|
246761
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Notification template' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15511
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246762
|
6.1 |
MEDIUM
Network
|
totemo
|
totemomail
|
Cross-site scripting (XSS) vulnerability in the 'Certificate' feature of totemomail 6.0.0 build 570 allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15510
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246763
|
7.5 |
HIGH
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow Directory Traversal.
|
CWE-22
Path Traversal
|
CVE-2018-14918
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246764
|
9.1 |
CRITICAL
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow Arbitrary file deletion.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14916
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246765
|
6.5 |
MEDIUM
Network
|
odoo
|
odoo
|
Improper Host header sanitization in the dbfilter routing component in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier allows a remote attacker to deny access to the service and …
|
CWE-20
Improper Input Validation
|
CVE-2018-14887
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246766
|
4.9 |
MEDIUM
Network
|
odoo
|
odoo
|
The module-description renderer in Odoo Community 11.0 and earlier and Odoo Enterprise 11.0 and earlier does not disable RST's local file inclusion, which allows privileged authenticated users to rea…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-14886
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246767
|
9.8 |
CRITICAL
Network
|
odoo
|
odoo
|
Incorrect access control in the database manager component in Odoo Community 10.0 and 11.0 and Odoo Enterprise 10.0 and 11.0 allows a remote attacker to restore a database dump without knowing the su…
|
CWE-284
Improper Access Control
|
CVE-2018-14885
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246768
|
6.1 |
MEDIUM
Network
|
loytec
|
lgate-902_firmware
|
LOYTEC LGATE-902 6.3.2 devices allow XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14919
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246769
|
9.8 |
CRITICAL
Network
|
lexmark
|
cx310_firmware cx410_firmware cx510_firmware xc2132_firmware mx31x_firmware mx41x_firmware mx51x_firmware xm1145_firmware mx61x_firmware xm3150_firmware mx71x_firmware
|
Various Lexmark devices have a Buffer Overflow (issue 1 of 2).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-15519
|
2024-11-21 12:50 |
2019-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246770
|
9.8 |
CRITICAL
Network
|
bubblesoftapps
|
bubbleupnp
|
In BubbleUPnP 0.9 update 30, the XML parsing engine for SSDP/UPnP functionality is vulnerable to an XML External Entity Processing (XXE) attack. Remote, unauthenticated attackers can use this vulnera…
|
CWE-611
XXE
|
CVE-2018-15506
|
2024-11-21 12:50 |
2019-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|