|
247051
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion
|
_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15563
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247052
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.
|
CWE-352
Origin Validation Error
|
CVE-2018-15702
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247053
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Cookie field.
|
CWE-20
Improper Input Validation
|
CVE-2018-15701
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247054
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Referer field.
|
CWE-20
Improper Input Validation
|
CVE-2018-15700
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247055
|
9.8 |
CRITICAL
Network
|
emc
|
esrs_policy_manager
|
Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may poten…
|
NVD-CWE-noinfo
|
CVE-2018-15764
|
2024-11-21 12:51 |
2018-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247056
|
6.7 |
MEDIUM
Local
|
avaya
|
aura_communication_manager
|
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected vers…
|
NVD-CWE-noinfo
|
CVE-2018-15611
|
2024-11-21 12:51 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247057
|
9.8 |
CRITICAL
Network
|
javamelody_project
|
javamelody
|
JavaMelody before 1.74.0 has XXE via parseSoapMethodName in bull/javamelody/PayloadNameRequestWrapper.java.
|
CWE-611
XXE
|
CVE-2018-15531
|
2024-11-21 12:51 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247058
|
7.5 |
HIGH
Network
|
xelerance
|
openswan
|
In verify_signed_hash() in lib/liboswkeys/signatures.c in Openswan before 2.6.50.1, the RSA implementation does not verify the value of padding string during PKCS#1 v1.5 signature verification. Conse…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2018-15836
|
2024-11-21 12:51 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247059
|
6.1 |
MEDIUM
Network
|
salesagility
|
suitecrm
|
An XSS issue was discovered in SalesAgility SuiteCRM 7.x before 7.8.21 and 7.10.x before 7.10.8, related to phishing an error message.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15606
|
2024-11-21 12:51 |
2018-09-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247060
|
7.5 |
HIGH
Network
|
adobe redhat
|
flash_player_desktop_runtime flash_player enterprise_linux_desktop enterprise_linux_server enterprise_linux_workstation
|
Adobe Flash Player versions 30.0.0.154 and earlier have a privilege escalation vulnerability. Successful exploitation could lead to information disclosure.
|
CWE-200
Information Exposure
|
CVE-2018-15967
|
2024-11-21 12:51 |
2018-09-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|