|
248841
|
5.4 |
MEDIUM
Network
|
joyplus-cms_project
|
joyplus-cms
|
joyplus-cms 1.6.0 has XSS via the manager/admin_ajax.php can_search_device array parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14388
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248842
|
8.8 |
HIGH
Network
|
wondercms
|
wondercms
|
An issue was discovered in WonderCMS before 2.5.2. An attacker can create a new session on a web application and record the associated session identifier. The attacker then causes the victim to authe…
|
CWE-384
Session Fixation
|
CVE-2018-14387
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248843
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
GitLab Community and Enterprise Edition before 10.7.7, 10.8.x before 10.8.6, and 11.x before 11.0.4 allows Directory Traversal with write access and resultant remote code execution via the GitLab pro…
|
CWE-22
Path Traversal
|
CVE-2018-14364
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248844
|
5.4 |
MEDIUM
Network
|
freelancewebdesignerchennai
|
job_portal
|
PHP Scripts Mall JOB SITE (aka Job Portal) 3.0.1 has Cross-site Scripting (XSS) via the search bar.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14082
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248845
|
6.1 |
MEDIUM
Network
|
instantcms
|
instantcms
|
InstantCMS 2.10.1 has /redirect?url= XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14382
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248846
|
6.1 |
MEDIUM
Network
|
pagekit
|
pagekit
|
Pagekit before 1.0.14 has a /user/login?redirect= open redirect vulnerability.
|
CWE-601
Open Redirect
|
CVE-2018-14381
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248847
|
6.1 |
MEDIUM
Network
|
graylog
|
graylog
|
In Graylog before 2.4.6, XSS was possible in typeahead components, related to components/common/TypeAheadInput.jsx and components/search/QueryInput.ts.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14380
|
2024-11-21 12:48 |
2018-07-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248848
|
7.5 |
HIGH
Network
|
eclipse
|
mojarra
|
The getLocalePrefix function in ResourceManager.java in Eclipse Mojarra before 2.3.7 is affected by Directory Traversal via the loc parameter. A remote attacker can download configuration files or Ja…
|
CWE-22
Path Traversal
|
CVE-2018-14371
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248849
|
8.8 |
HIGH
Network
|
techsmith
|
mp4v2
|
MP4Atom::factory in mp4atom.cpp in MP4v2 2.0.0 incorrectly uses the MP4ItemAtom data type in a certain case where MP4DataAtom is required, which allows remote attackers to cause a denial of service (…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2018-14379
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248850
|
7.5 |
HIGH
Network
|
debian neomutt
|
debian_linux neomutt
|
An issue was discovered in NeoMutt before 2018-07-16. newsrc.c does not properly restrict '/' characters that may have unsafe interaction with cache pathnames.
|
CWE-22
Path Traversal
|
CVE-2018-14363
|
2024-11-21 12:48 |
2018-07-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|