|
247091
|
6.5 |
MEDIUM
Network
|
proconf
|
proconf
|
In ProConf before 6.1, an Insecure Direct Object Reference (IDOR) allows any author to view and grab all submitted papers (Title and Abstract) and their authors' personal information (Name, Email, Or…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2018-16606
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247092
|
7.2 |
HIGH
Network
|
nibbleblog
|
nibbleblog
|
An issue was discovered in Nibbleblog v4.0.5. With an admin's username and password, an attacker can execute arbitrary PHP code by changing the username because the username is surrounded by double q…
|
CWE-94
Code Injection
|
CVE-2018-16604
|
2024-11-21 12:53 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247093
|
7.5 |
HIGH
Network
|
apereo
|
opencast
|
An issue was discovered in Apereo Opencast 4.x through 10.x before 10.6. It sends system digest credentials during authentication attempts to arbitrary external services in some situations.
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2018-16153
|
2024-11-21 12:52 |
2023-12-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247094
|
6.5 |
MEDIUM
Network
|
opera
|
opera_mini
|
The Opera Mini application 47.1.2249.129326 for Android allows remote attackers to spoof the Location Permission dialog via a crafted web site.
|
NVD-CWE-noinfo
|
CVE-2018-16135
|
2024-11-21 12:52 |
2022-12-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247095
|
6.1 |
MEDIUM
Network
|
mitsubishielectric
|
smartrtu_firmware
|
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16061
|
2024-11-21 12:52 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247096
|
7.5 |
HIGH
Network
|
mitsubishielectric
|
smartrtu_firmware
|
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2018-16060
|
2024-11-21 12:52 |
2021-10-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247097
|
5.9 |
MEDIUM
Network
|
versa-networks
|
versa_operating_system
|
In VOS compromised, an attacker at network endpoints can possibly view communications between an unsuspecting user and the service using man-in-the-middle attacks. Usage of unapproved SSH encryption …
|
CWE-326
Inadequate Encryption Strength
|
CVE-2018-16499
|
2024-11-21 12:52 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247098
|
5.5 |
MEDIUM
Local
|
versa-networks
|
versa_director
|
In Versa Director, the unencrypted backup files stored on the Versa deployment contain credentials stored within configuration files. These credentials are for various application components such as …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2018-16498
|
2024-11-21 12:52 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247099
|
7.8 |
HIGH
Local
|
versa-networks
|
versa_analytics
|
In Versa Analytics, the cron jobs are used for scheduling tasks by executing commands at specific dates and times on the server. If the job is run as the user root, there is a potential privilege esc…
|
CWE-269
Improper Privilege Management
|
CVE-2018-16497
|
2024-11-21 12:52 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247100
|
5.3 |
MEDIUM
Network
|
versa-networks
|
versa_director
|
In Versa Director, the un-authentication request found.
|
CWE-287
Improper Authentication
|
CVE-2018-16496
|
2024-11-21 12:52 |
2021-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|