|
246671
|
9.8 |
CRITICAL
Network
|
kraftway
|
24f2xg_router_firmware
|
Router Default Credentials in Kraftway 24F2XG Router firmware version 3.5.30.1118 allow remote attackers to get privileged access to the router.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2018-15350
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246672
|
7.8 |
HIGH
Local
|
telerik
|
justdecompile justassembly
|
An issue found in Progress Telerik JustAssembly through 2018.1.323.2 and JustDecompile through 2018.2.605.0 makes it possible to execute code by decompiling a compiled .NET object (such as DLL or EXE…
|
CWE-20
Improper Input Validation
|
CVE-2018-15122
|
2024-11-21 12:50 |
2018-08-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246673
|
7.5 |
HIGH
Network
|
tp-link
|
tl-wr840n_firmware
|
TP-Link WR840N devices have a buffer overflow via a long Authorization HTTP header.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15172
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246674
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/faxq.php after m…
|
CWE-78
OS Command
|
CVE-2018-15156
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246675
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/fax/fax_dispatch.php…
|
CWE-78
OS Command
|
CVE-2018-15155
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246676
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/billing/sl_eob_searc…
|
CWE-78
OS Command
|
CVE-2018-15154
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246677
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
OS command injection occurring in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary commands by making a crafted request to interface/main/daemon_frame.ph…
|
CWE-78
OS Command
|
CVE-2018-15153
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246678
|
9.1 |
CRITICAL
Network
|
open-emr
|
openemr
|
Authentication bypass vulnerability in portal/account/register.php in versions of OpenEMR before 5.0.1.4 allows a remote attacker to access (1) portal/add_edit_event_user.php, (2) portal/find_appt_po…
|
CWE-287
Improper Authentication
|
CVE-2018-15152
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246679
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/de_identification_forms/find_code_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via…
|
CWE-89
SQL Injection
|
CVE-2018-15151
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246680
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/de_identification_forms/de_identification_screen2.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL co…
|
CWE-89
SQL Injection
|
CVE-2018-15150
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|