|
246131
|
7.5 |
HIGH
Network
|
libsvg2_project
|
libsvg2
|
An issue was discovered in libsvg2 through 2012-10-19. The svgGetNextPathField function in svg_string.c returns its input pointer in certain circumstances, which might result in a memory leak caused …
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-17332
|
2024-11-21 12:54 |
2018-09-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246132
|
6.1 |
MEDIUM
Network
|
yunucms
|
yunucms
|
Cross-site scripting (XSS) vulnerability in index.php/index/category/index in YUNUCMS 1.1.4 allows remote attackers to inject arbitrary web script or HTML via the area parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17322
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246133
|
6.1 |
MEDIUM
Network
|
seacms
|
seacms
|
An issue was discovered in SeaCMS 6.64. XSS exists in admin_datarelate.php via the time or maxHit parameter in a dorandomset action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17321
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246134
|
6.1 |
MEDIUM
Network
|
ucms_project
|
ucms
|
An issue was discovered in UCMS 1.4.6. aaddpost.php has stored XSS via the sadmin/aindex.php minfo parameter in a sadmin_aaddpost action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17320
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246135
|
9.8 |
CRITICAL
Network
|
fruitywifi_project
|
fruitywifi
|
FruityWifi (aka PatatasFritas/PatataWifi) 2.1 allows remote attackers to execute arbitrary commands via shell metacharacters in the io_mode, ap_mode, io_action, io_in_iface, io_in_set, io_in_ip, io_i…
|
CWE-78
OS Command
|
CVE-2018-17317
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246136
|
9.8 |
CRITICAL
Network
|
nmealib_project
|
nmealib
|
A stack-based buffer overflow was discovered in the xtimor NMEA library (aka nmealib) 0.5.3. nmea_parse() in parser.c allows an attacker to trigger denial of service (even arbitrary code execution in…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17174
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246137
|
9.8 |
CRITICAL
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows remote attackers to execute arbitrary code via the sourceUri parameter to qsr_server/device/getThumbnail.
|
CWE-94
Code Injection
|
CVE-2018-17173
|
2024-11-21 12:54 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246138
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
Stored XSS exists in views/fields/wysiwyg.js in EspoCRM 5.3.6 via a /#Email/view saved draft message.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17302
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246139
|
5.4 |
MEDIUM
Network
|
espocrm
|
espocrm
|
Reflected XSS exists in client/res/templates/global-search/name-field.tpl in EspoCRM 5.3.6 via /#Account in the search panel.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17301
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246140
|
4.8 |
MEDIUM
Network
|
cuppacms
|
cuppacms
|
Stored XSS exists in CuppaCMS through 2018-09-03 via an administrator/#/component/table_manager/view/cu_menus section name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17300
|
2024-11-21 12:54 |
2018-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|