|
246581
|
5.4 |
MEDIUM
Network
|
razorcms
|
razorcms
|
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16726
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246582
|
5.4 |
MEDIUM
Network
|
dlink
|
dir-600m_firmware
|
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16605
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246583
|
6.5 |
MEDIUM
Adjacent
|
inteno
|
dg400_firmware
|
Inteno DG400 WU7U_ELION3.11.6-170614_1328 devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses, as demonstrated by macof.
|
NVD-CWE-noinfo
|
CVE-2018-16950
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246584
|
8.0 |
HIGH
Network
|
xunfeng_project
|
xunfeng
|
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.
|
CWE-352
Origin Validation Error
|
CVE-2018-16951
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246585
|
7.5 |
HIGH
Network
|
openafs debian
|
openafs debian_linux
|
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16949
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246586
|
7.5 |
HIGH
Network
|
openafs debian
|
openafs debian_linux
|
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several RPC server routines did not fully initialize their output variables before returning, leaking memory contents from bot…
|
CWE-200
Information Exposure
|
CVE-2018-16948
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246587
|
9.8 |
CRITICAL
Network
|
openafs debian
|
openafs debian_linux
|
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. The backup tape controller (butc) process accepts incoming RPCs but does not require (or allow for) authentication of those RP…
|
CWE-287
Improper Authentication
|
CVE-2018-16947
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246588
|
7.5 |
HIGH
Network
|
lg
|
lnb5110_firmware lnb5320_firmware lnb5320r_firmware lnb7210_firmware lnd3230r_firmware lnd5110_firmware lnd5110r_firmware lnd5220r_firmware lnd7210_firmware lnd7210r_firmwa…
|
LG LNB*, LND*, LNU*, and LNV* smart network camera devices have broken access control. Attackers are able to download /updownload/t.report (aka Log & Report) files and download backup files (via down…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2018-16946
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246589
|
9.8 |
CRITICAL
Network
|
rubedo_project
|
rubedo
|
Rubedo through 3.4.0 contains a Directory Traversal vulnerability in the theme component, allowing unauthenticated attackers to read and execute arbitrary files outside of the service root path, as d…
|
CWE-22
Path Traversal
|
CVE-2018-16836
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246590
|
6.5 |
MEDIUM
Network
|
xunfeng_project
|
xunfeng
|
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of…
|
CWE-352
Origin Validation Error
|
CVE-2018-16832
|
2024-11-21 12:53 |
2018-09-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|