|
246361
|
7.5 |
HIGH
Network
|
ethereum
|
go_ethereum
|
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block.
|
CWE-20
Improper Input Validation
|
CVE-2018-16733
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246362
|
8.8 |
HIGH
Network
|
chshcms
|
cscms
|
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
|
CWE-352
Origin Validation Error
|
CVE-2018-16732
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246363
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16731
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246364
|
6.1 |
MEDIUM
Network
|
chshcms
|
cscms
|
\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16730
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246365
|
6.1 |
MEDIUM
Network
|
baijiacms_project
|
baijiacms
|
An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component."
|
CWE-79
Cross-site Scripting
|
CVE-2018-16725
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246366
|
9.8 |
CRITICAL
Network
|
baijiacms_project
|
baijiacms
|
An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request.
|
CWE-89
SQL Injection
|
CVE-2018-16724
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246367
|
8.8 |
HIGH
Network
|
absolute
|
ctes_windows_agent
|
An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16715
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246368
|
9.1 |
CRITICAL
Network
|
octoprint
|
octoprint
|
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report …
|
CWE-200
Information Exposure
|
CVE-2018-16710
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246369
|
9.8 |
CRITICAL
Network
|
fujixerox
|
docucentre-v_3065_firmware apeosport-v_c4475_firmware apeosport-vi_c3371_firmware apeosport-v_c3375_firmware docucentre-vi_c2271_firmware apeosport-v_c5576_firmware docucentre-iv_c2…
|
Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPort-V 5070 devices a…
|
NVD-CWE-noinfo
|
CVE-2018-16709
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246370
|
4.3 |
MEDIUM
Network
|
gleeztech
|
gleezcms
|
An issue was discovered in Gleez CMS v1.2.0. Because of an Insecure Direct Object Reference vulnerability, it is possible for attackers (logged in users) to view profile page of other users, as demon…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-16704
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|