|
249741
|
6.1 |
MEDIUM
Network
|
ruckussecurity
|
icx7450-48_firmware
|
A reflected XSS vulnerability on Ruckus ICX7450-48 devices allows remote attackers to inject arbitrary web script or HTML.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11027
|
2024-11-21 12:42 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249742
|
8.1 |
HIGH
Network
|
divido
|
divido
|
In the Divido plugin for OpenCart, there is SQL injection. Attackers can use SQL injection to get some confidential information.
|
CWE-89
SQL Injection
|
CVE-2018-11231
|
2024-11-21 12:42 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249743
|
6.1 |
MEDIUM
Network
|
ckeditor
|
ckeditor_5-link
|
Cross-site scripting (XSS) vulnerability in the Link package for CKEditor 5 before 10.0.1 allows remote attackers to inject arbitrary web script through a crafted href attribute of a link (A) element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11093
|
2024-11-21 12:42 |
2018-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249744
|
6.5 |
MEDIUM
Network
|
horse_market_sell_\&_rent_portal_project
|
horse_market_sell_\&_rent_portal
|
Horse Market Sell & Rent Portal Script 1.5.7 has a CSRF vulnerability through which an attacker can change all of the target's account information remotely.
|
CWE-352
Origin Validation Error
|
CVE-2018-11096
|
2024-11-21 12:42 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249745
|
6.5 |
MEDIUM
Network
|
admin_notes_project
|
admin_notes
|
An issue was discovered in the Admin Notes plugin 1.1 for MyBB. CSRF allows an attacker to remotely delete all admin notes via an admin/index.php?empty=table (aka Clear Table) action.
|
CWE-352
Origin Validation Error
|
CVE-2018-11092
|
2024-11-21 12:42 |
2018-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249746
|
6.5 |
MEDIUM
Network
|
makemytrip
|
makemytrip
|
An issue was discovered in the MakeMyTrip application 7.2.4 for Android. The databases (locally stored) are not encrypted and have cleartext that might lead to sensitive information disclosure, as de…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-11242
|
2024-11-21 12:42 |
2018-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249747
|
7.5 |
HIGH
Network
|
hexagontoken
|
hexagon
|
An integer overflow in the _transfer function of a smart contract implementation for Hexagon (HXG), an Ethereum ERC20 token, allows attackers to accomplish an unauthorized increase of digital assets …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-11239
|
2024-11-21 12:42 |
2018-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249748
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
An issue was discovered in PoDoFo 0.9.5. The function PdfPage::GetPageNumber() in PdfPage.cpp in PoDoFo 0.9.5 allows remote attackers to cause a denial of service (NULL pointer dereference and applic…
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-11255
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249749
|
5.5 |
MEDIUM
Local
|
podofo_project
|
podofo
|
An issue was discovered in PoDoFo 0.9.5. There is an Excessive Recursion in the PdfPagesTree::GetPageNode() function of PdfPagesTree.cpp. Remote attackers could leverage this vulnerability to cause a…
|
CWE-674
Uncontrolled Recursion
|
CVE-2018-11254
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249750
|
6.5 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
In ImageMagick 7.0.7-23 Q16 x86_64 2018-01-24, there is a heap-based buffer over-read in ReadSUNImage in coders/sun.c, which allows attackers to cause a denial of service (application crash in SetGra…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11251
|
2024-11-21 12:42 |
2018-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|