|
249961
|
6.1 |
MEDIUM
Network
|
dlink
|
dir-815_firmware
|
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have XSS in the RESULT parameter to /htdocs/webinc/js/info.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10107
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249962
|
9.8 |
CRITICAL
Network
|
dlink
|
dir-815_firmware
|
D-Link DIR-815 REV. B (with firmware through DIR-815_REVB_FIRMWARE_PATCH_2.07.B01) devices have permission bypass and information disclosure in /htdocs/web/getcfg.php, as demonstrated by a /getcfg.ph…
|
CWE-200
Information Exposure
|
CVE-2018-10106
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249963
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Before WordPress 4.9.5, the version string was not escaped in the get_the_generator function, and could lead to XSS in a generator tag.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10102
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249964
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Before WordPress 4.9.5, the URL validator assumed URLs with the hostname localhost were on the same host as the WordPress server.
|
CWE-601
Open Redirect
|
CVE-2018-10101
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249965
|
6.1 |
MEDIUM
Network
|
wordpress debian
|
wordpress debian_linux
|
Before WordPress 4.9.5, the redirection URL for the login page was not validated or sanitized if forced to use HTTPS.
|
CWE-601
Open Redirect
|
CVE-2018-10100
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249966
|
6.1 |
MEDIUM
Network
|
smartscriptsolutions
|
domain_trader
|
XSS exists in Domain Trader 2.5.3 via the recoverlogin.php email_address parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10097
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249967
|
4.8 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 has XSS via the device_name parameter in a manager/admin_ajax.php?action=save flag=add request.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10096
|
2024-11-21 12:40 |
2018-04-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249968
|
5.5 |
MEDIUM
Local
|
linux debian canonical
|
linux_kernel debian_linux ubuntu_linux
|
The kernel_wait4 function in kernel/exit.c in the Linux kernel before 4.13, when an unspecified architecture and compiler is used, might allow local users to cause a denial of service by triggering a…
|
CWE-20
Improper Input Validation
|
CVE-2018-10087
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249969
|
8.1 |
HIGH
Network
|
mikrotik
|
routeros
|
An issue was discovered in MikroTik RouterOS 6.41.4. Missing OpenVPN server certificate verification allows a remote unauthenticated attacker capable of intercepting client traffic to act as a malici…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-10066
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249970
|
7.2 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (CMSMS) through 2.2.7 contains an arbitrary code execution vulnerability in the admin dashboard because the implementation uses "eval('function testfunction'.rand()" and it is possibl…
|
CWE-94
Code Injection
|
CVE-2018-10086
|
2024-11-21 12:40 |
2018-04-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|