|
247361
|
8.8 |
HIGH
Network
|
reprisesoftware
|
reprise_license_manager
|
An issue was discovered in Reprise License Manager (RLM) through 12.2BL2. Attackers can use the web interface to read and write data to any file on disk (as long as rlm.exe has access to it) via /gof…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2018-15573
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247362
|
6.1 |
MEDIUM
Network
|
tp5cms_project
|
tp5cms
|
tp5cms through 2017-05-25 has XSS via the admin.php/article/index.html q parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15566
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247363
|
8.8 |
HIGH
Network
|
simple-cms_project
|
simple_cms
|
An issue was discovered in daveismyname simple-cms through 2014-03-11. admin/addpage.php does not require authentication for adding a page. This can also be exploited via CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-15565
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247364
|
8.8 |
HIGH
Network
|
simple-cms_project
|
simple_cms
|
An issue was discovered in daveismyname simple-cms through 2014-03-11. There is a CSRF vulnerability that can delete any page via admin/?delpage=8.
|
CWE-352
Origin Validation Error
|
CVE-2018-15564
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247365
|
7.5 |
HIGH
Network
|
pycryptodome
|
pycryptodome
|
PyCryptodome before 3.6.6 has an integer overflow in the data_len variable in AESNI.c, related to the AESNI_encrypt and AESNI_decrypt functions, leading to the mishandling of messages shorter than 16…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-15560
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247366
|
6.1 |
MEDIUM
Network
|
xiuno
|
xiunobbs
|
The editor in Xiuno BBS 4.0.4 allows stored XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-15559
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247367
|
8.8 |
HIGH
Network
|
telus
|
actiontec_t2200h_firmware
|
fileshare.cmd on Telus Actiontec T2200H T2200H-31.128L.03 devices allows OS Command Injection via shell metacharacters in the smbdUserid or smbdPasswd field.
|
CWE-78
OS Command
|
CVE-2018-15553
|
2024-11-21 12:51 |
2018-08-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247368
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
An issue was discovered in GitLab Community and Enterprise Edition before 11.1.7, 11.2.x before 11.2.4, and 11.3.x before 11.3.1. The diff formatter using rouge can block for a long time in Sidekiq j…
|
NVD-CWE-noinfo
|
CVE-2018-15472
|
2024-11-21 12:50 |
2023-04-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247369
|
7.5 |
HIGH
Network
|
tcpdump redhat debian opensuse fedoraproject f5 apple
|
tcpdump enterprise_linux debian_linux leap fedora traffix_signaling_delivery_controller mac_os_x
|
The ICMPv6 parser in tcpdump before 4.9.3 has a buffer over-read in print-icmp6.c.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-14882
|
2024-11-21 12:50 |
2019-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247370
|
5.3 |
MEDIUM
Network
|
totemo
|
totemomail
|
Log viewer in totemomail 6.0.0 build 570 allows access to sessionIDs of high privileged users by leveraging access to a read-only auditor role.
|
CWE-284
Improper Access Control
|
CVE-2018-15513
|
2024-11-21 12:50 |
2019-08-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|