|
247291
|
7.5 |
HIGH
Network
|
phpcms
|
phpcms
|
PHPCMS 9 allows remote attackers to cause a denial of service (resource consumption) via large font_size, height, and width parameters in an api.php?op=checkcode request.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-14940
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247292
|
9.8 |
CRITICAL
Network
|
libreoffice
|
libreoffice
|
The get_app_path function in desktop/unx/source/start.c in LibreOffice through 6.0.5 mishandles the realpath function in certain environments such as FreeBSD libc, which might allow attackers to caus…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14939
|
2024-11-21 12:50 |
2018-08-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247293
|
9.1 |
CRITICAL
Network
|
digitalcorpora canonical
|
tcpflow ubuntu_linux
|
An issue was discovered in wifipcap/wifipcap.cpp in TCPFLOW through 1.5.0-alpha. There is an integer overflow in the function handle_prism during caplen processing. If the caplen is less than 144, on…
|
CWE-125 CWE-190
Out-of-bounds Read Integer Overflow or Wraparound
|
CVE-2018-14938
|
2024-11-21 12:50 |
2018-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247294
|
4.8 |
MEDIUM
Network
|
mylittleforum
|
my_little_forum
|
The Add page option in my little forum 2.4.12 allows XSS via the Menu Link field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14937
|
2024-11-21 12:50 |
2018-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247295
|
4.8 |
MEDIUM
Network
|
mylittleforum
|
my_little_forum
|
The Add page option in my little forum 2.4.12 allows XSS via the Title field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14936
|
2024-11-21 12:50 |
2018-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247296
|
9.8 |
CRITICAL
Network
|
nuuo
|
nvrmini_firmware
|
upgrade_handle.php on NUUO NVRmini devices allows Remote Command Execution via shell metacharacters in the uploaddir parameter for a writeuploaddir command.
|
CWE-78
OS Command
|
CVE-2018-14933
|
2024-11-21 12:50 |
2018-08-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247297
|
6.1 |
MEDIUM
Network
|
matera
|
banco
|
Matera Banco 1.0.0 is vulnerable to multiple reflected XSS, as demonstrated by the /contingency/web/index.jsp (aka home page) url parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14929
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247298
|
7.5 |
HIGH
Network
|
matera
|
banco
|
/contingency/servlet/ServletFileDownload executes as root and provides unauthenticated access to files via the file parameter.
|
CWE-200
Information Exposure
|
CVE-2018-14928
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247299
|
5.3 |
MEDIUM
Network
|
matera
|
banco
|
Matera Banco 1.0.0 is vulnerable to path traversal (allowing access to system files outside the default application folder) via the /contingency/servlet/ServletFileDownload file parameter, related to…
|
CWE-22
Path Traversal
|
CVE-2018-14927
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247300
|
8.8 |
HIGH
Network
|
matera
|
banco
|
Matera Banco 1.0.0 allows CSRF, as demonstrated by a /contingency/web/messageSend/messageSendHandler.jsp request.
|
CWE-352
Origin Validation Error
|
CVE-2018-14926
|
2024-11-21 12:50 |
2018-08-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|