_firmware
|
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14559
|
2024-11-21 12:49 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246845
|
7.5 |
HIGH
Network
|
tenda
|
ac7_firmware ac9_firmware ac10_firmware
|
An issue was discovered on Tenda AC7 devices with firmware through V15.03.06.44_CN(AC7), AC9 devices with firmware through V15.03.05.19(6318)_CN(AC9), and AC10 devices with firmware through V15.03.06…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14557
|
2024-11-21 12:49 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246846
|
6.1 |
MEDIUM
Network
|
paessler
|
prtg_network_monitor
|
PRTG before 19.1.49.1966 has Cross Site Scripting (XSS) in the WEBGUI.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14683
|
2024-11-21 12:49 |
2019-04-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246847
|
6.5 |
MEDIUM
Network
|
we-con
|
pi_studio pi_studio_hmi
|
WECON Technology PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior lacks proper validation of user-supplied data, which may result in a read past the end of an allocated …
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14814
|
2024-11-21 12:49 |
2019-03-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246848
|
8.8 |
HIGH
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in prot_get_ring_space in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has obtained code execution on the Wi-Fi chip) to overwri…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14745
|
2024-11-21 12:49 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246849
|
5.4 |
MEDIUM
Network
|
mybb
|
ban_list
|
In the Ban List plugin 1.0 for MyBB, any forum user with mod privileges can ban users and input an XSS payload into the ban reason, which is executed on the bans.php page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14724
|
2024-11-21 12:49 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246850
|
8.8 |
HIGH
Network
|
mybb
|
trash_bin
|
Trash Bin plugin 1.1.3 for MyBB has cross-site scripting (XSS) via a thread subject and a cross-site request forgery (CSRF) via a post subject.
|
CWE-352 CWE-79
Origin Validation Error Cross-site Scripting
|
CVE-2018-14575
|
2024-11-21 12:49 |
2019-03-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|