|
246881
|
8.6 |
HIGH
Network
|
microsoft
|
active_directory_federation_services
|
Microsoft ADFS 4.0 Windows Server 2016 and previous (Active Directory Federation Services) has an SSRF vulnerability via the txtBoxEmail parameter in /adfs/ls.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-16794
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246882
|
5.3 |
MEDIUM
Network
|
circontrol
|
circarlife_scada
|
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id.
|
CWE-200
Information Exposure
|
CVE-2018-16671
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246883
|
5.3 |
MEDIUM
Network
|
circontrol
|
circarlife_scada
|
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html.
|
CWE-287
Improper Authentication
|
CVE-2018-16670
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246884
|
9.8 |
CRITICAL
Network
|
circontrol
|
open_charge_point_protocol
|
An issue was discovered in CIRCONTROL Open Charge Point Protocol (OCPP) before 1.5.0, as used in CirCarLife, PowerStudio, and other products. Due to storage of credentials in XML files, an unprivileg…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-16669
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246885
|
5.3 |
MEDIUM
Network
|
circontrol
|
circarlife_scada
|
An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository.
|
CWE-287
Improper Authentication
|
CVE-2018-16668
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246886
|
9.8 |
CRITICAL
Network
|
western_digital
|
my_cloud_wdbctl0020hwt_firmware my_cloud_pr4100 my_cloud_pr2100_firmware my_cloud_mirror_gen_2_firmware my_cloud_mirror_firmware my_cloud_ex4100 my_cloud_ex4_firmware my_cloud_ex…
|
It was discovered that the Western Digital My Cloud device before 2.30.196 is affected by an authentication bypass vulnerability. An unauthenticated attacker can exploit this vulnerability to authent…
|
CWE-287
Improper Authentication
|
CVE-2018-17153
|
2024-11-21 12:53 |
2018-09-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246887
|
6.1 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
The login function of Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). The content of the in_hi_redirect parameter, when prefixed with the https:// sc…
|
CWE-79
Cross-site Scripting
|
CVE-2018-16955
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246888
|
6.1 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The login function of the portal is vulnerable to insecure redirection (also called an open redirect). The in_hi_redirect parame…
|
CWE-601
Open Redirect
|
CVE-2018-16954
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246889
|
6.1 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
The AjaxView::DisplayResponse() function of the portalpages.dll assembly in Oracle WebCenter Interaction Portal 10.3.3 is vulnerable to reflected cross-site scripting (XSS). User input from the name …
|
CWE-79
Cross-site Scripting
|
CVE-2018-16953
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246890
|
5.3 |
MEDIUM
Network
|
oracle
|
webcenter_interaction
|
An issue was discovered in Oracle WebCenter Interaction Portal 10.3.3. The portal component is delivered with an insecure default User Profile community configuration that allows anonymous users to r…
|
CWE-200
Information Exposure
|
CVE-2018-16959
|
2024-11-21 12:53 |
2018-09-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|