|
246801
|
6.5 |
MEDIUM
Network
|
zziplib_project
|
zziplib
|
An issue was discovered in ZZIPlib through 0.13.69. There is a memory leak triggered in the function __zzip_parse_root_directory in zip.c, which will lead to a denial of service attack.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2018-16548
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246802
|
6.1 |
MEDIUM
Network
|
e107
|
e107
|
e107 2.1.8 has XSS via the e107_admin/users.php?mode=main&action=list user_loginname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16381
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246803
|
6.1 |
MEDIUM
Network
|
btiteam
|
xbtit
|
An issue was discovered in BTITeam XBTIT 2.5.4. news.php allows XSS via the id parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16361
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246804
|
7.5 |
HIGH
Network
|
mi
|
xiaomi_miwifi_xiaomi_55dd_firmware
|
An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL…
|
CWE-200
Information Exposure
|
CVE-2018-16307
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246805
|
3.3 |
LOW
Local
|
fspro
|
event_log_explorer
|
FsPro Labs Event Log Explorer 4.6.1.2115 has ".elx" FileType XML External Entity Injection.
|
CWE-611
XXE
|
CVE-2018-16252
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246806
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview
|
The diagnosticsb2ksy parameter of the /rest endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16148
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246807
|
6.1 |
MEDIUM
Network
|
opsview
|
opsview
|
The data parameter of the /settings/api/router endpoint in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to Cross-Site Scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16147
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246808
|
7.2 |
HIGH
Network
|
opsview
|
opsview
|
The web management console of Opsview Monitor 5.4.x before 5.4.2 provides functionality accessible by an authenticated administrator to test notifications that are triggered under certain configurabl…
|
CWE-78
OS Command
|
CVE-2018-16146
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246809
|
8.1 |
HIGH
Network
|
opsview
|
opsview
|
The /etc/init.d/opsview-reporting-module script that runs at boot time in Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 invokes a file that can be edited by the nagios user, and would allow att…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16145
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246810
|
9.8 |
CRITICAL
Network
|
opsview
|
opsview
|
The test connection functionality in the NetAudit section of Opsview Monitor before 5.3.1 and 5.4.x before 5.4.2 is vulnerable to command injection due to improper sanitization of the rancid_password…
|
CWE-78
OS Command
|
CVE-2018-16144
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|