|
250971
|
5.5 |
MEDIUM
Local
|
k7computing
|
enterprise_security ultimate_security total_security antivrius
|
A Memory Leak issue was discovered in K7Computing K7AntiVirus Premium 15.01.00.53.
|
CWE-125
Out-of-bounds Read
|
CVE-2018-11005
|
2024-11-21 12:42 |
2021-01-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250972
|
9.8 |
CRITICAL
Network
|
netgear
|
wc7500_firmware wc7520_firmware wc7600v1_firmware wc7600v2_firmware wc9500_firmware
|
NETGEAR has released fixes for a pre-authentication command injection in request_handler.php security vulnerability on the following product models: WC7500, running firmware versions prior to 6.5.3.5…
|
CWE-77
Command Injection
|
CVE-2018-11106
|
2024-11-21 12:42 |
2020-04-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250973
|
5.4 |
MEDIUM
Network
|
redhat
|
cloudforms_management_engine
|
cloudforms version, cloudforms 5.8 and cloudforms 5.9, is vulnerable to a cross-site-scripting. A flaw was found in CloudForms's v2v infrastructure mapping delete feature. A stored cross-site scripti…
|
-
|
CVE-2018-10854
|
2024-11-21 12:42 |
2019-11-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250974
|
6.1 |
MEDIUM
Network
|
acquia
|
mautic
|
An issue was discovered in Mautic 2.13.1. It has Stored XSS via the company name field.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11200
|
2024-11-21 12:42 |
2019-09-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250975
|
6.1 |
MEDIUM
Network
|
acquia
|
mautic
|
An issue was discovered in Mautic 2.13.1. There is Stored XSS via the authorUrl field in config.json.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11198
|
2024-11-21 12:42 |
2019-09-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250976
|
8.8 |
HIGH
Network
|
jolokia redhat
|
jolokia openstack
|
A flaw was found in Jolokia versions from 1.2 to before 1.6.1. Affected versions are vulnerable to a system-wide CSRF. This holds true for properly configured instances with strict checking for origi…
|
CWE-352
Origin Validation Error
|
CVE-2018-10899
|
2024-11-21 12:42 |
2019-08-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250977
|
8.8 |
HIGH
Network
|
open-xchange
|
ox_guard
|
OX Guard 2.8.0 has CSRF.
|
CWE-352
Origin Validation Error
|
CVE-2018-10986
|
2024-11-21 12:42 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250978
|
6.1 |
MEDIUM
Network
|
monstra
|
monstra_cms
|
Monstra CMS 3.0.4 and earlier has XSS via index.php.
|
CWE-79
Cross-site Scripting
|
CVE-2018-11227
|
2024-11-21 12:42 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250979
|
9.8 |
CRITICAL
Network
|
cloudera
|
data_science_workbench
|
Remote code execution is possible in Cloudera Data Science Workbench version 1.3.0 and prior releases via unspecified attack vectors.
|
CWE-200 CWE-78
Information Exposure OS Command
|
CVE-2018-11215
|
2024-11-21 12:42 |
2019-07-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250980
|
3.1 |
LOW
Adjacent
|
polycom
|
realpresence_debut_firmware
|
An issue was discovered in versions earlier than 1.3.2 for Polycom RealPresence Debut where the admin cookie is reset only after a Debut is rebooted.
|
CWE-20
Improper Input Validation
|
CVE-2018-10947
|
2024-11-21 12:42 |
2019-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|