|
246461
|
4.3 |
MEDIUM
Network
|
wisetail
|
learning_management_system
|
Wisetail Learning Ecosystem (LE) through v4.11.6 allows insecure direct object reference (IDOR) attacks to download non-purchased course files via a modified id parameter.
|
CWE-538
File and Directory Information Exposure
|
CVE-2018-16970
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246462
|
7.8 |
HIGH
Local
|
webroot
|
secureanywhere
|
Webroot SecureAnywhere before 9.0.8.34 on macOS mishandles access to the driver by a process that lacks root privileges.
|
CWE-123
Write-what-where Condition
|
CVE-2018-16962
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246463
|
5.4 |
MEDIUM
Network
|
pluck-cms
|
pluck
|
Pluck 4.7.7 allows XSS via an SVG file that contains Javascript in a SCRIPT element, and is uploaded via pages->manage under admin.php?action=files.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16729
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246464
|
5.4 |
MEDIUM
Network
|
feindura
|
feindura
|
feindura 2.0.7 allows XSS via the tags field of a new page created at index.php?category=0&page=new.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16728
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246465
|
5.4 |
MEDIUM
Network
|
razorcms
|
razorcms
|
razorCMS 3.4.7 allows Stored XSS via the keywords of the homepage within the settings component.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16727
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246466
|
5.4 |
MEDIUM
Network
|
razorcms
|
razorcms
|
razorCMS 3.4.7 allows HTML injection via the description of the homepage within the settings component.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16726
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246467
|
5.4 |
MEDIUM
Network
|
dlink
|
dir-600m_firmware
|
D-Link DIR-600M devices allow XSS via the Hostname and Username fields in the Dynamic DNS Configuration page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16605
|
2024-11-21 12:53 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246468
|
6.5 |
MEDIUM
Adjacent
|
inteno
|
dg400_firmware
|
Inteno DG400 WU7U_ELION3.11.6-170614_1328 devices allow remote attackers to cause a denial of service (connectivity loss) via a series of packets with random MAC addresses, as demonstrated by macof.
|
NVD-CWE-noinfo
|
CVE-2018-16950
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246469
|
8.0 |
HIGH
Network
|
xunfeng_project
|
xunfeng
|
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.
|
CWE-352
Origin Validation Error
|
CVE-2018-16951
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246470
|
7.5 |
HIGH
Network
|
openafs debian
|
openafs debian_linux
|
An issue was discovered in OpenAFS before 1.6.23 and 1.8.x before 1.8.2. Several data types used as RPC input variables were implemented as unbounded array types, limited only by the inherent 32-bit …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16949
|
2024-11-21 12:53 |
2018-09-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|