|
249041
|
7.5 |
HIGH
Network
|
suse
|
obs-service-tar_scm
|
Relative Path Traversal vulnerability in obs-service-tar_scm of SUSE Linux Enterprise Server 15; openSUSE Factory allows remote attackers with control over a repository to overwrite files on the mach…
|
CWE-22
Path Traversal
|
CVE-2018-12476
|
2024-11-21 12:45 |
2020-01-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249042
|
6.5 |
MEDIUM
Network
|
arista
|
cloudvision_portal
|
Arista CloudVision Portal through 2018.1.1 has Incorrect Permissions.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-12357
|
2024-11-21 12:45 |
2019-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249043
|
8.8 |
HIGH
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. CSRF in htdocs/manage/users.php allows creating another user with admin privileges.
|
CWE-352
Origin Validation Error
|
CVE-2018-12628
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249044
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/list.php has XSS via the show_notification_list_issues or show_authorized_issues parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12627
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249045
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/popup.php has XSS via the cat parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12626
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249046
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/validate.php has XSS via the values parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12625
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249047
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. htdocs/switch.php has XSS via the current_page parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12623
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249048
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. htdocs/ajax/update.php has XSS via the field_name parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12622
|
2024-11-21 12:45 |
2019-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249049
|
6.1 |
MEDIUM
Network
|
eventum_project
|
eventum
|
An issue was discovered in Eventum 3.5.0. /htdocs/switch.php has an Open Redirect via the current_page parameter.
|
CWE-601
Open Redirect
|
CVE-2018-12621
|
2024-11-21 12:45 |
2019-07-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249050
|
6.1 |
MEDIUM
Network
|
digisol
|
dg-hr3400_firmware
|
DIGISOL DG-HR3400 devices have XSS via a modified SSID when the apssid value is unchanged.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12715
|
2024-11-21 12:45 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|