|
246421
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15510
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246422
|
7.5 |
HIGH
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2018-14918
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246423
|
9.1 |
CRITICAL
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14916
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246424
|
6.5 |
MEDIUM
Network
|
odoo
|
odoo
|
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and …
|
CWE-20
Improper Input Validation
|
CVE-2018-14887
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246425
|
4.9 |
MEDIUM
Network
|
odoo
|
odoo
|
The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to rea…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14886
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246426
|
9.8 |
CRITICAL
Network
|
odoo
|
odoo
|
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the su…
|
CWE-284
Improper Access Control
|
CVE-2018-14885
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246427
|
6.1 |
MEDIUM
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14919
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246428
|
9.8 |
CRITICAL
Network
|
lexmark
|
cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware mx41x_firmware mx51x_firmware xm1145_firmware mx61x_firmware xm3150_firmware mx71x_firmware
|
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15519
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246429
|
9.8 |
CRITICAL
Network
|
bubblesoftapps
|
bubbleupnp
|
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnera…
|
CWE-611
XXE
|
CVE-2018-15506
|
2024-11-21 12:50 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246430
|
5.3 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
An issue was discovered in Synacor Zimbra Collaboration Suite 8.6.x before 8.6.0 Patch 11, 8.7.x before 8.7.11 Patch 6, 8.8.x before 8.8.8 Patch 9, and 8.8.9 before 8.8.9 Patch 3. Account number enum…
|
CWE-200
Information Exposure
|
CVE-2018-15131
|
2024-11-21 12:50 |
2019-05-31 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|