|
247221
|
5.3 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enum…
|
CWE-200
Information Exposure
|
CVE-2018-15131
|
2024-11-21 12:50 |
2019-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247222
|
9.8 |
CRITICAL
Network
|
polycom
|
group_series hdx pano
|
An issue was discovered in Polycom Group Series 6.1.6.1 and earlier, HDX 3.1.12 and earlier, and Pano 1.1.1 and earlier. A remote code execution vulnerability exists in the content sharing functional…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15128
|
2024-11-21 12:50 |
2019-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247223
|
7.5 |
HIGH
Network
|
cisco
|
firepower_threat_defense
|
A vulnerability in the TCP ingress handler for the data interfaces that are configured with management access to Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote a…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2018-15462
|
2024-11-21 12:50 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247224
|
8.6 |
HIGH
Network
|
cisco
|
adaptive_security_appliance_software firepower_threat_defense
|
A vulnerability in the WebVPN login process of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to ca…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-15388
|
2024-11-21 12:50 |
2019-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247225
|
7.5 |
HIGH
Network
|
bpcbt
|
smartvista
|
BPC SmartVista 2 has Session Fixation via the JSESSIONID parameter.
|
CWE-384
Session Fixation
|
CVE-2018-15208
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247226
|
7.2 |
HIGH
Network
|
bpcbt
|
smartvista
|
BPC SmartVista 2 has Improper Access Control in the SVFE module, where it fails to appropriately restrict access: a normal user is able to access the SVFE2/pages/finadmin/currconvrate/currconvrate.js…
|
CWE-269
Improper Privilege Management
|
CVE-2018-15207
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247227
|
8.8 |
HIGH
Network
|
bpcbt
|
smartvista
|
BPC SmartVista 2 has CSRF via SVFE2/pages/admpages/roles/createrole.jsf.
|
CWE-352
Origin Validation Error
|
CVE-2018-15206
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247228
|
6.1 |
MEDIUM
Network
|
polarisft
|
intellect_core_banking
|
An issue was discovered in the Core and Portal modules in Polaris FT Intellect Core Banking 9.7.1. An open redirect exists via a /IntellectMain.jsp?IntellectSystem= URI.
|
CWE-601
Open Redirect
|
CVE-2018-14931
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247229
|
8.8 |
HIGH
Network
|
polarisft
|
intellect_core_banking
|
An issue was discovered in the Armor module in Polaris FT Intellect Core Banking 9.7.1. CSRF can occur via a /CollatWebApp/gcmsRefInsert?name=SUPP URI.
|
CWE-352
Origin Validation Error
|
CVE-2018-14930
|
2024-11-21 12:50 |
2019-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247230
|
7.5 |
HIGH
Network
|
coolpad t-mobile
|
defiant_firmware revvl_plus_firmware
|
The Coolpad Defiant (Coolpad/cp3632a/cp3632a:7.1.1/NMF26F/099480857:user/release-keys) and the T-Mobile Revvl Plus (Coolpad/alchemy/alchemy:7.1.1/143.14.171129.3701A-TMO/buildf_nj_02-206:user/release…
|
CWE-20
Improper Input Validation
|
CVE-2018-15003
|
2024-11-21 12:50 |
2019-04-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|