|
246281
|
6.1 |
MEDIUM
Network
|
tribulant
|
slideshow_gallery
|
The Tribulant Slideshow Gallery plugin before 1.6.6.1 for WordPress has XSS via the id, method, Gallerymessage, Galleryerror, or Galleryupdated parameter.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17946
|
2024-11-21 12:55 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246282
|
8.8 |
HIGH
Network
|
gnu
|
gnulib
|
The convert_to_decimal function in vasnprintf.c in Gnulib before 2018-09-23 has a heap-based buffer overflow because memory is not allocated for a trailing '\0' character during %f processing.
|
CWE-787
Out-of-bounds Write
|
CVE-2018-17942
|
2024-11-21 12:55 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246283
|
5.3 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
Zimbra Collaboration before 8.8.10 GA allows text content spoofing via a loginErrorCode value.
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2018-17938
|
2024-11-21 12:55 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246284
|
5.5 |
MEDIUM
Local
|
linux canonical redhat debian
|
linux_kernel ubuntu_linux enterprise_linux_desktop enterprise_linux_workstation enterprise_linux_server enterprise_linux_server_tus enterprise_linux_server_eus enterprise_linux_s…
|
An issue was discovered in the proc_pid_stack function in fs/proc/base.c in the Linux kernel through 4.18.11. It does not ensure that only root may inspect the kernel stack of an arbitrary task, allo…
|
CWE-362
Race Condition
|
CVE-2018-17972
|
2024-11-21 12:55 |
2018-10-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246285
|
5.4 |
MEDIUM
Network
|
jeesns
|
jeesns
|
An issue was discovered in JEESNS 1.3. The XSS filter in com.lxinet.jeesns.core.utils.XssHttpServletRequestWrapper.java could be bypassed, as demonstrated by a <svg/onLoad=confirm substring. NOTE: th…
|
CWE-79
Cross-site Scripting
|
CVE-2018-17886
|
2024-11-21 12:55 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246286
|
6.1 |
MEDIUM
Network
|
gwolle_guestbook_project
|
gwolle_guestbook
|
XSS exists in admin/gb-dashboard-widget.php in the Gwolle Guestbook (gwolle-gb) plugin before 2.5.4 for WordPress via the PATH_INFO to wp-admin/index.php
|
CWE-79
Cross-site Scripting
|
CVE-2018-17884
|
2024-11-21 12:55 |
2018-10-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246287
|
6.1 |
MEDIUM
Network
|
expressionengine
|
expressionengine
|
ExpressionEngine before 4.3.5 has reflected XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17874
|
2024-11-21 12:55 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246288
|
6.1 |
MEDIUM
Network
|
btiteam
|
xbtit
|
An issue was discovered in BTITeam XBTIT 2.5.4. The "returnto" parameter of account_change.php is vulnerable to an open redirect, a different vulnerability than CVE-2018-15683.
|
CWE-601
Open Redirect
|
CVE-2018-17870
|
2024-11-21 12:55 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246289
|
8.8 |
HIGH
Network
|
dasan
|
h660gw_firmware
|
DASAN H660GW devices do not implement any CSRF protection mechanism.
|
CWE-352
Origin Validation Error
|
CVE-2018-17869
|
2024-11-21 12:55 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246290
|
4.8 |
MEDIUM
Network
|
dasan
|
h660gw_firmware
|
DASAN H660GW devices have Stored XSS in the Port Forwarding functionality.
|
CWE-79
Cross-site Scripting
|
CVE-2018-17868
|
2024-11-21 12:55 |
2018-10-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|