|
247311
|
8.8 |
HIGH
Network
|
pivotal_software
|
pivotal_container_service
|
Pivotal Container Service, versions prior to 1.2.0, contains an information disclosure vulnerability which exposes IaaS credentials to application logs. A malicious user with access to application lo…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2018-15763
|
2024-11-21 12:51 |
2018-10-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247312
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.0.6, 11.1.x before 11.1.5, and 11.2.x before 11.2.2. There is Missing Authorization Control for API Repository Storage.
|
CWE-862
Missing Authorization
|
CVE-2018-16048
|
2024-11-21 12:51 |
2018-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247313
|
7.5 |
HIGH
Network
|
mensamax
|
mensamax
|
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. The use of a Hard-coded DES Cryptographic Key allows an attacker who decodes the application to decry…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2018-15753
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247314
|
8.1 |
HIGH
Network
|
mensamax
|
mensamax
|
An issue was discovered in the MensaMax (aka com.breustedt.mensamax) application 4.3 for Android. Cleartext Transmission of Sensitive Information allows man-in-the-middle attackers to eavesdrop authe…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2018-15752
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247315
|
6.1 |
MEDIUM
Network
|
intelliants
|
subrion
|
_core/admin/pages/add/ in Subrion CMS 4.2.1 has XSS via the titles[en] parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15563
|
2024-11-21 12:51 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247316
|
8.8 |
HIGH
Network
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to CSRF due to insufficient validation of the referer field.
|
CWE-352
Origin Validation Error
|
CVE-2018-15702
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247317
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Cookie field.
|
CWE-20
Improper Input Validation
|
CVE-2018-15701
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247318
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tl-wrn841n_firmware
|
The web interface in TP-Link TL-WRN841N 0.9.1 4.16 v0348.0 is vulnerable to a denial of service when an unauthenticated LAN user sends a crafted HTTP header containing an unexpected Referer field.
|
CWE-20
Improper Input Validation
|
CVE-2018-15700
|
2024-11-21 12:51 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247319
|
9.8 |
CRITICAL
Network
|
emc
|
esrs_policy_manager
|
Dell EMC ESRS Policy Manager versions 6.8 and prior contain a remote code execution vulnerability due to improper configurations of triggered JMX services. A remote unauthenticated attacker may poten…
|
NVD-CWE-noinfo
|
CVE-2018-15764
|
2024-11-21 12:51 |
2018-09-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247320
|
6.7 |
MEDIUM
Local
|
avaya
|
aura_communication_manager
|
A vulnerability in the local system administration component of Avaya Aura Communication Manager can allow an authenticated, privileged user on the local system to gain root privileges. Affected vers…
|
NVD-CWE-noinfo
|
CVE-2018-15611
|
2024-11-21 12:51 |
2018-09-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|