|
246681
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/forms/eye_mag/php/Anything_simple.php from library/forms.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary…
|
CWE-89
SQL Injection
|
CVE-2018-15149
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246682
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/patient_file/encounter/search_code.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL commands via the …
|
CWE-89
SQL Injection
|
CVE-2018-15148
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246683
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/forms_admin/forms_admin.php from library/registry.inc in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL co…
|
CWE-89
SQL Injection
|
CVE-2018-15147
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246684
|
8.8 |
HIGH
Network
|
open-emr
|
openemr
|
SQL injection vulnerability in interface/de_identification_forms/find_immunization_popup.php in versions of OpenEMR before 5.0.1.4 allows a remote authenticated attacker to execute arbitrary SQL comm…
|
CWE-89
SQL Injection
|
CVE-2018-15146
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246685
|
7.5 |
HIGH
Network
|
ericssonlg
|
ipecs_nms
|
Ericsson-LG iPECS NMS 30M allows directory traversal via ipecs-cm/download?filename=../ URIs.
|
CWE-22
Path Traversal
|
CVE-2018-15138
|
2024-11-21 12:50 |
2018-08-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246686
|
6.1 |
MEDIUM
Network
|
monstra
|
monstra
|
Multiple cross-site scripting (XSS) vulnerabilities in Monstra CMS 3.0.4 allow remote attackers to inject arbitrary web script or HTML via the (1) first name or (2) last name field in the edit profil…
|
CWE-79
Cross-site Scripting
|
CVE-2018-14922
|
2024-11-21 12:50 |
2018-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246687
|
6.1 |
MEDIUM
Network
|
thank_you\/like_project
|
thank_you\/like
|
inc/plugins/thankyoulike.php in the Eldenroot Thank You/Like plugin before 3.1.0 for MyBB allows XSS via a post or thread subject.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14888
|
2024-11-21 12:50 |
2018-08-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246688
|
7.5 |
HIGH
Network
|
zipato
|
zipabox_firmware
|
Sensitive Information Disclosure in Zipato Zipabox Smart Home Controller allows remote attacker get sensitive information that expands attack surface.
|
CWE-200
Information Exposure
|
CVE-2018-15125
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246689
|
9.8 |
CRITICAL
Network
|
zipato
|
zipabox_firmware
|
Weak hashing algorithm in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows unauthenticated attacker extract clear text passwords and get root access on the device.
|
CWE-326
Inadequate Encryption Strength
|
CVE-2018-15124
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246690
|
9.8 |
CRITICAL
Network
|
zipato
|
zipabox_firmware
|
Insecure configuration storage in Zipato Zipabox Smart Home Controller BOARD REV - 1 with System Version -118 allows remote attacker perform new attack vectors and take under control device and smart…
|
NVD-CWE-noinfo
|
CVE-2018-15123
|
2024-11-21 12:50 |
2018-08-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|