|
247351
|
9.8 |
CRITICAL
Network
|
elefantcms
|
elefantcms
|
apps/filemanager/handlers/upload/drop.php in Elefant CMS 2.0.3 performs a urldecode step too late in the "Cannot upload executable files" protection mechanism.
|
CWE-20
Improper Input Validation
|
CVE-2018-15601
|
2024-11-21 12:51 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247352
|
5.3 |
MEDIUM
Network
|
debian dropbear_ssh_project
|
debian_linux dropbear_ssh
|
The recv_msg_userauth_request function in svr-auth.c in Dropbear through 2018.76 is prone to a user enumeration vulnerability because username validity affects how fields in SSH_MSG_USERAUTH messages…
|
CWE-200
Information Exposure
|
CVE-2018-15599
|
2024-11-21 12:51 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247353
|
7.5 |
HIGH
Network
|
traefik
|
traefik
|
Containous Traefik 1.6.x before 1.6.6, when --api is used, exposes the configuration and secret if authentication is missing and the API's port is publicly reachable.
|
CWE-287
Improper Authentication
|
CVE-2018-15598
|
2024-11-21 12:51 |
2018-08-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247354
|
5.5 |
MEDIUM
Local
|
debian canonical linux
|
debian_linux ubuntu_linux linux_kernel
|
arch/x86/kernel/paravirt.c in the Linux kernel before 4.18.1 mishandles certain indirect calls, which makes it easier for attackers to conduct Spectre-v2 attacks against paravirtual guests.
|
CWE-200
Information Exposure
|
CVE-2018-15594
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247355
|
6.1 |
MEDIUM
Network
|
reprisesoftware
|
reprise_license_manager
|
An issue was discovered in the license editor in Reprise License Manager (RLM) through 12.2BL2. It is a cross-site scripting vulnerability in the /goform/edit_lf_get_data lf parameter via GET or POST…
|
CWE-79
Cross-site Scripting
|
CVE-2018-15574
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247356
|
6.5 |
MEDIUM
Local
|
debian canonical linux
|
debian_linux ubuntu_linux linux_kernel
|
The spectre_v2_select_mitigation function in arch/x86/kernel/cpu/bugs.c in the Linux kernel before 4.18.1 does not always fill RSB upon a context switch, which makes it easier for attackers to conduc…
|
NVD-CWE-noinfo
|
CVE-2018-15572
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247357
|
4.8 |
MEDIUM
Network
|
bijiadao
|
waimai_super_cms
|
In waimai Super Cms 20150505, there is stored XSS via the /admin.php/Foodcat/editsave fcname parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15570
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247358
|
6.5 |
MEDIUM
Network
|
mylittleforum
|
my_little_forum
|
my little forum 2.4.12 allows CSRF for deletion of users.
|
CWE-352
Origin Validation Error
|
CVE-2018-15569
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247359
|
8.8 |
HIGH
Network
|
tp5cms_project
|
tp5cms
|
tp5cms through 2017-05-25 has CSRF via admin.php/category/delete.html.
|
CWE-352
Origin Validation Error
|
CVE-2018-15568
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247360
|
6.1 |
MEDIUM
Network
|
cmsuno_project
|
cmsuno
|
CMSUno before 1.5.3 has XSS via the title field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15567
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|