|
246861
|
5.4 |
MEDIUM
Network
|
mondula
|
multi_step_form
|
The Mondula Multi Step Form plugin before 1.2.8 for WordPress has multiple stored XSS via wp-admin/admin-ajax.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-14846
|
2024-11-21 12:49 |
2018-12-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246862
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in dhd_bus_flow_ring_create_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (wh…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14856
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246863
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in dhd_bus_flow_ring_flush_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 allow an attacker (who has obtained code exec…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14855
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246864
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Buffer overflow in dhd_bus_flow_ring_delete_response in drivers/net/wireless/bcmdhd4358/dhd_pcie.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allow an attacker (wh…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14854
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246865
|
4.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
A NULL pointer dereference in dhd_prot_txdata_write_flush in drivers/net/wireless/bcmdhd4358/dhd_msgbuf.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an atta…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-14853
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246866
|
6.3 |
MEDIUM
Adjacent
|
samsung
|
galaxy_s6_firmware
|
Out-of-bounds array access in dhd_rx_frame in drivers/net/wireless/bcmdhd4358/dhd_linux.c in the bcmdhd4358 Wi-Fi driver on the Samsung Galaxy S6 SM-G920F G920FXXU5EQH7 allows an attacker (who has ob…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-14852
|
2024-11-21 12:49 |
2018-12-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246867
|
4.3 |
MEDIUM
Network
|
theforeman
|
katello
|
A SQL injection flaw was found in katello's errata-related API. An authenticated remote attacker can craft input data to force a malformed SQL query to the backend database, which will leak internal …
|
-
|
CVE-2018-14623
|
2024-11-21 12:49 |
2018-12-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246868
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
Incorrect access control in the Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to bypass authentication due to insecure token generation.
|
CWE-287
Improper Authentication
|
CVE-2018-14709
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246869
|
9.8 |
CRITICAL
Network
|
drobo
|
5n2_firmware
|
An insecure transport protocol used by Drobo Dashboard API on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows attackers to intercept network traffic.
|
CWE-287
Improper Authentication
|
CVE-2018-14708
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246870
|
7.5 |
HIGH
Network
|
drobo
|
5n2_firmware
|
Directory traversal in the Drobo Pix web application on Drobo 5N2 NAS version 4.0.5-13.28.96115 allows unauthenticated attackers to upload files to arbitrary locations.
|
CWE-22
Path Traversal
|
CVE-2018-14707
|
2024-11-21 12:49 |
2018-12-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|