|
247131
|
9.8 |
CRITICAL
Network
|
saltstack
|
salt
|
SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allow remote attackers to bypass authentication and execute arbitrary commands via salt-api(netapi).
|
CWE-287
Improper Authentication
|
CVE-2018-15751
|
2024-11-21 12:51 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247132
|
5.3 |
MEDIUM
Network
|
saltstack
|
salt
|
Directory Traversal vulnerability in salt-api in SaltStack Salt before 2017.7.8 and 2018.3.x before 2018.3.3 allows remote attackers to determine which files exist on the server.
|
CWE-22
Path Traversal
|
CVE-2018-15750
|
2024-11-21 12:51 |
2018-10-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247133
|
8.8 |
HIGH
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.2 and below is vulnerable to a stack buffer overflow vulnerability. A remote authenticated attacker could potentially exploit this vulnerability by sending a crafted HTTP requ…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-15704
|
2024-11-21 12:51 |
2018-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247134
|
6.1 |
MEDIUM
Network
|
advantech
|
webaccess
|
Advantech WebAccess 8.3.2 and below is vulnerable to multiple reflected cross site scripting vulnerabilities. A remote unauthenticated attacker could potentially exploit this vulnerability by trickin…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15703
|
2024-11-21 12:51 |
2018-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247135
|
5.5 |
MEDIUM
Local
|
dell
|
emc_secure_remote_services
|
Dell EMC Secure Remote Services, versions prior to 3.32.00.08, contains an Information Exposure vulnerability. The log file contents store sensitive data including executed commands to generate authe…
|
CWE-200
Information Exposure
|
CVE-2018-15765
|
2024-11-21 12:51 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247136
|
8.1 |
HIGH
Network
|
pivotal_software
|
spring_security_oauth
|
Spring Security OAuth, versions 2.3 prior to 2.3.4, and 2.2 prior to 2.2.3, and 2.1 prior to 2.1.3, and 2.0 prior to 2.0.16, and older unsupported versions could be susceptible to a privilege escalat…
|
NVD-CWE-noinfo
|
CVE-2018-15758
|
2024-11-21 12:51 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247137
|
7.5 |
HIGH
Network
|
vmware oracle debian
|
spring_framework flexcube_private_banking insurance_policy_administration_j2ee retail_xstore_point_of_service weblogic_server retail_invoice_matching primavera_gateway insurance_…
|
Spring Framework, version 5.1, versions 5.0.x prior to 5.0.10, versions 4.3.x prior to 4.3.20, and older unsupported versions on the 4.2.x branch provide support for range requests when serving stati…
|
NVD-CWE-noinfo
|
CVE-2018-15756
|
2024-11-21 12:51 |
2018-10-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247138
|
7.8 |
HIGH
Local
|
adobe
|
technical_communications_suite
|
Adobe Technical Communications Suite versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2018-15976
|
2024-11-21 12:51 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247139
|
7.8 |
HIGH
Local
|
adobe
|
framemaker
|
Adobe Framemaker versions 1.0.5.1 and below have an insecure library loading (dll hijacking) vulnerability. Successful exploitation could lead to privilege escalation.
|
CWE-426
Untrusted Search Path
|
CVE-2018-15974
|
2024-11-21 12:51 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247140
|
6.1 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager versions 6.4, 6.3, 6.2, 6.1, and 6.0 have a stored cross-site scripting vulnerability. Successful exploitation could lead to sensitive information disclosure.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15973
|
2024-11-21 12:51 |
2018-10-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|