|
246031
|
5.4 |
MEDIUM
Network
|
nagios
|
nagios_xi
|
A cross-site scripting vulnerability exists in Nagios XI before 5.5.4 via the 'name' parameter within the Account Information page. Exploitation of this vulnerability allows an attacker to execute ar…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17146
|
2024-11-21 12:53 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246032
|
6.1 |
MEDIUM
Network
|
zrlog
|
zrlog
|
An issue was discovered in ZRLOG 2.0.1. There is a Stored XSS vulnerability in the nickname field of the comment area.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17079
|
2024-11-21 12:53 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246033
|
9.8 |
CRITICAL
Network
|
vtech
|
storio_max_firmware
|
VTech Storio Max before 56.D3JM6 allows remote command execution via shell metacharacters in an Android activity name. It exposes the storeintenttranslate.x service on port 1668 listening for request…
|
CWE-78
OS Command
|
CVE-2018-16618
|
2024-11-21 12:53 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246034
|
9.8 |
CRITICAL
Network
|
gvectors
|
wpforo_forum
|
An issue was discovered in the update function in the wpForo Forum plugin before 1.5.2 for WordPress. A registered forum is able to escalate privilege to the forum administrator without any form of u…
|
NVD-CWE-noinfo
|
CVE-2018-16613
|
2024-11-21 12:53 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246035
|
7.5 |
HIGH
Network
|
fangfa
|
fdcms
|
admin/Lib/Action/FpluginAction.class.php in FDCMS (aka Fangfa Content Manage System) 4.2 allows SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2018-17048
|
2024-11-21 12:53 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246036
|
7.5 |
HIGH
Network
|
kyocera
|
taskalfa_4002i_firmware taskalfa_6002i_firmware
|
DoBox_CstmBox_Info.model.htm on Kyocera TASKalfa 4002i and 6002i devices allows remote attackers to read the documents of arbitrary users via a modified HTTP request.
|
CWE-200
Information Exposure
|
CVE-2018-16656
|
2024-11-21 12:53 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246037
|
5.4 |
MEDIUM
Network
|
typesettercms
|
typesetter
|
Typesetter 5.1 allows XSS via the index.php/Admin LABEL parameter during new page creation.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16639
|
2024-11-21 12:53 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246038
|
4.8 |
MEDIUM
Network
|
typesettercms
|
typesetter
|
index.php/Admin/Classes in Typesetter 5.1 allows XSS via the description of a new class name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16626
|
2024-11-21 12:53 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246039
|
4.8 |
MEDIUM
Network
|
typesettercms
|
typesetter
|
index.php/Admin/Uploaded in Typesetter 5.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16625
|
2024-11-21 12:53 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246040
|
5.4 |
MEDIUM
Network
|
getkirby
|
kirby
|
panel/pages/home/edit in Kirby v2.5.12 allows XSS via the title of a new page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16624
|
2024-11-21 12:53 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|