|
246521
|
5.4 |
MEDIUM
Network
|
rcfilters_project
|
rcfilters
|
In the rcfilters plugin 2.1.6 for Roundcube, XSS exists via the _whatfilter and _messages parameters (in the Filters section of the settings).
|
CWE-79
Cross-site Scripting
|
CVE-2018-16736
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246522
|
7.5 |
HIGH
Network
|
ethereum
|
go_ethereum
|
In Go Ethereum (aka geth) before 1.8.14, TraceChain in eth/api_tracer.go does not verify that the end block is after the start block.
|
CWE-20
Improper Input Validation
|
CVE-2018-16733
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246523
|
8.8 |
HIGH
Network
|
chshcms
|
cscms
|
\upload\plugins\sys\admin\Setting.php in CScms 4.1 allows CSRF via admin.php/setting/ftp_save.
|
CWE-352
Origin Validation Error
|
CVE-2018-16732
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246524
|
9.8 |
CRITICAL
Network
|
chshcms
|
cscms
|
CScms 4.1 allows arbitrary file upload by (for example) adding the php extension to the default filetype list (gif, jpg, png), and then providing a .php pathname within fileurl JSON data.
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-16731
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246525
|
6.1 |
MEDIUM
Network
|
chshcms
|
cscms
|
\upload\plugins\sys\Install.php in CScms 4.1 has XSS via the site name.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16730
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246526
|
6.1 |
MEDIUM
Network
|
baijiacms_project
|
baijiacms
|
An issue is discovered in baijiacms V4. XSS exists via the assets/weengine/components/zclip/ZeroClipboard.swf id parameter, aka "Non-standard use of the flash component."
|
CWE-79
Cross-site Scripting
|
CVE-2018-16725
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246527
|
9.8 |
CRITICAL
Network
|
baijiacms_project
|
baijiacms
|
An issue is discovered in baijiacms V4. Blind SQL Injection exists via the order parameter in an index.php?act=index request.
|
CWE-89
SQL Injection
|
CVE-2018-16724
|
2024-11-21 12:53 |
2018-09-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246528
|
8.8 |
HIGH
Network
|
absolute
|
ctes_windows_agent
|
An issue was discovered in Absolute Software CTES Windows Agent through 1.0.0.1479. The security permissions on the %ProgramData%\CTES folder and sub-folders may allow write access to low-privileged …
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-16715
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246529
|
9.1 |
CRITICAL
Network
|
octoprint
|
octoprint
|
OctoPrint through 1.3.9 allows remote attackers to obtain sensitive information or cause a denial of service via HTTP requests on port 8081. NOTE: the vendor disputes the significance of this report …
|
CWE-200
Information Exposure
|
CVE-2018-16710
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246530
|
9.8 |
CRITICAL
Network
|
fujixerox
|
docucentre-v_3065_firmware apeosport-v_c4475_firmware apeosport-vi_c3371_firmware apeosport-v_c3375_firmware docucentre-vi_c2271_firmware apeosport-v_c5576_firmware docucentre-iv_c2…
|
Fuji Xerox DocuCentre-V 3065, ApeosPort-VI C3371, ApeosPort-V C4475, ApeosPort-V C3375, DocuCentre-VI C2271, ApeosPort-V C5576, DocuCentre-IV C2263, DocuCentre-V C2263, and ApeosPort-V 5070 devices a…
|
NVD-CWE-noinfo
|
CVE-2018-16709
|
2024-11-21 12:53 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|