|
246081
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c6503_firmware
|
On the RICOH MP C6503 Plus printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUs…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17311
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246082
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c1803_jpn_firmware
|
On the RICOH MP C1803 JPN printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUse…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17310
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246083
|
6.1 |
MEDIUM
Network
|
ricoh
|
mp_c406zspf_firmware
|
On the RICOH MP C406Z printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWiz…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17309
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246084
|
9.8 |
CRITICAL
Network
|
thinkphp
|
thinkphp
|
In ThinkPHP 5.1.24, the inner function delete can be used for SQL injection when its WHERE condition's value can be controlled by a user's request.
|
CWE-89
SQL Injection
|
CVE-2018-17566
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246085
|
9.8 |
CRITICAL
Network
|
horus_cms_project
|
horus_cms
|
Horus CMS allows SQL Injection, as demonstrated by a request to the /busca or /home URI.
|
CWE-89
SQL Injection
|
CVE-2018-17410
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246086
|
7.5 |
HIGH
Network
|
seacms
|
seacms
|
SeaCMS 6.64 and 7.2 allows remote attackers to delete arbitrary files via the filedir parameter.
|
CWE-22
Path Traversal
|
CVE-2018-17365
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246087
|
8.1 |
HIGH
Network
|
postman
|
postman
|
An information-disclosure issue was discovered in Postman through 6.3.0. It validates a server's X.509 certificate and presents an error if the certificate is not valid. Unfortunately, the associated…
|
CWE-295
Improper Certificate Validation
|
CVE-2018-17215
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246088
|
5.4 |
MEDIUM
Network
|
modx
|
modx_revolution
|
MODX Revolution v2.6.5-pl allows stored XSS via a Create New Media Source action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17556
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246089
|
7.5 |
HIGH
Network
|
commscope
|
arris_tg2492lg-na_firmware
|
The web component on ARRIS TG2492LG-NA 061213 devices allows remote attackers to obtain sensitive information via the /snmpGet oids parameter.
|
CWE-200
Information Exposure
|
CVE-2018-17555
|
2024-11-21 12:54 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246090
|
9.8 |
CRITICAL
Network
|
axon
|
evidence_sync
|
Axon (formerly TASER International) Evidence Sync 3.15.89 is vulnerable to process injection. NOTE: the vendor's position is that this CVE is not associated with information that supports any finding…
|
NVD-CWE-noinfo
|
CVE-2018-17538
|
2024-11-21 12:54 |
2018-09-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|