|
248971
|
9.8 |
CRITICAL
Network
|
abbyy
|
flexicapture
|
The HTTP API in ABBYY FlexiCapture before 12 Release 1 Update 7 allows an attacker to conduct Access Control attacks via the /FlexiCapture12/Login/Server/SevaUserProfile FlexiCaptureTmsSts2 parameter.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-13791
|
2024-11-21 12:48 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248972
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
A Server Side Request Forgery (SSRF) vulnerability in tools/files/importers/remote.php in concrete5 8.2.0 can lead to attacks on the local network and mapping of the internal network, because of URL …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-13790
|
2024-11-21 12:48 |
2018-07-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248973
|
8.8 |
HIGH
Network
|
solarwinds
|
network_performance_monitor
|
SolarWinds Network Performance Monitor 12.3 allows SQL Injection via the /api/ActiveAlertsOnThisEntity/GetActiveAlerts TriggeringObjectEntityNames parameter.
|
CWE-89
SQL Injection
|
CVE-2018-13442
|
2024-11-21 12:47 |
2019-07-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248974
|
8.8 |
HIGH
Network
|
block
|
jit-wasm
|
EOS.IO jit-wasm 4.1 has a heap-based buffer overflow via a crafted wast file.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-13443
|
2024-11-21 12:47 |
2019-04-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248975
|
5.4 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
The two-dimensional filter statistics gadget in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.12.4, and from version 7.13.0 before version 7.13.1 allows remote attackers t…
|
CWE-79
Cross-site Scripting
|
CVE-2018-13403
|
2024-11-21 12:47 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248976
|
4.1 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
The VerifyPopServerConnection resource in Atlassian Jira before version 7.6.10, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2018-13404
|
2024-11-21 12:47 |
2019-02-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248977
|
8.8 |
HIGH
Network
|
terra-master
|
terramaster_operating_system
|
System command injection in ajaxdata.php in TerraMaster TOS 3.1.03 allows attackers to execute system commands via the "newname" parameter.
|
CWE-78
OS Command
|
CVE-2018-13418
|
2024-11-21 12:47 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248978
|
8.8 |
HIGH
Network
|
atlassian
|
sourcetree
|
There was an argument injection vulnerability in Sourcetree for Windows from version 0.5.1.0 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to com…
|
NVD-CWE-noinfo
|
CVE-2018-13397
|
2024-11-21 12:47 |
2018-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248979
|
8.8 |
HIGH
Network
|
atlassian
|
sourcetree
|
There was an argument injection vulnerability in Sourcetree for macOS from version 1.0b2 before version 3.0.0 via Git subrepositories in Mercurial repositories. An attacker with permission to commit …
|
NVD-CWE-noinfo
|
CVE-2018-13396
|
2024-11-21 12:47 |
2018-11-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248980
|
6.1 |
MEDIUM
Network
|
atlassian
|
jira jira_server
|
Many resources in Atlassian Jira before version 7.6.9, from version 7.7.0 before version 7.7.5, from version 7.8.0 before version 7.8.5, from version 7.9.0 before version 7.9.3, from version 7.10.0 b…
|
CWE-601
Open Redirect
|
CVE-2018-13402
|
2024-11-21 12:47 |
2018-10-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|