|
247401
|
5.4 |
MEDIUM
Network
|
trendmicro
|
deep_discovery_inspector
|
A Reflected Cross-Site Scripting (XSS) vulnerability in Trend Micro Deep Discovery Inspector 3.85 and below could allow an attacker to bypass CSRF protection and conduct an attack on vulnerable insta…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15365
|
2024-11-21 12:50 |
2018-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247402
|
9.8 |
CRITICAL
Network
|
isweb
|
isweb
|
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the…
|
CWE-22
Path Traversal
|
CVE-2018-14957
|
2024-11-21 12:50 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247403
|
9.8 |
CRITICAL
Network
|
isweb
|
isweb
|
CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.
|
CWE-89
SQL Injection
|
CVE-2018-14956
|
2024-11-21 12:50 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247404
|
7.8 |
HIGH
Local
|
vectra
|
cognito
|
Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability.
|
NVD-CWE-noinfo
|
CVE-2018-14891
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247405
|
5.4 |
MEDIUM
Network
|
vectra
|
cognito
|
Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14890
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247406
|
7.8 |
HIGH
Local
|
apache
|
couchdb
|
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
|
CWE-20
Improper Input Validation
|
CVE-2018-14889
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247407
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages.
|
CWE-200
Information Exposure
|
CVE-2018-15310
|
2024-11-21 12:50 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247408
|
7.5 |
HIGH
Network
|
lwolf
|
loading_docs
|
Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-15502
|
2024-11-21 12:50 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247409
|
9.1 |
CRITICAL
Network
|
kone
|
group_controller_firmware
|
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the na…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2018-15486
|
2024-11-21 12:50 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247410
|
9.1 |
CRITICAL
Network
|
kone
|
group_controller_firmware
|
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03.
|
CWE-287
Improper Authentication
|
CVE-2018-15485
|
2024-11-21 12:50 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|