|
247421
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12626
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247422
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12625
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247423
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12623
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247424
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12622
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247425
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
|
CWE-601
Open Redirect
|
CVE-2018-12621
|
2024-11-21 12:45 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247426
|
6.1 |
MEDIUM
Network
|
digisol
|
dg-hr3400_firmware
|
DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12715
|
2024-11-21 12:45 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247427
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/post_note.php has XSS via the garlic_prefix parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12624
|
2024-11-21 12:45 |
2019-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247428
|
5.9 |
MEDIUM
Network
|
yarnpkg
|
website
|
The signature verification routine in install.sh in yarnpkg/website through 2018-06-05 only verifies that the yarn release is signed by any (arbitrary) key in the local keyring of the user, and does …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-12556
|
2024-11-21 12:45 |
2019-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247429
|
5.9 |
MEDIUM
Network
|
mozilla
|
network_security_services
|
A cached side channel attack during handshakes using RSA encryption could allow for the decryption of encrypted content. This is a variant of the Adaptive Chosen Ciphertext attack (AKA Bleichenbacher…
|
NVD-CWE-noinfo
|
CVE-2018-12404
|
2024-11-21 12:45 |
2019-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247430
|
5.9 |
MEDIUM
Network
|
mozilla
|
network_security_services
|
When handling a SSLv2-compatible ClientHello request, the server doesn't generate a new random value but sends an all-zero value instead. This results in full malleability of the ClientHello for SSLv…
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2018-12384
|
2024-11-21 12:45 |
2019-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|