|
246401
|
7.5 |
HIGH
Network
|
lg
|
supersign_cms
|
LG SuperSign CMS allows TVs to be rebooted remotely without authentication via a direct HTTP request to /qsr_server/device/reboot on port 9080.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-16706
|
2024-11-21 12:53 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246402
|
9.8 |
CRITICAL
Network
|
tecnick limesurvey
|
tcpdf limesurvey
|
An issue was discovered in TCPDF before 6.2.22. Attackers can trigger deserialization of arbitrary data via the phar:// wrapper.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-17057
|
2024-11-21 12:53 |
2018-09-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246403
|
6.1 |
MEDIUM
Network
|
knet
|
cisco_configuration_manager
|
K-Net Cisco Configuration Manager through 2014-11-19 has XSS via devices.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17051
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246404
|
6.1 |
MEDIUM
Network
|
cqu_lankers_project
|
cqu_lankers
|
CQU-LANKERS through 2017-11-02 has XSS via the public/api.php callback parameter in an uploadpic action.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17049
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246405
|
6.1 |
MEDIUM
Network
|
translate_man_project
|
translate_man
|
translate man before 2018-08-21 has XSS via containers/outputBox/outputBox.vue and store/index.js.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17046
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246406
|
8.8 |
HIGH
Network
|
cms_maelostore_project
|
cms_maelostore
|
An issue was discovered in CMS MaeloStore V.1.5.0. There is a CSRF vulnerability that can change the administrator password via admin/modul/users/aksi_users.php?act=update.
|
CWE-352
Origin Validation Error
|
CVE-2018-17045
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246407
|
4.8 |
MEDIUM
Network
|
yzmcms
|
yzmcms
|
In YzmCMS 5.1, stored XSS exists via the admin/system_manage/user_config_add.html title parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17044
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246408
|
7.8 |
HIGH
Local
|
doc2txt_project
|
doc2txt
|
An issue has been found in doc2txt through 2014-03-19. It is a heap-based buffer overflow in the function Storage::init in Storage.cpp, called from parse_doc in parse_doc.cpp.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17043
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246409
|
5.5 |
MEDIUM
Local
|
scalabium
|
dbf2txt
|
An issue has been found in dbf2txt through 2012-07-19. It is a infinite loop.
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2018-17042
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246410
|
6.1 |
MEDIUM
Network
|
1234n
|
minicms
|
MiniCMS 1.10, when Internet Explorer is used, allows XSS via a crafted URI because $_SERVER['REQUEST_URI'] is mishandled.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17039
|
2024-11-21 12:53 |
2018-09-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|