|
248871
|
6.1 |
MEDIUM
Network
|
mao10
|
mao10cms
|
mao10cms 6 allows XSS via the article page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12696
|
2024-11-21 12:45 |
2018-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248872
|
6.1 |
MEDIUM
Network
|
mao10
|
mao10cms
|
mao10cms 6 allows XSS via the m=bbs&a=index page.
|
CWE-79
Cross-site Scripting
|
CVE-2018-12695
|
2024-11-21 12:45 |
2018-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248873
|
7.5 |
HIGH
Network
|
tp-link
|
tl-wa850re_firmware
|
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote attackers to cause a denial of service (reboot) via data/reboot.json.
|
CWE-20
Improper Input Validation
|
CVE-2018-12694
|
2024-11-21 12:45 |
2018-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248874
|
6.5 |
MEDIUM
Network
|
tp-link
|
tl-wa850re_firmware
|
Stack-based buffer overflow in TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to cause a denial of service (outage) via a long type parameter to /da…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-12693
|
2024-11-21 12:45 |
2018-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248875
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wa850re_firmware
|
TP-Link TL-WA850RE Wi-Fi Range Extender with hardware version 5 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the wps_setup_pin parameter to /data/wps.se…
|
CWE-78
OS Command
|
CVE-2018-12692
|
2024-11-21 12:45 |
2018-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248876
|
9.8 |
CRITICAL
Network
|
phpldapadmin_project
|
phpldapadmin
|
phpLDAPadmin 1.2.2 allows LDAP injection via a crafted server_id parameter in a cmd.php?cmd=login_form request, or a crafted username and password in the login panel.
|
NVD-CWE-Other
|
CVE-2018-12689
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248877
|
9.8 |
CRITICAL
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has a segmentation fault in the wav2Decode function.
|
CWE-20
Improper Input Validation
|
CVE-2018-12688
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248878
|
7.5 |
HIGH
Network
|
tinyexr_project
|
tinyexr
|
tinyexr 0.9.5 has an assertion failure in DecodePixelData in tinyexr.h.
|
CWE-617
Reachable Assertion
|
CVE-2018-12687
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248879
|
7.1 |
HIGH
Local
|
civetweb_project
|
civetweb
|
Out-of-bounds Read in the send_ssi_file function in civetweb.c in CivetWeb through 1.10 allows attackers to cause a Denial of Service or Information Disclosure via a crafted SSI file.
|
CWE-200 CWE-125
Information Exposure Out-of-bounds Read
|
CVE-2018-12684
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248880
|
9.8 |
CRITICAL
Network
|
portainer
|
portainer
|
Portainer before 1.18.0 supports unauthenticated requests to the websocket endpoint with an unvalidated id query parameter for the /websocket/exec endpoint, which allows remote attackers to bypass in…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-12678
|
2024-11-21 12:45 |
2018-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|