|
245621
|
7.8 |
HIGH
Local
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltratio…
|
CWE-125
Out-of-bounds Read
|
CVE-2018-18986
|
2024-11-21 12:56 |
2019-02-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245622
|
8.8 |
HIGH
Network
|
lcds
|
laquis_scada
|
LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a sy…
|
CWE-20
Improper Input Validation
|
CVE-2018-18988
|
2024-11-21 12:56 |
2019-02-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245623
|
9.8 |
CRITICAL
Network
|
vignette
|
content_management
|
In Vignette Content Management version 6, it is possible to gain remote access to administrator privileges by discovering the admin password in the vgn/ccb/user/mgmt/user/edit/0,1628,0,00.html?uid=ad…
|
CWE-200
Information Exposure
|
CVE-2018-18941
|
2024-11-21 12:56 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245624
|
6.1 |
MEDIUM
Network
|
netscape
|
enterprise_server
|
servlet/SnoopServlet (a servlet installed by default) in Netscape Enterprise 3.63 has reflected XSS via an arbitrary parameter=[XSS] in the query string. A remote unauthenticated attacker could poten…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18940
|
2024-11-21 12:56 |
2019-02-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245625
|
5.4 |
MEDIUM
Network
|
tridium
|
niagara_enterprise_security niagara niagara_ax_framework
|
Tridium Niagara Enterprise Security 2.3u1, all versions prior to 2.3.118.6, Niagara AX 3.8u4, all versions prior to 3.8.401.1, Niagara 4.4u2, all versions prior to 4.4.93.40.2, and Niagara 4.6, all v…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18985
|
2024-11-21 12:56 |
2019-01-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245626
|
7.5 |
HIGH
Network
|
rockwellautomation
|
factorytalk_services_platform
|
In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that coul…
|
CWE-787
Out-of-bounds Write
|
CVE-2018-18981
|
2024-11-21 12:56 |
2019-01-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245627
|
5.9 |
MEDIUM
Network
|
sky
|
sky_go
|
The Sky Go Desktop application 1.0.19-1 through 1.0.23-1 for Windows performs several requests over cleartext HTTP. This makes the data submitted in these requests prone to Man in The Middle (MiTM) a…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2018-18908
|
2024-11-21 12:56 |
2019-01-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245628
|
9.8 |
CRITICAL
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The TIBCO Spotfire authentication component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability in the handling of the a…
|
CWE-287
Improper Authentication
|
CVE-2018-18814
|
2024-11-21 12:56 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245629
|
6.1 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Spotfire web server component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains multiple vulnerabilities that may allow persistent…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18813
|
2024-11-21 12:56 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245630
|
5.3 |
MEDIUM
Network
|
tibco
|
spotfire_server spotfire_analytics_platform_for_aws
|
The Spotfire Library component of TIBCO Software Inc.'s TIBCO Spotfire Analytics Platform for AWS Marketplace, and TIBCO Spotfire Server contains a vulnerability that might theoretically fail to rest…
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2018-18812
|
2024-11-21 12:56 |
2019-01-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|