|
251481
|
5.3 |
MEDIUM
Network
|
samsung
|
samsung_mobile
|
A malformed OMACP WAP push message can cause memory corruption on a Samsung S7 Edge device when processing the String Extension portion of the WbXml payload. This is due to an integer overflow in mem…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2018-10751
|
2024-11-21 12:41 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251482
|
9.8 |
CRITICAL
Network
|
zohocorp
|
manageengine_adaudit_plus
|
Zoho ManageEngine ADAudit Plus before 5.0.0 build 5100 allows blind SQL Injection.
|
CWE-89
SQL Injection
|
CVE-2018-10466
|
2024-11-21 12:41 |
2018-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251483
|
5.3 |
MEDIUM
Network
|
dataiku
|
data_science_studio
|
The REST API in Dataiku DSS before 4.2.3 allows remote attackers to obtain sensitive information (i.e., determine if a username is valid) because of profile pictures visibility.
|
CWE-200
Information Exposure
|
CVE-2018-10732
|
2024-11-21 12:41 |
2018-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251484
|
8.8 |
HIGH
Network
|
trendmicro
|
smart_protection_server
|
A SQL injection remote code execution vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow a remote attacker to execute arbitrary code on vulnerable installations due to …
|
CWE-89
SQL Injection
|
CVE-2018-10350
|
2024-11-21 12:41 |
2018-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251485
|
6.3 |
MEDIUM
Adjacent
|
bd
|
database_manager performa reada
|
A vulnerability in ReadA version 1.1.0.2 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA, Kiestra WCA, and InoqulA+ specimen processor) …
|
CWE-89
SQL Injection
|
CVE-2018-10595
|
2024-11-21 12:41 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251486
|
5.6 |
MEDIUM
Adjacent
|
bd
|
database_manager performa reada
|
A vulnerability in DB Manager version 3.0.1.0 and previous and PerformA version 3.0.0.0 and previous allows an authorized user with access to a privileged account on a BD Kiestra system (Kiestra TLA,…
|
CWE-89
SQL Injection
|
CVE-2018-10593
|
2024-11-21 12:41 |
2018-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251487
|
6.1 |
MEDIUM
Network
|
ilias
|
ilias
|
ILIAS before 5.1.26, 5.2.x before 5.2.15, and 5.3.x before 5.3.4, due to inconsistencies in parameter handling, is vulnerable to various instances of reflected cross-site-scripting.
|
CWE-79
Cross-site Scripting
|
CVE-2018-10428
|
2024-11-21 12:41 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251488
|
8.1 |
HIGH
Network
|
citrix
|
xenmobile_server
|
There is a Hazelcast Library Java Deserialization Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2018-10654
|
2024-11-21 12:41 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251489
|
9.8 |
CRITICAL
Network
|
citrix
|
xenmobile_server
|
There is an XML External Entity (XXE) Processing Vulnerability in Citrix XenMobile Server 10.8 before RP2 and 10.7 before RP3.
|
CWE-611
XXE
|
CVE-2018-10653
|
2024-11-21 12:41 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
251490
|
7.5 |
HIGH
Network
|
citrix
|
xenmobile_server
|
There is a Sensitive Data Leakage issue in Citrix XenMobile Server 10.7 before RP3.
|
CWE-200
Information Exposure
|
CVE-2018-10652
|
2024-11-21 12:41 |
2018-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|