|
247241
|
8.8 |
HIGH
Network
|
onethink
|
onethink
|
An issue was discovered in OneThink v1.1. There is a CSRF vulnerability in admin.php?s=/AuthManager/addToGroup.html that can endow administrator privileges.
|
CWE-352
Origin Validation Error
|
CVE-2018-15197
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247242
|
8.8 |
HIGH
Network
|
gogs
|
gogs
|
A CSRF vulnerability in the admin panel in Gogs through 0.11.53 allows remote attackers to execute admin operations via a crafted issue / link.
|
CWE-352
Origin Validation Error
|
CVE-2018-15193
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247243
|
8.6 |
HIGH
Network
|
gogs gitea
|
gogs gitea
|
An SSRF vulnerability in webhooks in Gitea through 1.5.0-rc2 and Gogs through 0.11.53 allows remote attackers to access intranet services.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-15192
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247244
|
6.1 |
MEDIUM
Network
|
gogs
|
gogs
|
Open redirect vulnerability in Gogs before 0.12 allows remote attackers to redirect users to arbitrary websites and conduct phishing attacks via an initial /\ substring in the user/login redirect_to …
|
CWE-601
Open Redirect
|
CVE-2018-15178
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247245
|
8.8 |
HIGH
Network
|
gxlcms
|
gxlcms
|
In Gxlcms 2.0, a news/index.php?s=Admin-Admin-Insert CSRF attack can add an administrator account.
|
CWE-352
Origin Validation Error
|
CVE-2018-15177
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247246
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at MSVCR120!memcpy+0x0000000000000074 and application crash) or possibly have unspecified other impact vi…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15176
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247247
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView 2.45 allows remote attackers to cause a denial of service (User Mode Write AV starting at Qt5Core!QVariant::~QVariant+0x0000000000000014 and application crash) or possibly have unspecified oth…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15175
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247248
|
7.8 |
HIGH
Local
|
xnview
|
xnview
|
XnView 2.45 allows remote attackers to cause a denial of service (Read Access Violation at the Instruction Pointer and application crash) or possibly have unspecified other impact via a crafted ICO f…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15174
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247249
|
7.5 |
HIGH
Network
|
nmap
|
nmap
|
Nmap through 7.70, when the -sV option is used, allows remote attackers to cause a denial of service (stack consumption and application crash) via a crafted TCP-based service.
|
NVD-CWE-noinfo
|
CVE-2018-15173
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247250
|
6.1 |
MEDIUM
Network
|
zohocorp
|
manageengine_applications_manager
|
A reflected Cross-site scripting (XSS) vulnerability in Zoho ManageEngine Applications Manager 13 before build 13820 allows remote attackers to inject arbitrary web script or HTML via the /deleteMO.d…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15169
|
2024-11-21 12:50 |
2018-08-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|