|
246411
|
8.8 |
HIGH
Network
|
simple-cms_project
|
simple_cms
|
An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-15565
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246412
|
8.8 |
HIGH
Network
|
simple-cms_project
|
simple_cms
|
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.
|
CWE-352
Origin Validation Error
|
CVE-2018-15564
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246413
|
7.5 |
HIGH
Network
|
pycryptodome
|
pycryptodome
|
PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-15560
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246414
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
The editor in Xiuno BBS 4.0.4 allows stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15559
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246415
|
8.8 |
HIGH
Network
|
telus
|
actiontec_t2200h_firmware
|
fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPasswd field.
|
CWE-78
OS Command
|
CVE-2018-15553
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246416
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq j…
|
NVD-CWE-noinfo
|
CVE-2018-15472
|
2024-11-21 12:50 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246417
|
7.5 |
HIGH
Network
|
tcpdump redhat debian opensuse fedoraproject f5 apple
|
tcpdump enterprise_linux debian_linux leap fedora traffix_signaling_delivery_controller mac_os_x
|
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14882
|
2024-11-21 12:50 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246418
|
5.3 |
MEDIUM
Network
|
totemo
|
totemomail
|
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
|
CWE-284
Improper Access Control
|
CVE-2018-15513
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246419
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Authorisation Service' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15512
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246420
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15511
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|