|
246111
|
9.8 |
CRITICAL
Network
|
moxa
|
thingspro
|
Hidden Token Access in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
|
NVD-CWE-noinfo
|
CVE-2018-18395
|
2024-11-21 12:55 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246112
|
9.8 |
CRITICAL
Network
|
moxa
|
thingspro
|
Sensitive Information Stored in Clear Text in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-18394
|
2024-11-21 12:55 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246113
|
9.8 |
CRITICAL
Network
|
moxa
|
thingspro
|
Password Management Issue in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
|
NVD-CWE-noinfo
|
CVE-2018-18393
|
2024-11-21 12:55 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246114
|
8.8 |
HIGH
Network
|
moxa
|
thingspro
|
Privilege Escalation via Broken Access Control in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
|
NVD-CWE-noinfo
|
CVE-2018-18392
|
2024-11-21 12:55 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246115
|
8.8 |
HIGH
Network
|
moxa
|
thingspro
|
User Privilege Escalation in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
|
NVD-CWE-noinfo
|
CVE-2018-18391
|
2024-11-21 12:55 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246116
|
7.5 |
HIGH
Network
|
moxa
|
thingspro
|
User Enumeration in Moxa ThingsPro IIoT Gateway and Device Management Software Solutions version 2.1.
|
CWE-200
Information Exposure
|
CVE-2018-18390
|
2024-11-21 12:55 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246117
|
9.8 |
CRITICAL
Network
|
kibokolabs
|
arigato_autoresponder_and_newsletter
|
The Arigato Autoresponder and Newsletter (aka bft-autoresponder) v2.5.1.7 plugin for WordPress allows remote attackers to execute arbitrary code via PHP code in attachments[] data to models/attachmen…
|
CWE-94
Code Injection
|
CVE-2018-18461
|
2024-11-21 12:55 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246118
|
6.1 |
MEDIUM
Network
|
3cx
|
live_chat
|
XSS exists in the wp-live-chat-support v8.0.15 plugin for WordPress via the modules/gdpr.php term parameter in a wp-admin/admin.php wplivechat-menu-gdpr-page request.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18460
|
2024-11-21 12:55 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246119
|
5.5 |
MEDIUM
Local
|
xpdfreader
|
xpdf
|
The function DCTStream::getBlock in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18459
|
2024-11-21 12:55 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246120
|
5.5 |
MEDIUM
Local
|
xpdfreader
|
xpdf
|
The function DCTStream::decodeImage in Stream.cc in Xpdf 4.00 allows remote attackers to cause a denial of service (NULL pointer dereference) via a crafted pdf file, as demonstrated by pdftoppm.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-18458
|
2024-11-21 12:55 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|