|
245561
|
5.4 |
MEDIUM
Network
|
columbiaweather
|
weather_microserver_firmware
|
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a stored Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script via changestationna…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18875
|
2024-11-21 12:56 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245562
|
8.8 |
HIGH
Network
|
cerio
|
dt-300n_firmware
|
Cerio DT-300N 1.1.6 through 1.1.12 devices allow OS command injection because of improper input validation of the web-interface PING feature's use of Save.cgi to execute a ping command, as exploited …
|
CWE-78
OS Command
|
CVE-2018-18852
|
2024-11-21 12:56 |
2019-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245563
|
7.5 |
HIGH
Network
|
artha_project
|
artha
|
Artha ~ The Open Thesaurus 1.0.3.0 has a Buffer Overflow.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18944
|
2024-11-21 12:56 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245564
|
6.1 |
MEDIUM
Network
|
helpy.io
|
helpy
|
Helpy v2.1.0 has Stored XSS via the Ticket title.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18886
|
2024-11-21 12:56 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245565
|
5.4 |
MEDIUM
Network
|
columbiaweather
|
weather_microserver_firmware
|
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, a networkdiags.php reflected Cross-site scripting (XSS) vulnerability allows remote authenticated users to inject arbitrary web script.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18880
|
2024-11-21 12:56 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245566
|
8.8 |
HIGH
Network
|
columbiaweather
|
weather_microserver_firmware
|
In firmware version MS_2.6.9900 of Columbia Weather MicroServer, an authenticated web user can pipe commands directly to the underlying operating system as user input is not sanitized in networkdiags…
|
CWE-94
Code Injection
|
CVE-2018-18879
|
2024-11-21 12:56 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245567
|
6.5 |
MEDIUM
Network
|
opnsense
|
opnsense
|
OPNsense 18.7.x before 18.7.7 has Incorrect Access Control.
|
CWE-284
Improper Access Control
|
CVE-2018-18958
|
2024-11-21 12:56 |
2019-06-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245568
|
9.1 |
CRITICAL
Network
|
citrix
|
xenmobile_server
|
An Incorrect Access Control vulnerability has been identified in Citrix XenMobile Server 10.8.0 before Rolling Patch 6 and 10.9.0 before Rolling Patch 3. An attacker can impersonate and take actions …
|
CWE-287
Improper Authentication
|
CVE-2018-18571
|
2024-11-21 12:56 |
2019-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245569
|
6.1 |
MEDIUM
Network
|
synacor
|
zimbra_collaboration_suite
|
mailboxd component in Synacor Zimbra Collaboration Suite 8.6, 8.7 before 8.7.11 Patch 7, and 8.8 before 8.8.10 Patch 2 has Persistent XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18631
|
2024-11-21 12:56 |
2019-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245570
|
9.8 |
CRITICAL
Network
|
tubigan
|
welcome_to_our_resort
|
The Tubigan "Welcome to our Resort" 1.0 software allows SQL Injection via index.php?p=accomodation&q=[SQL], index.php?p=rooms&q=[SQL], or admin/login.php.
|
CWE-89
SQL Injection
|
CVE-2018-18800
|
2024-11-21 12:56 |
2019-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|