|
246981
|
7.5 |
HIGH
Local
|
docker
|
docker
|
In Docker through 18.06.1-ce-rc2, the API endpoints behind the 'docker cp' command are vulnerable to a symlink-exchange attack with Directory Traversal, giving attackers arbitrary read-write access t…
|
CWE-362
Race Condition
|
CVE-2018-15664
|
2024-11-21 12:51 |
2019-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246982
|
6.1 |
MEDIUM
Network
|
xerox
|
colorqube_8580_firmware
|
Cross-site scripting (XSS) in the web interface of the Xerox ColorQube 8580 allows remote persistent injection of custom HTML / JavaScript code.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15530
|
2024-11-21 12:51 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246983
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in adm/boardgroup_form_update.php and adm/boardgroup_list_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15584
|
2024-11-21 12:51 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246984
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in adm/sms_admin/num_book_write.php and adm/sms_admin/num_book_update.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script o…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15582
|
2024-11-21 12:51 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246985
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in adm/faqmasterformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15581
|
2024-11-21 12:51 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246986
|
6.1 |
MEDIUM
Network
|
sir
|
gnuboard
|
Cross-Site Scripting (XSS) vulnerability in adm/contentformupdate.php in gnuboard5 before 5.3.1.6 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15580
|
2024-11-21 12:51 |
2019-04-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246987
|
8.8 |
HIGH
Network
|
odoo
|
odoo
|
Improper access control in the Helpdesk App of Odoo Enterprise 10.0 through 12.0 allows remote authenticated attackers to obtain elevated privileges via a crafted request.
|
CWE-863
Incorrect Authorization
|
CVE-2018-15640
|
2024-11-21 12:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246988
|
6.1 |
MEDIUM
Network
|
odoo
|
odoo
|
Cross-site scripting vulnerability in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote attackers to inject arbitrary web script in the browser of…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15635
|
2024-11-21 12:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246989
|
6.5 |
MEDIUM
Network
|
odoo
|
odoo
|
Improper access control in the Discuss App of Odoo Community 12.0 and earlier, and Odoo Enterprise 12.0 and earlier allows remote authenticated attackers to e-mail themselves arbitrary files from the…
|
NVD-CWE-noinfo
|
CVE-2018-15631
|
2024-11-21 12:51 |
2019-04-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246990
|
7.5 |
HIGH
Network
|
tp-link
|
tl-wr840n_firmware
|
TP-Link TL-WR840N devices allow remote attackers to cause a denial of service (networking outage) via fragmented packets, as demonstrated by an "nmap -f" command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15840
|
2024-11-21 12:51 |
2019-03-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|