|
245671
|
9.8 |
CRITICAL
Network
|
gitlab
|
gitlab
|
An issue was discovered in the wiki API in GitLab Community and Enterprise Edition before 11.2.7, 11.3.x before 11.3.8, and 11.4.x before 11.4.3. It allows for remote code execution.
|
NVD-CWE-noinfo
|
CVE-2018-18649
|
2024-11-21 12:56 |
2018-11-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245672
|
8.8 |
HIGH
Network
|
nuuo
|
nuuo_cms
|
NUUO CMS All versions 3.3 and prior the web server application allows injection of arbitrary SQL characters, which can be used to inject SQL into an executing statement and allow arbitrary code execu…
|
CWE-89
SQL Injection
|
CVE-2018-18982
|
2024-11-21 12:56 |
2018-11-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245673
|
5.4 |
MEDIUM
Network
|
tibco
|
statistica_server
|
The web application of the TIBCO Statistica component of TIBCO Software Inc.'s TIBCO Statistica Server contains vulnerabilities which may allow an authenticated user to perform cross-site scripting (…
|
CWE-79
Cross-site Scripting
|
CVE-2018-18807
|
2024-11-21 12:56 |
2018-11-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245674
|
8.1 |
HIGH
Network
|
royalapplications
|
royal_ts royal_tsx
|
The Royal browser extensions TS before 4.3.60728 (Release Date 2018-07-28) and TSX before 3.3.1 (Release Date 2018-09-13) allow Credentials Disclosure.
|
CWE-200
Information Exposure
|
CVE-2018-18865
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245675
|
9.6 |
CRITICAL
Network
|
loadbalancer
|
enterprise_va_max
|
Loadbalancer.org Enterprise VA MAX before 8.3.3 has XSS because Apache HTTP Server logs are displayed.
|
CWE-79
Cross-site Scripting
|
CVE-2018-18864
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245676
|
9.8 |
CRITICAL
Network
|
pcman_ftp_server_project
|
pcman_ftp_server
|
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2018-18861
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245677
|
7.8 |
HIGH
Local
|
liquidvpn
|
liquidvpn
|
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execu…
|
CWE-78
OS Command
|
CVE-2018-18859
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245678
|
7.8 |
HIGH
Local
|
liquidvpn
|
liquidvpn
|
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execu…
|
CWE-78
OS Command
|
CVE-2018-18858
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245679
|
7.8 |
HIGH
Local
|
liquidvpn
|
liquidvpn
|
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execu…
|
CWE-78
OS Command
|
CVE-2018-18857
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245680
|
7.8 |
HIGH
Local
|
liquidvpn
|
liquidvpn
|
Multiple local privilege escalation vulnerabilities have been identified in the LiquidVPN client through 1.37 for macOS. An attacker can communicate with an unprotected XPC service and directly execu…
|
CWE-78
OS Command
|
CVE-2018-18856
|
2024-11-21 12:56 |
2018-11-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|