|
246801
|
5.3 |
MEDIUM
Network
|
endress
|
wirelesshart_fieldgate_swg70_firmware
|
Endress+Hauser WirelessHART Fieldgate SWG70 3.x devices allow Directory Traversal via the fcgi-bin/wgsetcgi filename parameter.
|
CWE-22
Path Traversal
|
CVE-2018-16059
|
2024-11-21 12:52 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246802
|
9.8 |
CRITICAL
Network
|
umbraengineering
|
ps
|
A command Injection in ps package versions <1.0.0 for Node.js allowed arbitrary commands to be executed when attacker controls the PID.
|
CWE-78
OS Command
|
CVE-2018-16460
|
2024-11-21 12:52 |
2018-09-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246803
|
5.5 |
MEDIUM
Local
|
nasm
|
netwide_assembler
|
asm/labels.c in Netwide Assembler (NASM) is prone to NULL Pointer Dereference, which allows the attacker to cause a denial of service via a crafted file.
|
CWE-476
NULL Pointer Dereference
|
CVE-2018-16517
|
2024-11-21 12:52 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246804
|
6.5 |
MEDIUM
Adjacent
|
technicolor
|
tg588v_firmware
|
Technicolor TG588V V2 devices allow remote attackers to cause a denial of service (networking outage) via a flood of random MAC addresses, as demonstrated by macof. NOTE: this might overlap CVE-2018-…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2018-16310
|
2024-11-21 12:52 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246805
|
6.1 |
MEDIUM
Network
|
userproplugin
|
userpro
|
The UserPro plugin through 4.9.23 for WordPress allows XSS via the shortcode parameter in a userpro_shortcode_template action to wp-admin/admin-ajax.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16285
|
2024-11-21 12:52 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246806
|
6.8 |
MEDIUM
Physics
|
pulsesecure
|
pulse_secure_desktop_client
|
In Pulse Secure Pulse Desktop Client 5.3RX before 5.3R5 and 9.0R1, there is a Privilege Escalation Vulnerability with Dynamic Certificate Trust.
|
CWE-295
Improper Certificate Validation
|
CVE-2018-16261
|
2024-11-21 12:52 |
2018-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246807
|
7.8 |
HIGH
Local
|
artifex canonical debian
|
ghostscript ubuntu_linux debian_linux
|
An issue was discovered in Artifex Ghostscript before 9.24. The .setdistillerkeys PostScript command is accepted even though it is not intended for use during document processing (e.g., after the sta…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-16585
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246808
|
6.1 |
MEDIUM
Network
|
exceljs_project
|
exceljs
|
An unescaped payload in exceljs <v1.6 allows a possible XSS via cell value when worksheet is displayed in browser.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16459
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246809
|
8.8 |
HIGH
Network
|
micropyramid
|
django_crm
|
MicroPyramid Django-CRM 0.2 allows CSRF for /users/create/, /users/##/edit/, and /accounts/##/delete/ URIs.
|
CWE-352
Origin Validation Error
|
CVE-2018-16552
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246810
|
5.4 |
MEDIUM
Network
|
lavalite
|
lavalite
|
LavaLite 5.5 has XSS via a /edit URI, as demonstrated by client/job/job/Zy8PWBekrJ/edit.
|
CWE-79
Cross-site Scripting
|
CVE-2018-16551
|
2024-11-21 12:52 |
2018-09-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|