|
246611
|
9.8 |
CRITICAL
Network
|
isweb
|
isweb
|
CMS ISWEB 3.5.3 is vulnerable to directory traversal and local file download, as demonstrated by moduli/downloadFile.php?file=oggetto_documenti/../.././inc/config.php (one can take the control of the…
|
CWE-22
Path Traversal
|
CVE-2018-14957
|
2024-11-21 12:50 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246612
|
9.8 |
CRITICAL
Network
|
isweb
|
isweb
|
CMS ISWEB 3.5.3 is vulnerable to multiple SQL injection flaws. An attacker can inject malicious queries into the application and obtain sensitive information.
|
CWE-89
SQL Injection
|
CVE-2018-14956
|
2024-11-21 12:50 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246613
|
7.8 |
HIGH
Local
|
vectra
|
cognito
|
Management Console in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local privilege escalation vulnerability.
|
NVD-CWE-noinfo
|
CVE-2018-14891
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246614
|
5.4 |
MEDIUM
Network
|
vectra
|
cognito
|
Vectra Networks Cognito Brain and Sensor before 4.2 contains a cross-site scripting (XSS) vulnerability in the Web Management Console.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14890
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246615
|
7.8 |
HIGH
Local
|
apache
|
couchdb
|
CouchDB in Vectra Networks Cognito Brain and Sensor before 4.3 contains a local code execution vulnerability.
|
CWE-20
Improper Input Validation
|
CVE-2018-14889
|
2024-11-21 12:50 |
2018-09-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246616
|
4.3 |
MEDIUM
Network
|
f5
|
big-ip_access_policy_manager
|
A vulnerability in BIG-IP APM portal access 11.5.1-11.5.7, 11.6.0-11.6.3, and 12.1.0-12.1.3 discloses the BIG-IP software version in rewritten pages.
|
CWE-200
Information Exposure
|
CVE-2018-15310
|
2024-11-21 12:50 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246617
|
7.5 |
HIGH
Network
|
lwolf
|
loading_docs
|
Insecure permissions in Lone Wolf Technologies loadingDOCS 2018-08-13 allow remote attackers to download any confidential files via https requests for predictable URLs.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-15502
|
2024-11-21 12:50 |
2018-09-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246618
|
9.1 |
CRITICAL
Network
|
kone
|
group_controller_firmware
|
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Local File Inclusion and File modification is possible through the open HTTP interface by modifying the na…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2018-15486
|
2024-11-21 12:50 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246619
|
9.1 |
CRITICAL
Network
|
kone
|
group_controller_firmware
|
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. FTP does not require authentication or authorization, aka KONE-03.
|
CWE-287
Improper Authentication
|
CVE-2018-15485
|
2024-11-21 12:50 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246620
|
9.8 |
CRITICAL
Network
|
kone
|
group_controller_firmware
|
An issue was discovered on KONE Group Controller (KGC) devices before 4.6.5. Unauthenticated Remote Code Execution is possible through the open HTTP interface by modifying autoexec.bat, aka KONE-01.
|
CWE-78
OS Command
|
CVE-2018-15484
|
2024-11-21 12:50 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|