|
246311
|
6.1 |
MEDIUM
Network
|
ipandao
|
editor.md
|
Pandao Editor.md 1.5.0 allows XSS via crafted attributes of an invalid IMG element.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16330
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246312
|
9.8 |
CRITICAL
Network
|
imagemagick
|
imagemagick
|
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the GetMagickProperty function in MagickCore/property.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16329
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246313
|
9.8 |
CRITICAL
Network
|
imagemagick
|
imagemagick
|
In ImageMagick before 7.0.8-8, a NULL pointer dereference exists in the CheckEventLogging function in MagickCore/log.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16328
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246314
|
4.8 |
MEDIUM
Network
|
intelliants
|
subrion
|
There is Stored XSS in Subrion 4.2.1 via the admin panel URL configuration.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16327
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246315
|
6.1 |
MEDIUM
Network
|
get-simple
|
getsimple_cms
|
There is XSS in GetSimple CMS 3.4.0.9 via the admin/edit.php title field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16325
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246316
|
6.1 |
MEDIUM
Network
|
icewarp
|
mail_server
|
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16324
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246317
|
6.5 |
MEDIUM
Network
|
imagemagick canonical
|
imagemagick ubuntu_linux
|
ReadXBMImage in coders/xbm.c in ImageMagick before 7.0.8-9 leaves data uninitialized when processing an XBM file that has a negative pixel value. If the affected code is used as a library loaded into…
|
CWE-200
Information Exposure
|
CVE-2018-16323
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246318
|
7.2 |
HIGH
Network
|
idreamsoft
|
icms
|
idreamsoft iCMS 7.0.11 allows admincp.php?app=config Directory Traversal, resulting in execution of arbitrary PHP code from a ZIP file.
|
CWE-22
Path Traversal
|
CVE-2018-16320
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246319
|
5.4 |
MEDIUM
Network
|
portainer
|
portainer
|
A stored Cross-site scripting (XSS) vulnerability in Portainer through 1.19.1 allows remote authenticated users to inject arbitrary JavaScript and/or HTML via the Team Name field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16316
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246320
|
6.5 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
In waimai Super Cms 20150505, there is a CSRF vulnerability that can change the configuration via admin.php?m=Config&a=add.
|
CWE-352
Origin Validation Error
|
CVE-2018-16315
|
2024-11-21 12:52 |
2018-09-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|