|
247801
|
4.8 |
MEDIUM
Network
|
seacms
|
seacms
|
SeaCMS V6.61 has XSS via the site name parameter on an adm1n/admin_config.php page (aka a system management page).
|
CWE-79
Cross-site Scripting
|
CVE-2018-12431
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247802
|
9.8 |
CRITICAL
Network
|
simple_password_store_project
|
simple_password_store
|
An issue was discovered in password-store.sh in pass in Simple Password Store 1.7.x before 1.7.2. The signature verification routine parses the output of GnuPG with an incomplete regular expression, …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-12356
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247803
|
7.5 |
HIGH
Network
|
matrix
|
synapse
|
In Synapse before 0.31.2, unauthorised users can hijack rooms when there is no m.room.power_levels event in force.
|
NVD-CWE-noinfo
|
CVE-2018-12423
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247804
|
7.5 |
HIGH
Network
|
icehrm
|
icehrm
|
IceHrm before 23.0.1.OS has a risky usage of a hashed password in a request.
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2018-12420
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247805
|
9.8 |
CRITICAL
Network
|
ltb-project
|
ldap_tool_box_self_service_password
|
LTB (aka LDAP Tool Box) Self Service Password before 1.3 allows a change to a user password (without knowing the old password) via a crafted POST request, because the ldap_bind return value is mishan…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2018-12421
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247806
|
5.5 |
MEDIUM
Local
|
junrar_project
|
junrar
|
Archive.java in Junrar before 1.0.1, as used in Apache Tika and other products, is affected by a denial of service vulnerability due to an infinite loop when handling corrupt RAR files.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-12418
|
2024-11-21 12:45 |
2018-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247807
|
6.1 |
MEDIUM
Network
|
eng
|
knowage
|
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name or description field to the "Olap Schemas' Catalogue" catalogue.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12355
|
2024-11-21 12:45 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247808
|
8.8 |
HIGH
Network
|
knowage-suite
|
knowage
|
Knowage (formerly SpagoBI) 6.1.1 allows CSRF via every form, as demonstrated by a /knowage/restful-services/2.0/analyticalDrivers/ POST request.
|
CWE-352
Origin Validation Error
|
CVE-2018-12354
|
2024-11-21 12:45 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247809
|
6.1 |
MEDIUM
Network
|
knowage-suite
|
knowage
|
Knowage (formerly SpagoBI) 6.1.1 allows XSS via the name field to the "Business Model's Catalogue" catalogue.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12353
|
2024-11-21 12:45 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247810
|
5.4 |
MEDIUM
Network
|
articlecms_project
|
articlecms
|
ArticleCMS through 2017-02-19 has XSS via an "add an article" action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12339
|
2024-11-21 12:45 |
2018-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|