|
250061
|
7.8 |
HIGH
Local
|
devicelock
|
plug_and_play_auditor
|
DLPnpAuditor.exe in DeviceLock Plug and Play Auditor (freeware) 5.72 has a Unicode Buffer Overflow (SEH).
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-10655
|
2024-11-21 12:41 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250062
|
5.4 |
MEDIUM
Network
|
opmantek
|
open-audit
|
Cross-site scripting (XSS) vulnerability in Open-AudIT Community 2.2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted name of a component, as demonstrated by the action …
|
CWE-79
Cross-site Scripting
|
CVE-2018-10314
|
2024-11-21 12:41 |
2018-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250063
|
9.8 |
CRITICAL
Network
|
redhat
|
wildfly
|
An issue was discovered in WildFly 10.1.2.Final. In the case of a default installation without a security realm reference, an attacker can successfully access the server without authentication. NOTE:…
|
CWE-287
Improper Authentication
|
CVE-2018-10683
|
2024-11-21 12:41 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250064
|
7.5 |
HIGH
Network
|
auroradao
|
aura
|
The Owned smart contract implementation for Aurora DAO (AURA), an Ethereum ERC20 token, allows attackers to acquire contract ownership because the setOwner function is declared as public. An attacker…
|
NVD-CWE-noinfo
|
CVE-2018-10705
|
2024-11-21 12:41 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250065
|
9.8 |
CRITICAL
Network
|
wildfly
|
wildfly
|
An issue was discovered in WildFly 10.1.2.Final. It is possible for an attacker to access the administration panel on TCP port 9990 without any authentication using "anonymous" access that is automat…
|
CWE-287
Improper Authentication
|
CVE-2018-10682
|
2024-11-21 12:41 |
2018-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250066
|
7.8 |
HIGH
Local
|
kde debian opensuse
|
plasma debian_linux leap
|
kwallet-pam in KDE KWallet before 5.12.6 allows local users to obtain ownership of arbitrary files via a symlink attack.
|
CWE-59
Link Following
|
CVE-2018-10380
|
2024-11-21 12:41 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250067
|
9.8 |
CRITICAL
Network
|
kongtop
|
d303_firmware d305_firmware d403_firmware a303_firmware a403_firmware
|
KONGTOP DVR devices A303, A403, D303, D305, and D403 contain a backdoor that prints the login password via a Print_Password function call in certain circumstances.
|
CWE-200
Information Exposure
|
CVE-2018-10734
|
2024-11-21 12:41 |
2018-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250068
|
6.1 |
MEDIUM
Network
|
vestacp
|
control_panel
|
An issue was discovered in Vesta Control Panel 0.9.8-20. There is Reflected XSS via $_REQUEST['path'] to the view/file/index.php URI, which can lead to remote PHP code execution via vectors involving…
|
CWE-79
Cross-site Scripting
|
CVE-2018-10686
|
2024-11-21 12:41 |
2018-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250069
|
9.8 |
CRITICAL
Network
|
rangerstudio
|
directus
|
Directus 6.4.9 has a hardcoded admin password for the Admin account because of an INSERT statement in api/schema.sql.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-10723
|
2024-11-21 12:41 |
2018-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250070
|
6.5 |
MEDIUM
Network
|
datenstrom
|
yellow
|
The edit/ URI in Datenstrom Yellow 0.7.3 has CSRF via a delete action that can delete articles.
|
CWE-352
Origin Validation Error
|
CVE-2018-10758
|
2024-11-21 12:41 |
2018-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|