|
249991
|
7.8 |
HIGH
Local
|
libreoffice debian redhat canonical
|
libreoffice debian_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server ubuntu_linux
|
sot/source/sdstor/stgstrms.cxx in LibreOffice before 5.4.5.1 and 6.x before 6.0.1.1 uses an incorrect integer data type in the StgSmallStrm class, which allows remote attackers to cause a denial of s…
|
CWE-416
Use After Free
|
CVE-2018-10119
|
2024-11-21 12:40 |
2018-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249992
|
8.8 |
HIGH
Network
|
h2database cognitect
|
h2 datomic
|
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designe…
|
CWE-20
Improper Input Validation
|
CVE-2018-10054
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249993
|
4.8 |
MEDIUM
Network
|
iscripts
|
supportdesk
|
iScripts SupportDesk v4.3 has XSS via the admin/inteligentsearchresult.php txtinteligentsearch parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10052
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249994
|
5.4 |
MEDIUM
Network
|
iscripts
|
supportdesk
|
iScripts SupportDesk v4.3 has XSS via the staff/inteligentsearchresult.php txtinteligentsearch parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10051
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249995
|
7.2 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has SQL injection via the "registration_settings.php" ddlFree parameter in the Admin Panel.
|
CWE-89
SQL Injection
|
CVE-2018-10050
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249996
|
4.8 |
MEDIUM
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has XSS via the "registration_settings.php" txtDate parameter in the Admin Panel.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10049
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249997
|
8.8 |
HIGH
Network
|
iscripts
|
eswap
|
iScripts eSwap v2.4 has CSRF via "registration_settings.php" in the Admin Panel.
|
CWE-352
Origin Validation Error
|
CVE-2018-10048
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249998
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Stored XSS in admin/siteprefs.php via the metadata parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10033
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249999
|
4.8 |
MEDIUM
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has Reflected XSS in admin/moduleinterface.php via the m1_version parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10032
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250000
|
8.8 |
HIGH
Network
|
cmsmadesimple
|
cms_made_simple
|
CMS Made Simple (aka CMSMS) 2.2.7 has CSRF in admin/moduleinterface.php.
|
CWE-352
Origin Validation Error
|
CVE-2018-10031
|
2024-11-21 12:40 |
2018-04-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|