|
246251
|
5.9 |
MEDIUM
Network
|
amazon
|
amazon_web_services_freertos freertos
|
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. Out of bounds memory…
|
CWE-200
Information Exposure
|
CVE-2018-16599
|
2024-11-21 12:53 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246252
|
5.9 |
MEDIUM
Network
|
amazon
|
amazon_web_services_freertos freertos
|
An issue was discovered in Amazon Web Services (AWS) FreeRTOS through 1.3.1, FreeRTOS up to V10.0.1 (with FreeRTOS+TCP), and WITTENSTEIN WHIS Connect middleware TCP/IP component. In xProcessReceivedU…
|
CWE-441
Confused Deputy
|
CVE-2018-16598
|
2024-11-21 12:53 |
2018-12-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246253
|
9.1 |
CRITICAL
Network
|
solarwinds
|
sftp\/scp_server
|
SolarWinds SFTP/SCP server through 2018-09-10 is vulnerable to XXE via a world readable and writable configuration file that allows an attacker to exfiltrate data.
|
CWE-611
XXE
|
CVE-2018-16792
|
2024-11-21 12:53 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246254
|
9.8 |
CRITICAL
Network
|
solarwinds
|
sftp\/scp_server
|
In SolarWinds SFTP/SCP Server through 2018-09-10, the configuration file is world readable and writable, and stores user passwords in an insecure manner, allowing an attacker to determine passwords f…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-16791
|
2024-11-21 12:53 |
2018-12-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246255
|
10.0 |
CRITICAL
Network
|
freebsd
|
freebsd
|
In FreeBSD before 11.2-STABLE(r341486) and 11.2-RELEASE-p6, insufficient bounds checking in one of the device models provided by bhyve can permit a guest operating system to overwrite memory in the b…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17160
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246256
|
8.8 |
HIGH
Network
|
pluck-cms
|
pluck
|
Pluck v4.7.7 allows CSRF via admin.php?action=settings.
|
CWE-352
Origin Validation Error
|
CVE-2018-16634
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246257
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck v4.7.7 allows XSS via the admin.php?action=editpage&page= page title.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16633
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246258
|
5.4 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
Subrion CMS v4.2.1 allows XSS via the panel/configuration/general/ SITE TITLE parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16631
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246259
|
4.8 |
MEDIUM
Network
|
intelliants
|
subrion_cms
|
panel/uploads/#elf_l1_XA in Subrion CMS v4.2.1 allows XSS via an SVG file with JavaScript in a SCRIPT element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16629
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246260
|
5.4 |
MEDIUM
Network
|
getkirby
|
kirby
|
panel/login in Kirby v2.5.12 allows XSS via a blog name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16628
|
2024-11-21 12:53 |
2018-12-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|